Back to skill

Security audit

knowledge-card-designer

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese knowledge-card generation skill with local rendering scripts; it has quality and local HTML-sanitization issues, but I found no hidden credential access, persistence, exfiltration, or destructive behavior.

Install this only if you want a Chinese-language Xiaolvshu/WeChat-style card workflow. Expect it to create local HTML, TXT, and PNG outputs under the OpenClaw workspace and to rely on local Chrome or Playwright for screenshots. Do not put secrets or untrusted HTML/JavaScript into the topic or card text unless the generator is updated to escape user input.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (27)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个通用、面向多场景的知识卡片设计技能,强调内容创作与设计方法论;但代码实际仅执行固定模板文件的本地渲染与截图,且主题限定为“GTC 2026 产业趋势卡片”。这不是单纯的实现细节差异,而是主要目的和能力范围上的偏差。虽然两者都与“卡片生成”有关,但代码并未体现声明中的通用知识卡片生成、读书笔记/书籍分享场景适配或设计原则应用能力,因此应判定为描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is related to the declared domain of Xiaolvshu-style knowledge cards, so it is not unrelated or malicious. However, the description overstates the functionality. The script does not actually generate polished final cards or PNG outputs; instead it creates basic HTML templates and a TXT draft with many '待填写' placeholders. It also does not contain substantive logic demonstrating CRAP-principle layout reasoning or color psychology beyond selecting hardcoded color palettes. Thus the declared description is only partially accurate and materially exaggerates the implemented capability.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises file-writing and shell-like operational capabilities through referenced scripts and generation/export workflow, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an unsafe trust boundary: an agent may infer broader execution rights than intended and perform filesystem or command execution actions without least-privilege constraints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description is written as a prescriptive Chinese-only capability ('生成小绿书风格知识卡片的专家技能') and the file provides all instructions, examples, and outputs exclusively in Chinese with no opt-in or alternative language handling. This creates a natural-language locale policy issue because the skill appears to impose a specific language experience rather than offering a user choice or documenting that it is intentionally region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill scope expands from visual design into recommendation-algorithm gaming and engagement optimization guidance, including formulaic interaction hooks and traffic-distribution tactics. This broadening can cause agents to generate manipulative growth content outside the declared design-only purpose, increasing the risk of policy evasion, spammy output, or platform-abuse assistance.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_card.py (reported line 34)May include surrounding context.

python
]
    
    try:
        subprocess.run(cmd, check=True, capture_output=True, timeout=30)
        
        # 使用PIL裁剪到精确尺寸
        img = Image.open(temp_file)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code file includes its primary description, usage instructions, and generated user-facing guidance entirely in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

User-controlled topic text is inserted directly into generated HTML and TXT without escaping or validation. In this skill context, that can turn untrusted input into active HTML/JavaScript when the generated preview pages are opened locally, and it also persists any sensitive text a user may accidentally include into output artifacts stored under the workspace.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Earlier documentation states the cover output size is 900×383px for 微信读书首页展示, but later sections require a 竖版3:4 cover at 1080×1440px as a must-follow formula and checklist item. This is an active contradiction in the skill's own documentation about what cover format should be generated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN", and the visible UI text throughout the template is also fixed in Chinese. This creates a language/locale constraint without any indication of user opt-in or a documented region-specific reason, which matches the policy-violation category for forced language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document sets lang="zh-CN", which hard-codes a specific language/locale. Under the policy, locale-specific behavior should offer user choice or clearly document why the restriction is necessary; this standalone template provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document declares lang="zh-CN", which hard-codes a specific language/locale in a user-facing template. Under the policy, locale constraints should either offer user opt-in/choice or be clearly documented as justified for a region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document declares lang="zh-CN", which hard-codes a specific language/locale for the skill content. Under the policy, locale constraints should either be optional for the user or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document declares lang="zh-CN", which fixes the content to a specific language/locale. Under the policy, locale-specific behavior should either provide user opt-in/choice or clearly document why the restriction is necessary; this file contains no such indication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document declares lang="zh-CN", which hard-codes a specific language/locale. Under the policy criteria, locale restrictions should either be optional for the user or clearly justified as region-specific; no such opt-in or justification appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document declares lang="zh-CN", which hard-codes a specific language/locale. Under the policy, locale constraints should either offer user choice or be clearly documented as justified for a region-specific use case, and no such opt-in or justification appears in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document declares lang="zh-CN", which fixes the content locale to Simplified Chinese. Under the policy, locale-specific behavior should either provide user choice or clearly justify the restriction; this file does neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document declares lang="zh-CN", and all visible user-facing content is written in Chinese, which indicates a fixed language choice. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN", which fixes the content to a specific language/locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative or justification is provided in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all guidance in a single language and does not indicate that the user can choose another language or that the content is intentionally restricted to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and examples exclusively in Chinese, with no indication that users may choose another language or that the skill is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire document is written in Chinese and presents the guidance as a universal design reference without any indication that language selection is optional or that the skill is intended only for Chinese-speaking users. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill file is written as a Chinese-only visual system specification, including headings, labels, and usage guidance, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language workflow. Under the policy rule, a fixed language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that the user can choose another language or that the content is intentionally limited to a Chinese-only audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This file presents all instructions in Chinese and does not provide any user opt-in, alternative language, or justification for a Chinese-only audience, which may conflict with a policy requiring language choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.