Back to skill

Security audit

teaching-materials

Security checks for vulnerabilities and agentic risk

Overview

This teaching-materials skill is useful in scope, but it asks for website passwords, stores them locally in plaintext, and automatically reuses them, which is too sensitive for a document-generation helper.

Install only if you are comfortable auditing and changing the credential workflow. Do not give the agent reusable website passwords or allow plaintext `accounts.json` storage; use manual login, browser sessions, or a secure credential manager instead. Also review external downloads, screenshots, and generated file locations before letting the skill fetch or save resources.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:95
Finding

Mandatory Collection and Plaintext Storage of Website Credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
integration_demo.md:90
Finding

Unpinned Third-Party Package Execution Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs the agent to ask for users' third-party site usernames and passwords and save them to a local JSON file. Collecting raw credentials for unrelated external services is highly sensitive, materially expands the attack surface, and can lead to credential theft, reuse compromise, or unauthorized account access if the file is exposed or mishandled.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs users to provide usernames and passwords for external websites and store them locally, but does not present an adequate risk warning or safe secret-handling model. Users may be induced to disclose reusable credentials to the agent for a non-essential feature, creating a serious credential exposure risk.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs the agent to request, store, and automatically use users' website credentials later. That is a direct secret-handling anti-pattern: it enables credential collection and reuse by the agent, which is dangerous even if framed as local-only because compromise of the host, logs, or files could expose the accounts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely framed as a Chinese primary/secondary teaching document tool, which implies a fixed language/locale experience. The file does not state that the user may choose another language or that the Chinese-only scope is an intentional region-specific constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill expands from document generation into automatic web search, downloading, and local persistence of third-party content. That creates unnecessary network and filesystem side effects, increases copyright/compliance risk, and can cause the agent to fetch and store untrusted external data without explicit per-action user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill describes automatic search, download, and local saving of external resources without a clear, prominent warning that it will transmit queries externally and modify the filesystem. Lack of disclosure reduces informed user consent and makes unintended data transfer or storage more likely.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill claims the credentials are only for download automation, but it also directs persistent storage and later automatic reuse. This contradiction masks ongoing secret handling risk and normalizes repeated autonomous use of stored credentials, increasing the chance of silent misuse or compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill mandates scraping, screenshot capture, and content extraction from arbitrary educational websites as part of normal operation. This broadens the agent's privileges beyond document generation and may lead to unsafe handling of untrusted content, policy violations, or unintended collection of protected material.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes this skill as a tool for generating teaching documents such as PPTs, lesson plans, and student worksheets. This file documents additional behavior where the skill analyzes content, decides when a mind map is needed, and invokes a separate diagram-generator skill to produce diagram artifacts, which is broader than the stated document-generation scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The workflow states that PPT and diagram files are saved automatically, but does not present this as a user-consented filesystem write. Silent local file creation can surprise users, overwrite existing content, or leave sensitive educational materials on disk in locations they did not intend.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The documentation references user-local MCP configuration and a separate skill, which implies this skill may rely on local environment details and cross-skill resources outside its core teaching-material scope. That can enable unintended capability discovery, environment probing, or dependency on local configuration without clear user consent, increasing attack surface if the referenced tool or config is manipulated.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Referencing a concrete local skill path reveals the existence and naming of another installed skill, which is a form of environment and capability enumeration. In isolation this is limited, but combined with other behaviors it can help an attacker map local tooling and target cross-skill abuse or dependency confusion.

Content

Scanner excerpt · integration_demo.md (reported line 150)May include surrounding context.

md
- 思维导图使用指南: `references/mindmap_guide.md`
- 课件制作指南: `references/ppt_guide.md`
- diagram-generator 技能文档: `~/.workbuddy/skills/diagram-generator/SKILL.md`

## 常见问题

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill content is written exclusively in Chinese and does not offer any language or locale choice. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The resource acquisition section encourages direct download, web clipping, screenshots, and content extraction from third-party platforms without any warning about copyright, consent, privacy, or site restrictions. This omission makes risky behavior seem endorsed and increases the chance that users or downstream agents will collect and reuse protected or sensitive material improperly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guidance explicitly recommends acquiring third-party educational content through screenshot capture and using scrape_url to save external pages, which can facilitate bypassing normal download controls and copying content outside intended platform workflows. In a document-generation skill, this expands the skill from creating original teaching materials into potentially unauthorized content acquisition, creating copyright, terms-of-service, and data-handling risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide instructs the skill to go beyond document generation by invoking an external MCP diagram service and writing generated artifacts to disk. This expands the trust boundary: user-controlled lesson content may be sent to another service and persisted locally without clear authorization, validation, or data-handling constraints, creating privacy, integrity, and unintended side-effect risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document title and all instructions are written in Chinese, and the guidance uses mandatory language such as '必须使用' without indicating that other languages/locales are optional. This can violate language/locale policy when a skill forces a specific language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

SQP-3 applies to natural-language policy issues in any file. This document consistently presents the skill experience in Chinese and all example requests are Chinese-only, with no indication that other languages are supported or that Chinese is an optional locale choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest focuses on generating teaching documents like PPTs, lesson plans, and guides. Here the skill is documented as outputting extra diagram files such as .md and .excalidraw artifacts, which are separate deliverables not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Specifying a default local save directory without a clear warning or opt-in normalizes automatic storage of generated output on the user's machine. While lower severity than arbitrary writes, it still creates privacy and clutter risks and may expose student or teacher content in predictable locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file is entirely presented in Chinese and does not indicate that other languages are supported or that Chinese is optional. Under the policy rule for language or locale constraints, this can be a natural-language policy issue when no user opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Using a fixed local path for generated diagrams introduces an unnecessary filesystem side effect and can expose data to other local users/processes, overwrite existing files, or fail unpredictably across environments. Even if intended for convenience, hardcoded output locations reduce user control and increase the chance of accidental data leakage or unsafe file handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire template is written in Chinese and presented as a universal teaching-design template, with no indication that language selection is optional. Under the policy criteria, this can be a natural-language locale constraint because it effectively enforces a specific language without user opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.