Back to skill

Security audit

expert-writing-asmcp

Security checks for vulnerabilities and agentic risk

Overview

This AnyShare writing skill is mostly purpose-aligned, but it can upload documents, continue generation after inactivity, and create share links, so users should review it before installing.

Review before installing. Use only with documents you are comfortable uploading to AnyShare, use a least-privilege token, verify generated share links and access controls, and do not allow body generation or sharing to proceed without an explicit fresh confirmation. Avoid confidential materials until the timeout auto-proceed, background job handling, token argument exposure, and temporary-file handling are fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:91
Finding

Automatic Remote Processing Without Explicit User Confirmation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:141
Finding

Predictable Shared Temporary Files Store Sensitive Document Content

Content
View full analysis
/tmp/selection.txt nohup bash -c 'mcporter call ... selection:"$(cat /tmp/selection.txt)" skill_name:__大纲写作__1 times:1 --timeout 180000' & ``` Additional predictable files are used throughout the workflow, including: ```text /tmp/template_response.json /tmp/writing_query.txt /tmp/template_outline.json /tmp/verify_short_id.txt /tmp/writing_result.json /tmp/selection.txt ``` Generated outline and body documents are also written under fixed `/tmp` names later in `SKILL.md`. ### Technical Analysis The workflow stores source-derived and generated content under static names in the system-wide temporary directory. It does not: - Create a private temporary directory. - Set a restrictive `umask`. - Verify file ownership or reject symbolic links. - Create files atomically. - Remove temporary files when processing finishes. - Isolate concurrent Skill executions. Shell redirection follows existing filesystem objects. Depending on operating-system hardening, permissions, and the relationship between local users, an attacker may be able to pre-create a file or symbolic link, induce collisions, redirect writes, or read files created with permissive default modes. Even without an active attacker, concurrent executions can overwrite each other's temporary state and cause one user's outline or result to be processed in another task. ### Attack Path 1. An attacker with local access predicts the fixed temporary filename, such as `/tmp/selection.txt`. 2. Before the Skill writes the file, the attacker creates a conflicting file or symbolic link, where permitted by local filesystem protections. 3. The Skill writes outline content through shell redirection without validating t ...[truncated 1181 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:685
Finding

AnyShare Access Token Passed Through Command-Line Arguments

Content
View full analysis
/tmp/writing_result.json 2>&1 & ``` The same `access_token="$ACCESS_TOKEN"` pattern is used in multiple other `mcporter` calls, including directory creation, file upload, upload completion, and sharing-link generation. ### Technical Analysis Although the project directs users to store the bearer token in the MCP configuration, its execution examples also pass that token as a command-line argument. Command-line arguments may be exposed through: - Process-inspection utilities. - `/proc//cmdline` where local policy permits access. - Process monitoring or diagnostic agents. - Shell debugging and command auditing. - Error reports that capture invoked command arguments. The `nohup` body-generation command is particularly exposed because it is expected to run for several minutes, increasing the observation window. Whether unrelated local users can read the process arguments depends on the operating system and process-isolation configuration, but processes and monitoring tools operating under the same account commonly can. This also conflicts with `SECURITY.md:43-44`, which states that the tool should automatically inject the token rather than expose it through ordinary output or invocation data. ### Attack Path 1. A user configures a valid AnyShare bearer token. 2. The Skill starts the long-running `nohup mcporter` process with the token embedded in its argument vector. 3. A mal ...[truncated 1041 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (29)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 7)May include surrounding context.

md
| 信息类型 | 示例 | 风险等级 | 处理方式 |
|---------|------|---------|---------|
| Access Token | `ory_at_xxx...` | 🔴 高 | 仅存 mcporter 配置,禁止硬编码 |
| 文档库 GNS | `gns://FC1B4FE2...` | 🟡 中 | 可公开,不含内容 |
| 用户上传的参考资料 | 项目文档/报告等 | 🔴 高 | 仅在全文写作流程中使用,不外传 |
| AI 生成内容 | 大纲/正文 | 🟡 中 | 保存到用户指定目录,不公开发布 |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 17)May include surrounding context.

md
| 信息类型 | 示例 | 风险等级 | 处理方式 |
|---------|------|---------|---------|
| Access Token | `ory_at_xxx...` | 🔴 高 | 仅存 mcporter 配置,禁止硬编码 |
| 文档库 GNS | `gns://FC1B4FE2...` | 🟡 中 | 可公开,不含内容 |
| 用户上传的参考资料 | 项目文档/报告等 | 🔴 高 | 仅在全文写作流程中使用,不外传 |
| AI 生成内容 | 大纲/正文 | 🟡 中 | 保存到用户指定目录,不公开发布 |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY.md (reported line 54)May include surrounding context.

md
| 信息类型 | 示例 | 风险等级 | 处理方式 |
|---------|------|---------|---------|
| Access Token | `ory_at_xxx...` | 🔴 高 | 仅存 mcporter 配置,禁止硬编码 |
| 文档库 GNS | `gns://FC1B4FE2...` | 🟡 中 | 可公开,不含内容 |
| 用户上传的参考资料 | 项目文档/报告等 | 🔴 高 | 仅在全文写作流程中使用,不外传 |
| AI 生成内容 | 大纲/正文 | 🟡 中 | 保存到用户指定目录,不公开发布 |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
| 信息类型 | 示例 | 风险等级 | 处理方式 |
|---------|------|---------|---------|
| Access Token | `ory_at_xxx...` | 🔴 高 | 仅存 mcporter 配置,禁止硬编码 |
| 文档库 GNS | `gns://FC1B4FE2...` | 🟡 中 | 可公开,不含内容 |
| 用户上传的参考资料 | 项目文档/报告等 | 🔴 高 | 仅在全文写作流程中使用,不外传 |
| AI 生成内容 | 大纲/正文 | 🟡 中 | 保存到用户指定目录,不公开发布 |

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented workflow authorizes automatic progression to full document generation after 5 minutes of silence, without requiring explicit approval for the resulting write/upload actions. Because the skill handles uploaded source material and persists generated outputs, silence being treated as consent can directly cause unauthorized processing of sensitive content.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 421)May include surrounding context.

md
REV=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['rev'])")

# 上传文件
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
    --data-binary @"文件路径" "$URL"

# 确认上传

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 574)May include surrounding context.

bash
echo "📄 获取内置写作模板..."
curl -s -X GET \
  "https://anyshare.aishu.cn/api/intelli-search/v1/skills/templates/default?skill_name=__全文写作__3" \
  -H "authorization: $ACCESS_TOKEN" \
  -H "content-type: application/json" > /tmp/template_response.json

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 650)May include surrounding context.

md
AUTH=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][2])")
DATE=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][4])")

curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
    --data-binary @/tmp/大纲.md "$URL"

mcporter call anyshare-asmcp.file_osendupload \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 731)May include surrounding context.

md
DATE=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][4])")
FULL_GNS=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['docid'])")

curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
    --data-binary @/tmp/正文.md "$URL"

mcporter call anyshare-asmcp.file_osendupload \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Triggers like 帮我写作 and 基于资料写作 are broad enough to match ordinary writing requests, increasing the chance the skill activates unexpectedly. In this skill's context, activation can lead to file upload, external API calls, document generation, and sharing operations, so overbroad triggering increases the risk of unintended data handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill defines contradictory approval rules: it says explicit user confirmation is required before generating the body, but also says to auto-proceed after 5 minutes of silence. This ambiguity can cause the agent to perform costly or sensitive actions without valid consent, especially because later steps upload and generate documents from user data.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly instructs the agent to proceed after a timeout even without explicit approval. That bypasses a normal human-in-the-loop safety boundary and is especially risky here because the downstream actions involve document creation and external service interaction.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

Using nohup backgrounds a long-running action so it persists beyond the interactive session. In this skill, that matters because it can continue processing and transmitting user data after the user is no longer actively supervising the workflow.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

python3 -c "import json; print(json.load(open('/tmp/template_outline.json')).get('document_content',''))" > /tmp/selection.txt

通过文件传递

nohup bash -c 'mcporter call ... selection:"$(cat /tmp/selection.txt)" skill_name:__大纲写作__1 times:1 --timeout 180000' &

text

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The usage flow shows file upload, external processing, persistent storage, and share-link creation, but does not prominently warn users about data transmission and the implications of creating a shareable link. In a document-writing skill, this omission materially increases privacy and confidentiality risk for sensitive project files.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

This backgrounded smart_assistant call enables continued body generation outside the normal interaction loop. Combined with the timeout/auto-proceed logic, it reduces user control and can allow unauthorized or unnoticed processing to continue.

Content

Scanner excerpt · SKILL.md (reported line 335)May include surrounding context.

md
SHORT_ID=$(cat /tmp/verify_short_id.txt)
OUTLINE=$(python3 -c "import json; print(json.load(open('/tmp/template_outline.json')).get('document_content',''))")

nohup mcporter call anyshare-asmcp.smart_assistant \
    bot_id:smart_assistant \
    query:"基于以下大纲,撰写完整的可行性研究报告正文内容" \
    selection:"$OUTLINE" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This step uploads user-supplied files to an external AnyShare endpoint via curl --data-binary, which is a real external data transmission path. In context, uploading is part of the intended function, but it is still security-relevant because sensitive local content may be transferred off-host and persisted remotely.

Content

Scanner excerpt · SKILL.md (reported line 421)May include surrounding context.

md
REV=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['rev'])")

# 上传文件
curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
    --data-binary @"文件路径" "$URL"

# 确认上传

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The phase-2 example performs actual external upload of local files to a remote service. Although this is expected functionality, it remains a genuine data-exfiltration surface if the skill is triggered unintentionally or used with confidential documents.

Content

Scanner excerpt · SKILL.md (reported line 550)May include surrounding context.

md
REV=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['rev'])")

    # 上传
    curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
        --data-binary @"$FILE" "$URL"

    # 确认

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The generated outline is uploaded to the external service, extending the transmission scope beyond source files to derived content that may summarize sensitive materials. This increases exposure because synthesized documents can still contain confidential information.

Content

Scanner excerpt · SKILL.md (reported line 650)May include surrounding context.

md
AUTH=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][2])")
DATE=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][4])")

curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
    --data-binary @/tmp/大纲.md "$URL"

mcporter call anyshare-asmcp.file_osendupload \

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The later phase-5 nohup example again detaches sensitive content generation from the user session. In this context, persistence is more dangerous because it processes full outline content and writes results to temporary files and remote storage.

Content

Scanner excerpt · SKILL.md (reported line 685)May include surrounding context.

md
python3 -c "import json; print(json.load(open('/tmp/template_outline.json')).get('document_content',''))" > /tmp/selection.txt

# 后台执行,避免60秒超时
nohup mcporter call anyshare-asmcp.smart_assistant \
    access_token="$ACCESS_TOKEN" \
    bot_id:smart_assistant \
    query:"基于以下大纲,撰写完整的可行性研究报告正文内容" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The generated final document is uploaded externally, creating another real transmission point for potentially sensitive content. Because this occurs late in an automated workflow, users may overlook that the full output is being stored remotely.

Content

Scanner excerpt · SKILL.md (reported line 731)May include surrounding context.

md
DATE=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['authrequest'][4])")
FULL_GNS=$(echo "$UPLOAD" | python3 -c "import sys,json; print(json.load(sys.stdin)['docid'])")

curl -X PUT -H "$AUTH" -H "Content-Type: application/octet-stream" -H "$DATE" \
    --data-binary @/tmp/正文.md "$URL"

mcporter call anyshare-asmcp.file_osendupload \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The troubleshooting guide instructs users to directly edit a file containing an Authorization token and restart the daemon, but provides no warning about protecting the credential, avoiding accidental disclosure, or using safer secret-handling mechanisms. In an agent-skill context, operational docs are often copied verbatim by users or automation, so normalizing plaintext token handling increases the chance of credential leakage through logs, screenshots, version control, backups, or overbroad file permissions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

该索引在关键词表中将“总结”和“调研”等常见日常词语直接作为模板匹配触发词,且未提供排除条件或更具体的约束。对于基于自然语言描述自动选模板的技能,这类高频通用词容易与普通写作请求混淆,造成意外调用错误模板。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

文档说明技能会根据“描述的场景”自动读取对应模板文件,并给出“写个融资用的计划书”这类示例,但没有说明匹配优先级、歧义处理方式或不触发条件。这会让技能在用户未明确指定模板时依据宽泛场景词自行激活,存在误判风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The template explicitly guides use of questionnaires, interviews, and focus groups, which commonly involve collection of personal or sensitive information. Because it provides no privacy notice, consent, minimization, retention, or lawful-processing guidance, users may conduct research in a way that violates privacy requirements or exposes respondent data through overcollection or improper handling.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.generated_source_template_injection

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SECURITY.md:37

User-controlled placeholder is embedded directly into generated source code.

Critical
Code
suspicious.generated_source_template_injection
Location
SKILL.md:592