Back to skill

Security audit

Weread Digest

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed WeRead note summarizer and knowledge-base archiver, with local file changes gated by user configuration and confirmation.

Install this if you want local WeRead note analysis and optional archiving into an Obsidian or Markdown knowledge base. Before using archive mode, verify the configured knowledge-base path and review the proposed file changes before confirming; also make sure you trust the separate weread skill because this skill depends on its export scripts and Cookie setup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents the skill as a note-digest/summarization tool, but later functionality performs file and folder creation, updates indexes, and modifies an external knowledge base. This is a significant scope expansion because a user invoking a summarization skill may not expect broad filesystem writes outside the WeRead export directory.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims to operate purely as an AI processing layer over existing local exports, but its instructions also tell the agent to invoke external WeRead scripts to refresh data and query shelf information. That mismatch expands the capability from passive summarization into active data collection and script execution, which can surprise users and increase the attack surface if those dependent scripts are unsafe or misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The archive feature describes creating folders, writing markdown files, updating indexes, and potentially creating new directory structures, but the upfront skill description does not clearly warn that local files will be modified. That lack of prominent disclosure undermines informed consent and increases the risk of users triggering persistent changes without understanding the consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrase '入库' is extremely broad and likely to appear in normal conversation, which raises the chance of accidental activation of the archival workflow. In this skill, accidental activation is more dangerous because the archive feature can lead to local file creation and modification once configuration exists.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The design principles state that the skill does not make new API calls and only uses exported files, yet the workflows instruct running scripts for fresh exports and shelf retrieval. This contradiction weakens trust boundaries and can lead reviewers or users to underestimate that the skill may trigger networked or privileged operations through its dependencies.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.