Back to skill

Security audit

citation-finder

Security checks for vulnerabilities and agentic risk

Overview

This citation lookup skill is coherent and purpose-aligned, with ordinary third-party academic search exposure and dependency-hardening caveats.

Before installing, use a virtual environment and consider pinning dependency versions. Search queries will be sent to CrossRef, Semantic Scholar, Baidu Scholar, and sometimes CNKI, so do not enter confidential paper titles or private research details unless that sharing is acceptable. Manually verify final citations before submission.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:48
Finding

Unpinned Third-Party Dependencies Permit Mutable Supply-Chain Resolution

Content
View full analysis
=2.28.0 beautifulsoup4>=4.11.0 rapidfuzz>=3.0.0 \`\`\` Install: `pip install requests beautifulsoup4 rapidfuzz` ``` The corresponding installation instructions in `README.md:18-22` are: ```markdown ### Install dependencies \`\`\`bash pip install requests beautifulsoup4 rapidfuzz \`\`\` ``` ### Technical Analysis The project instructs users to install dependencies directly by package name and permits mutable versions through lower-bound constraints. It does not provide a lockfile, exact version pins, artifact hashes, or an explicitly trusted package index. Consequently, the source code reviewed in this repository does not uniquely determine the code installed into the runtime environment. Pip may resolve newer direct or transitive dependency versions that were not reviewed with the skill. If a dependency release, transitive dependency, or configured package index is compromised, attacker-controlled package content could be introduced into the environment. This is a supply-chain hardening weakness rather than evidence that any currently named dependency is malicious. ### Attack Path 1. A user follows the documented `pip install` command. 2. Pip queries the user's configured package index and resolves current versions of the named packages and their transitive dependencies. 3. A direct or transitive dependency has been compromised, or the environment is configured to use an attacker-controlled or unsafe package index. 4. Pip downloads and installs the attacker-controlled artifact because no exact version or hash validation is required. 5. Malicious dependency code executes when imported or u ...[truncated 934 chars]
Remediation
View remediation
beautifulsoup4== rapidfuzz== ``` 2. Generate and commit a lockfile containing resolved transitive dependencies. Use an appropriate tool such as `pip-tools`, Poetry, or uv. 3. Record cryptographic hashes for every permitted distribution and require hash verification during installation: ```bash python -m pip install --require-hashes -r requirements.txt ``` 4. Generate the hashes from trusted artifacts obtained from the official Python Package Index or an organization-controlled mirror. 5. Document the expected package index and avoid configurations that merge an internal index with an untrusted public source in a way that enables dependency confusion. 6. Run dependency vulnerability and provenance checks in CI, and review updates before regenerating the lockfile. 7. Install the project in an isolated virtual environment or container under a minimally privileged account. 8. Update both `SKILL.md` and `README.md` so that their installation commands use the locked, hash-verified manifest rather than resolving packages by unpinned names. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented behavior suggests comprehensive Chinese and English citation retrieval, but the implementation reportedly omits major claimed Chinese sources and formatting outputs. In this context, the danger is integrity-related: users may receive incomplete or fabricated-looking results under a trusted academic-assistant label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented behavior suggests comprehensive Chinese and English citation retrieval, but the implementation reportedly omits major claimed Chinese sources and formatting outputs. In this context, the danger is integrity-related: users may receive incomplete or fabricated-looking results under a trusted academic-assistant label.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior suggests comprehensive Chinese and English citation retrieval, but the implementation reportedly omits major claimed Chinese sources and formatting outputs. In this context, the danger is integrity-related: users may receive incomplete or fabricated-looking results under a trusted academic-assistant label.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README presents the skill entirely in Chinese and gives only a Chinese conversational trigger example, implying the interaction language is fixed rather than user-selectable. The policy requires flagging language or locale constraints when they are imposed without explicit opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises network-dependent behavior but does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, missing scope boundaries can lead to overbroad tool access, unclear review expectations, and accidental execution with more network capability than intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Overly broad trigger keywords can cause the skill to activate on general reference or paper-related requests outside its precise competence. In an automated agent setting, this increases the chance of inappropriate routing, unexpected network use, and delivery of low-confidence academic outputs where a different tool or plain response would be safer.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code includes natural-language instructions that hard-code a Chinese citation style convention in the GB/T formatter comment, and the module description advertises support for multiple formats without documenting that one formatter enforces a specific language/locale output. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code hardcodes user-facing messages in Chinese throughout the skill, including the main result formatting, candidate prompts, errors, and CLI usage text. That creates a language/locale policy issue because the skill does not offer any language choice or opt-in despite searching both English and Chinese sources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The Accept-Language header forces a zh-CN/zh preference for all requests, which is a natural-language locale constraint. There is no visible opt-in, configurability, or documented reason that this skill must always prefer Chinese locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module description explicitly states it searches English academic databases, and the exported function name search_english reinforces an English-only constraint. This imposes a language restriction without any visible user choice or justification for the locale limitation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_en.py (reported line 9)May include surrounding context.

python
import requests
from rapidfuzz import fuzz

CROSSREF_URL = "https://api.crossref.org/works"
SEMANTIC_SCHOLAR_URL = "https://api.semanticscholar.org/graph/v1/paper/search"

HEADERS = {

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/search_en.py (reported line 10)May include surrounding context.

python
from rapidfuzz import fuzz

CROSSREF_URL = "https://api.crossref.org/works"
SEMANTIC_SCHOLAR_URL = "https://api.semanticscholar.org/graph/v1/paper/search"

HEADERS = {
    "User-Agent": "CitationFinder/1.0 (mailto:citation-finder@example.com)"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The workflow explicitly detects input language and routes searches across Chinese and English sources, while the description frames operation around Chinese or English only. This creates a locale/language constraint without an explicit user opt-in or a documented justification for excluding other languages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code sends the user-provided query to Baidu Scholar via a network request, which is a form of data transmission to a third party. Although the module docstring states the data sources, there is no explicit user disclosure, confirmation, or warning that search terms will be sent externally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The fallback search sends the query to CNKI over the network, exposing user-provided search terms to an external service. The code does not include an explicit warning, confirmation, or other user disclosure about this third-party transmission.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.