Back to skill

Security audit

Read Later Pro

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a read-later tool, but it asks for broad URL, file, and credential-related workflows with weak scoping and some unsafe or unsupported behavior.

Review this carefully before installing. Use it only with URLs and files you trust, avoid giving service passwords or tokens until credential handling is clarified, do not rely on the advertised unsupported features, and be aware that saved library data is written under your home directory and deletions are irreversible from the tool.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract_article.py:22
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/convert_format.py:11
Finding

Unescaped Markdown and Metadata Allow Active-Content Injection in Generated Documents

Content
View full analysis
{title} body {{ font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif; max-width: 800px; margin: 0 auto; padding: 40px 20px; line-height: 1.6; color: #333; }} h1 {{ color: #222; border-bottom: 2px solid #eee; padding-bottom: 10px; }} h2 {{ color: #444; margin-top: 30px; }} p {{ margin: 15px 0; }} a {{ color: #0066cc; }} img {{ max-width: 100%; height: auto; }} blockquote {{ border-left: 4px solid #ddd; margin: 0; padding-left: 20px; color: #666; }} code {{ background: #f4f4f4; padding: 2px 6px; border-radius: 3px; font-family: monospace; }} pre {{ background: #f4f4f4; padding: 15px; overflow-x: auto; border-radius: 5px; }} """ # Simple markdown to HTML conversion content = markdown_content # Headers content = re.sub(r'^### (.+)$', r'

\1

', content, flags=re.MULTILINE) content = re.sub(r'^## (.+)$', r'

\1

', content, flags=re.MULTILINE) content = re.sub(r'^# (.+)$', r'

\1

', content, flags=re.MULTILINE) # Bold and italic content = re.sub(r'\*\*\*(.+?)\*\*\*', r'\1', content) content = re.sub(r'\*\*(.+?)\*\*', r'\1', content) content = re.sub(r'\*(.+?)\*', r'\1', content) # Links content = re.sub(r'\[([^\]]+)\]\(([^)]+)\)', r'\1', content) # Code blocks content = re.sub(r'```(.+?)```', r'
text
\1
', content, flags=re.DOTALL) content = re.sub(r'`(.+?)`', r'\1', ...[truncated 2877 chars]
Remediation
View remediation
` elements, event-handler attributes, title-element termination, `javascript:` links, malformed attributes, and SVG-based active content. 10. For EPUB output, generate a standards-compliant EPUB archive and sanitize every XHTML resource included in it. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior and the detected capabilities do not align: the skill claims extensive offline storage, export, organization, and sync features, while analysis indicates those functions are not actually implemented and that outbound network access occurs without declared permissions. This mismatch is dangerous because users may trust the skill with URLs, files, or credentials under false assumptions about what it does, masking unexpected data transmission or incomplete processing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises capabilities that require network, file read, and file write behavior, but it declares no explicit tool scope or permissions. This creates a trust and review gap: an agent or reviewer cannot easily determine what external access the skill will need, increasing the chance of unintended data access or exfiltration through URL fetching, local article storage, and import operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'use when' scope is so broad that the skill may be invoked for many generic reading, note-taking, or organization requests, increasing the chance of unnecessary network fetches, file writes, or credential-handling workflows. Over-broad routing is a security concern because it expands the situations in which the skill can access sensitive URLs, local content, or third-party integrations without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation instructs users to provide service credentials and fetch remote URLs but does not warn that these actions transmit data to external services and may store sensitive tokens or imported content locally. In a skill that handles article retrieval and third-party imports, missing disclosure materially increases the risk of users exposing credentials, private reading history, or sensitive URLs without informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Advertising a '--full-content' option to attempt paywall bypass introduces a capability unrelated to a normal read-later workflow and signals intentional circumvention of publisher access controls. Even if experimental, this increases legal, policy, and abuse risk and could encourage the skill to retrieve content in ways users and platform owners do not expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delete command performs a destructive operation by invoking article deletion and then only reports success after the fact. There is no confirmation prompt, pre-deletion warning, or other user disclosure in the CLI flow before data is permanently removed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.