Back to skill

Security audit

Anki Card Creator

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a simple local Anki TSV generator, but its documentation and dependency file overstate capabilities and understate setup and content-rendering risks.

Review before installing. Do not run the included requirements.txt as-is; the script appears to need only Python's standard library. Treat the advertised advanced features as unsupported unless the package is corrected, use trusted input files only, inspect generated cards before importing them into Anki, and choose an output path that will not overwrite important files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Standard-library modules declared as external, unpinned dependencies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:25
Finding

Untrusted card content is exported as unescaped HTML

Content
View full analysis
{drug_name}

Mechanism of action?" back = f"{drug_name}
{mechanism}

Indications: {indications}
Side effects: {side_effects}" return front, back def create_anatomy_card(self, structure, location, function): """Create anatomy card.""" front = f"{structure}

Location and function?" back = f"{structure}
Location: {location}
Function: {function}" return front, back def export_anki_format(self, cards, output_file): """Export cards in Anki import format (TSV).""" with open(output_file, 'w') as f: for front, back in cards: # Escape tabs and newlines front = front.replace('\t', ' ').replace('\n', '
') back = back.replace('\t', ' ').replace('\n', '
') f.write(f"{front}\t{back}\n") ``` ### Technical Analysis Question-and-answer input and command-line values are inserted directly into fields that are intentionally rendered as HTML. The exporter only replaces tabs and newline characters; it does not HTML-encode special characters or validate active markup. An attacker controlling an input file or values such as `--name`, `--mec ...[truncated 2320 chars]
Remediation
View remediation
{drug_name}

Mechanism of action?" back = ( f"{drug_name}
{mechanism}

" f"Indications: {indications}
" f"Side effects: {side_effects}" ) return front, back ``` 3. Apply the same encoding to questions and answers parsed from input files before export. 4. Keep trusted formatting generated by the application separate from untrusted text; do not escape the complete final template after adding intended tags. 5. If user-authored formatting is required, sanitize it through a strict allowlist that excludes scripts, event-handler attributes, embedded objects, dangerous URL schemes, and remote resources. 6. Add tests covering tags such as `
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation significantly overstates implemented functionality, claiming advanced features like spaced repetition optimization, cloze/image occlusion support, tagging, and .apkg workflows while the later concrete interface only exposes simple basic card generation. This is dangerous because users or downstream agents may trust nonexistent capabilities, make unsafe assumptions about processing behavior, or route sensitive study materials into a tool that does not provide the claimed controls or outputs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest and headline description advertise a broad, sophisticated skill scope that is not supported by the later documented CLI parameters and minimal interface. In agent ecosystems, this kind of overselling is dangerous because tool selection and trust decisions are often based on metadata first, leading to misuse, failed automation, or inappropriate exposure of user files to an unsuitable tool.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document claims both auto-download/embed of relevant images and 'no external API calls' or low/no network access, which is internally contradictory. This is dangerous because users may approve the skill under a false assumption that it is offline-only, when media retrieval behavior could introduce unreviewed network access, unexpected data disclosure, or supply-chain risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The lifecycle section says cloze deletion, image inclusion, and .apkg export are planned improvements, yet earlier sections present them as current capabilities with usage examples. This inconsistency undermines trust in the skill and can cause users or agents to invoke unsupported workflows, potentially mishandling files or relying on absent safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file documents writing generated card data to user-specified output files, but it does not clearly warn users that existing files at the output path may be created or overwritten. Although file output is part of the skill's purpose, a brief explicit warning about filesystem changes would improve user disclosure for data-affecting behavior.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
# No external dependencies required
# Uses Python standard library only
argparse
re

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# No external dependencies required
# Uses Python standard library only
argparse
re

Static analysis

No suspicious patterns detected.