Back to skill

Security audit

Bearblog

Security checks for vulnerabilities and agentic risk

Overview

The skill is for Bear Blog post management, but its examples include unsafe authenticated browser automation that can publish, unpublish, and delete posts without clear user confirmation.

Install only if you are comfortable letting the agent operate an authenticated Bear Blog browser session. Review content, target post, slug, and visibility yourself before publishing or unpublishing, and do not use the documented confirmation-bypass deletion flow without a separate explicit confirmation and backup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation expands from blog post management into full account login automation, including credential entry and reliance on persistent session cookies. This increases the skill's authority and attack surface by enabling account access workflows that are broader than the stated purpose and could be misused to take over or operate a user's publishing account.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents arbitrary browser-side JavaScript evaluation to read and modify page state, which is more powerful than necessary for ordinary post editing. Exposing evaluate-based DOM/script execution makes it easier to perform unintended actions, scrape broader account data, or bypass normal tool safety constraints.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Overriding window.confirm to force deletion bypasses an explicit user-safety control built into the application. This makes destructive actions easier to trigger accidentally or programmatically and removes an important last-chance barrier against irreversible content loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The publish action is a state-changing operation that can make content public, but the documentation presents it as a routine click without any warning, confirmation, or review step. In an agent context, this raises the risk of unintended publication of drafts, sensitive text, or incomplete content.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The delete workflow not only performs a destructive action but also suppresses the site's confirmation mechanism, with no compensating safety guidance. In a browser automation skill, this materially increases the chance of irreversible deletion from a mistaken target selection or malicious prompting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

Unpublish changes public visibility and can affect availability, readers, and linked content, yet the documentation gives no warning that this is a user-visible state change. While less severe than deletion, it still creates avoidable operational risk in an automation context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow instructs the operator to enter account credentials directly into the browser tool and then proceed with authenticated actions, but it does not warn about sensitive credential handling, secret exposure in logs, or the risks of using persistent session cookies. In an agent setting, this can lead to accidental disclosure of credentials or unintended authenticated actions if outputs, traces, or session state are reused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The publish step performs a real remote state-changing action by creating or publishing a live blog post, yet the workflow presents it as a routine step without an explicit confirmation or warning about irreversibility and production impact. In an agent-assisted workflow, this increases the chance of accidental publication, unintended content disclosure, or unauthorized modification of the user's site.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.