Back to skill

Security audit

百度网盘官方 skill

Security checks for vulnerabilities and agentic risk

Overview

The skill largely matches its Baidu Drive purpose, but its install, update, uninstall, and memory-restore paths have review-worthy risks around network-supplied code and persistent agent files.

Install only if you are comfortable giving the skill access to your Baidu Drive account and to local agent memory files. Review install/update prompts carefully, avoid --yes for uninstall or update, do not use it in untrusted environments, and treat restored memory backups or generated share links as sensitive.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/update.sh:126
Finding

Remotely Controlled Skill Package Can Replace Audited Skill Code

Content
View full analysis
/dev/null; then curl -fsSL -o "$zip_path" "$remote_url" || { log_error "下载 Skill 更新包失败" return 1 } elif command -v wget &> /dev/null; then wget -q -O "$zip_path" "$remote_url" || { log_error "下载 Skill 更新包失败" return 1 } fi # SHA256 完整性校验(强制) local checksum=$(query_get "$SKILLS_INFO" "checksum") if [ -z "$checksum" ]; then log_error "配置接口未提供 checksum,无法验证更新包完整性,拒绝更新" return 1 fi local actual="" if command -v sha256sum &> /dev/null; then actual=$(sha256sum "$zip_path" | awk '{print $1}') elif command -v shasum &> /dev/null; then actual=$(shasum -a 256 "$zip_path" | awk '{print $1}') else log_error "未找到 sha256sum/shasum 工具,无法验证更新包完整性" return 1 fi if [ "$actual" != "$checksum" ]; then log_error "SHA256 校验失败!文件可能被篡改" log_error " 期望: ${checksum}" log_error " 实际: ${actual}" return 1 fi log_info "SHA256 校验通过" # 解压覆盖 log_info "正在解压更新..." if command -v unzip &> /dev/null; then unzip -qo "$zip_path" -d "$SKILL_DIR" || { log_error "解压失败" return 1 } else log_error "未找到 unzip 工具" return 1 fi } ``` ### Technical Analysis The update metadata obtained from ...[truncated 1928 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:199
Finding

Downloaded Installer Executes When Integrity Verification Is Unavailable

Content
View full analysis
/dev/null; then actual_checksum=$(sha256sum "${installer_name}" | awk '{print $1}') elif command -v shasum &> /dev/null; then actual_checksum=$(shasum -a 256 "${installer_name}" | awk '{print $1}') else log_warn "未找到 sha256sum/shasum 工具,跳过完整性校验" fi if [ -n "$actual_checksum" ]; then if [ "$actual_checksum" != "$expected_checksum" ]; then log_error "SHA256 校验失败!文件可能被篡改" log_error " 期望: ${expected_checksum}" log_error " 实际: ${actual_checksum}" rm -f "${installer_name}" exit 1 fi log_info "SHA256 校验通过" fi else log_warn "当前平台 ${platform_key} 无预置校验值,跳过完整性校验" fi # 执行安装器(非交互模式) ./${installer_name} --yes ``` ### Technical Analysis The installer is downloaded from the network and then executed locally. Verification fails open in two cases: - Neither `sha256sum` nor `shasum` is installed. - `get_checksum` has no checksum for the detected platform. The platform detector recognizes Windows environments, but `get_checksum` contains entries only for Darwin and Linux. A Windows installer can therefore reach execution without a pinned digest. Linux and macOS also skip verification if no supported hashing utility is available. HTTPS offers transport protection but does not replace artifact authentication if the CDN, release account, proxy trust store, DNS environment, or delivery infrastructure is compromised. ### Attack Path 1. The installation runs on a platform without a configured checksum or without `sha256su ...[truncated 782 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
scripts/memory-backup.sh:673
Finding

Unauthenticated Memory Backups Can Poison Persistent Agent Control Files

Content
View full analysis
/dev/null 2>&1 || { echo "无法下载 manifest.json,请检查备份路径是否正确。" >&2 exit 1 } read_manifest "$manifest_tmp" || { echo "Invalid manifest" >&2; exit 1; } # 兼容性检查 local compat_warnings if ! compat_warnings=$(validate_compatibility "$manifest_tmp" "$AGENT_NAME" "$MEMORY_SYSTEM_NAME" 2>/dev/null); then if [ "$force" != "true" ]; then if echo "$compat_warnings" | grep -q "Agent mismatch"; then echo "兼容性警告:备份来自 \"$MANIFEST_AGENT\",当前环境是 \"$AGENT_NAME\"" >&2 echo "不同 Agent 类型的记忆文件可能存在兼容性问题" >&2 else echo "兼容性校验失败:" >&2 while IFS= read -r w; do echo " $w" >&2 done <<< "$compat_warnings" fi echo "" >&2 echo "使用 --force 跳过此警告并强制恢复" >&2 exit 1 else echo "兼容性警告(已通过 --force 跳过):" while IFS= read -r w; do echo " $w" done <<< "$compat_warnings" fi fi # Safety net: 恢复前备份当前本地记忆 local safety_timestamp safety_timestamp=$(date +"%Y-%m-%dT%H-%M-%S") local safety_dir="$WORKSPACE_DIR/.backup-before-restore/$safety_timestamp" mkdir -p "$safety_dir" if [ -d "$MEMORY_DIR" ]; then cp -r "$MEMORY_DIR" "$safety_dir/memory" 2>/dev/null || true fi for wf in "${WORKSPACE_FILES[@]}"; do local wp="$WORKSPACE_DIR/$wf" if [ -f "$wp" ]; then cp "$wp" "$safety_dir/$wf" 2>/dev/null || true fi done echo "已备份当前记忆到 $safety_dir" # 下载所有备份文件 local total=${#MANIFEST_FILES[@]} echo "" echo "开始恢复,共 ${total} 个文件..." local i local failed_files=() for ((i = 0; i < total; i++)); do local file="${MANIFEST_FILES[$i]}" local local_tmp="$tmp_dir/$file" mkdir -p "$(dirname "$local_tmp")" if ! _bdpan_download "${backup ...[truncated 2040 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/uninstall.sh:46
Finding

Environment-Controlled Configuration Path Enables Arbitrary Recursive Deletion

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill explicitly permits installation and update flows that download and execute remote code, and it even notes that install.sh lacks local SHA256 verification and relies only on HTTPS. That creates a supply-chain risk: if the remote source, transport, or upstream package is compromised, the agent could execute attacker-controlled code on the local system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill explicitly permits installation and update flows that download and execute remote code, and it even notes that install.sh lacks local SHA256 verification and relies only on HTTPS. That creates a supply-chain risk: if the remote source, transport, or upstream package is compromised, the agent could execute attacker-controlled code on the local system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly permits installation and update flows that download and execute remote code, and it even notes that install.sh lacks local SHA256 verification and relies only on HTTPS. That creates a supply-chain risk: if the remote source, transport, or upstream package is compromised, the agent could execute attacker-controlled code on the local system.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly permits installation and update flows that download and execute remote code, and it even notes that install.sh lacks local SHA256 verification and relies only on HTTPS. That creates a supply-chain risk: if the remote source, transport, or upstream package is compromised, the agent could execute attacker-controlled code on the local system.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The cleanup command interpolates a PID into an rm path template, and the skill does not define strict validation for that value in this document. If the PID or derived filename were malformed, attacker-influenced, or mismatched with the actual created log path, the agent could delete unintended files under /tmp or another expanded path in downstream implementations.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

bash
# 3. 下载完成后清理日志
rm -f /tmp/bdpan-dl-<PID>.log

Agent 执行大文件后台下载时的行为规范:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · reference/bdpan-commands.md (reported line 476)May include surrounding context.

md
|------|------|
| `--config-path <path>` | 指定配置文件完整路径(适用于 AI Agent 集成) |
| `--json` | JSON 格式输出 |
| `--no-check-update` | 禁用版本更新检查 |
| `--help` | 显示帮助 |
| `--version` | 显示版本 |

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · reference/bdpan-commands.md (reported line 639)May include surrounding context.

md
import subprocess
import os

env = os.environ.copy()
env["BDPAN_CONFIG_PATH"] = "/home/user/.config/bdpan/config.json"

result = subprocess.run(

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · reference/examples.md (reported line 336)May include surrounding context.

bdpan upload "/tmp/${BACKUP_FILE}" "backup/${BACKUP_FILE}"

清理

rm "/tmp/${BACKUP_FILE}"

echo "备份完成: ${BACKUP_FILE}"

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The guide instructs unconditional deletion of ~/.config/bdpan/config.json, which modifies user state and may destroy stored configuration or credentials without backup or verification. In an agent context, destructive file operations are more dangerous because users may follow them verbatim, and a malformed environment or symlink could cause unintended effects.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 61)May include surrounding context.

解决方案:

bash
# 清除配置并重试
rm ~/.config/bdpan/config.json
bash ${CLAUDE_SKILL_DIR}/scripts/login.sh

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The troubleshooting step unconditionally deletes ~/.local/bin/bdpan, which is a destructive filesystem action and could remove the wrong file if the path is unexpected or replaced. While intended for reinstall, agent-delivered instructions that invoke rm on executable paths are riskier because they change the user's environment and can be misapplied without validation.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 258)May include surrounding context.

解决方案:

bash
# 删除现有二进制文件
rm ~/.local/bin/bdpan

# 重新安装
bash ${CLAUDE_SKILL_DIR}/scripts/install.sh

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

Using nohup to launch long-running downloads creates persistent background processes outside the normal agent execution window. In an agent context, that weakens containment and auditability: a started process may continue consuming bandwidth, writing files, or acting on stale assumptions after the conversation state changes or the user revokes intent.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

大文件(> 50MB)后台下载流程:

bash
# 1. 启动后台下载(nohup + 进度日志)
nohup bdpan download <远端路径> <本地路径> > /tmp/bdpan-dl-$$.log 2>&1 & echo $!

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

This is the same underlying persistence issue: the skill instructs the agent to start a detached nohup download and then poll it later. In a security-sensitive assistant environment, detached jobs can outlive user expectations and make it harder to enforce revocation, quotas, or safe rollback.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

bash
# 1. 启动后台下载(nohup + 进度日志)
nohup bdpan download <远端路径> <本地路径> > /tmp/bdpan-dl-$$.log 2>&1 & echo $!
bash

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all operational and safety instructions only in Chinese, including login, logout, and security guidance. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation describes creation of Baidu Drive share links, including a permanent-share option, but does not warn that these links may expose files to anyone with the URL and extraction code. In an agent skill context, omission of this warning is risky because an automated workflow may generate public sharing links for sensitive files or memory backups without the user understanding the exposure.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference/bdpan-commands.md (reported line 580)May include surrounding context.

}

text

### mv/cp/rename/mkdir 命令输出

```json
{

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference/bdpan-commands.md (reported line 580)May include surrounding context.

}

text

### mv/cp/rename/mkdir 命令输出

```json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The upload/share examples show taking local files and immediately generating public share links without any disclosure that this exposes data outside the local environment. In an agent setting, users may not appreciate that a simple 'upload and share' flow can publish sensitive documents and create unintended external access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The download examples write remote content to local paths without warning that files may overwrite existing content or introduce untrusted data onto the user's machine. For an agent, this can lead to unsafe local side effects, especially if remote files are later opened or processed automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The transfer examples import content from external share links into the user's cloud storage without warning that the source may be untrusted, misleading, or contain unexpected files. This can cause persistence of malicious or sensitive content in the user's account and may trigger later unsafe handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The examples expand from simple Baidu Drive operations into general-purpose shell scripting, including loops, tar, and file deletion. In an agent-skill context, this broadens the operational scope and can normalize execution of arbitrary local shell commands, increasing the chance that an agent will perform unintended or unsafe actions on the host system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is written entirely in Chinese and provides operational instructions without any indication that the language choice is optional or limited to a China-specific compliance context. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 305)May include surrounding context.

安装所需依赖(特定于发行版):

bash
# Debian/Ubuntu
sudo apt-get install libc6

# Fedora/RHEL
sudo dnf install glibc

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 308)May include surrounding context.

安装所需依赖(特定于发行版):

bash
# Debian/Ubuntu
sudo apt-get install libc6

# Fedora/RHEL
sudo dnf install glibc

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 349)May include surrounding context.

bash
# 检查配置文件是否存在及权限
ls -la ~/.config/bdpan/

# 检查登录状态和 Token 有效期
bdpan whoami

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script’s comments, prompts, warnings, and help output are written in Chinese, and all user-facing interaction later in the file assumes the user can read Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.