Back to skill

Security audit

Paper Results Reverse Engineer

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate paper-analysis purpose, but it gives agents under-scoped local command and file-handling instructions for PDFs and temporary outputs.

Review before installing. Use this skill only when you are comfortable letting the agent read selected papers and write analysis files locally. Avoid giving arbitrary filesystem paths; prefer uploaded PDFs or pasted Results text. If PDF handling is enabled, require shell-free execution, per-run private temp files, sanitized filenames, and confirmation before cleanup or deletion.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/prompt-templates.md:116
Finding

Command Injection Through Unsanitized PDF Path Interpolation

Content
View full analysis
/tmp/paper_extracted.txt` 2. If `pdftotext` returns empty/garbled (scanned PDF), tell user to provide a text-selectable PDF or paste Results text manually 3. Scan extracted text for `Results` / `Results and Discussion` / `结果` heading 4. Extract from that heading to the next major heading (`Discussion`, `4.`, `References`, etc.) 5. Print the detected Results section summary so the user can confirm 6. Proceed to Modules A–G **PDF input types handled:** - `.pdf` file attachment in webchat/desktop - Any local path to a PDF on the user's machine - If the PDF is on the user's machine (not uploaded), use `read` to find the path then `exec` with `pdftotext` ``` The expected executable form is reinforced in `tests/test-case-5.md`, lines 17–23: ```markdown ### Step 1: Extract text from the PDF Agent runs: ```bash pdftotext -layout "" /tmp/paper_extracted.txt ``` If successful, reads `/tmp/paper_extracted.txt`. ``` ### Technical Analysis The Skill explicitly instructs the Agent to pass a user-supplied or locally discovered PDF path to `exec`. It does not require argument-array execution, shell avoidance, path canonicalization, upload-root containment, or filename validation. If the implementation constructs a shell command by replacing `` with the supplied path, shell metacharacters or command-substitution syntax embedded in that path may be evaluated. Enclosing the interpolated path in double quotes does not neutralize shell substitutions such as `$()` or backticks when the resulting text is parsed by a shell. The issue is particularly significant because the Skill accepts both uploade ...[truncated 1350 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/prompt-templates.md:116
Finding

Predictable Shared Temporary File for Extracted PDF Content

Content
View full analysis
/tmp/paper_extracted.txt` 2. If `pdftotext` returns empty/garbled (scanned PDF), tell user to provide a text-selectable PDF or paste Results text manually ``` The same fixed path is prescribed in `tests/test-case-5.md`, lines 17–23: ```markdown ### Step 1: Extract text from the PDF Agent runs: ```bash pdftotext -layout "" /tmp/paper_extracted.txt ``` If successful, reads `/tmp/paper_extracted.txt`. ``` ### Technical Analysis Every PDF extraction writes to the globally predictable path `/tmp/paper_extracted.txt`. The workflow does not require: - Exclusive temporary-file creation. - A per-run private directory. - Restrictive permissions. - Symlink rejection. - Ownership validation. - Atomic file handling. - Guaranteed cleanup. On a multi-user or concurrent system, different Skill runs can overwrite the same file or read content produced by another run. Depending on operating-system protections and `pdftotext` file-opening behavior, a local attacker may also attempt a symlink or race-condition attack against the predictable target. Because extracted papers may contain unpublished or otherwise sensitive material, cross-run disclosure is security-relevant even without code execution. ### Attack Path 1. A local attacker or concurrent process predicts the fixed `/tmp/paper_extracted.txt` path. 2. The attacker pre-creates the path, substitutes a link where permitted, or repeatedly replaces it during extraction. 3. The Agent invokes `pdftotext`, which writes to the shared target. 4. The Agent subsequently reads the same predictable path without validating ownership or file iden ...[truncated 920 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
docs/execution-constraints.md:27
Finding

Metadata-Derived Paths Are Used for Temporary Writes and Cleanup Without Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (51)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · docs/module-h-spec.md (reported line 85)May include surrounding context.

md
- Whether Source Ledger is needed: yes / no
- Whether design-incompatible handling is needed: yes / no

## Output Rules

- Module H: 1–2 pages max (unless user requests full bridge).
- Do NOT copy target paper's original sentences — abstract function labels only.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template instructs the agent to run a local shell command (pdftotext) against user-supplied PDF paths, including paths on the user's machine. That creates a clear capability escalation from text analysis to local file access and command execution, which can expose sensitive local files or be adapted into broader command/path abuse depending on the agent runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file states that both README.md and SKILL.md were fully localized to Chinese, but provides no indication that users can choose another language or that the locale restriction is region-specific. Under the language/locale policy rule, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description, usage scenarios, trigger examples, and recommended prompts are written entirely in Chinese, which implies operation in a specific language. There is no opt-in, alternative language option, or stated reason that the skill must be Chinese-only, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The 'When to Use' section says to activate on open-ended requests such as '这张图怎么讲', writing-strategy extraction, PPT scripts, and statistical reporting checks. These phrases can arise in many ordinary conversations and the file does not provide exclusion conditions or negative examples to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill mandates a file-first output model but does not clearly warn users that local files and possibly intermediate artifacts will be created. This weakens informed consent and can expose sensitive research content on disk where other local users, backups, sync tools, or unrelated software may access it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs processing uploaded PDFs with pdftotext, which expands the skill from pure text analysis into invoking an external tool on user-supplied files. External document parsers increase attack surface and can introduce local command/file-handling risks if the runtime actually honors such instructions, especially when combined with automatic workflow behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's declared purpose is paper-results analysis, but it also directs creation of Markdown outputs and temporary files under Desktop paths. Writing user-derived content to predictable local locations creates unintended data persistence and privacy exposure, especially for unpublished manuscripts, copyrighted PDFs, or sensitive research materials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented output and temp-file layout normalizes storing analysis artifacts on disk without an explicit caution about persistence. Because the skill handles paper content, figures, and excerpts, this can leak confidential or proprietary research data through residual files, predictable paths, and incomplete cleanup.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document says the branch is 'Activated when Axis 1 = Survey / Correlational study' and then adds a separate 'When' condition for cross-sectional mediation, but it does not clearly define the full trigger scope, boundaries, or non-matching cases. Because this is a markdown file and the activation language is broad, a user or orchestrator may be unclear when Branch B applies versus when other branches or subrules should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Mandating the label '统计间接效应' without user language opt-in can cause unauthorized language switching in model output, which may break downstream pipelines, violate user expectations, or be abused as an instruction-level output-shaping mechanism. In an agent skill that may feed structured academic analysis into other tools or user workflows, forced language changes increase the risk of misinterpretation and degraded interoperability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Requiring specific Chinese warning phrases such as '可能' and '⚠️ 模板文本污染' without offering language choice can force output into an unexpected language and format. In this skill context, that is more dangerous because the content is intended for analytical writeups and possibly chaining into another academic-writing skill, so rigid language injection can corrupt consistency, confuse recipients, or interfere with parsing and quality control.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · docs/branch-g-meta-analysis.md (reported line 23)May include surrounding context.

md
Before comparing post-test and follow-up effects: check whether study sets are the same, whether follow-up k is substantially smaller, whether statistical power is lower, whether attrition bias exists, whether heterogeneity differs.

**Prohibited:** "effect decayed from d=0.34 to d=0.22" or "SWB effect more durable than depression effect" without checking k/N/study-set equivalence.

## G3: Results Heading Detection Rule

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file repeatedly prescribes Chinese-only wording for required and prohibited phrasing, such as the approved and banned expressions and mandatory labels. Because this guidance is framed as universal guardrails rather than a region-specific or opt-in locale setting, it forces a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions require the final merged file to use the specific H1 # 论文 Results 反向拆解, and later repeat this as a hard rule. This imposes a language/locale choice in natural-language output without user opt-in or an explicit justification that the skill is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs automatic deletion or moving of temporary phase files after a successful merge, but it does not require explicit user confirmation or a prominent warning before performing this potentially destructive action. In an agent setting, silent cleanup can cause unintended data loss, remove artifacts needed for audit/debugging, or overwrite the user's expectations about file retention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This line mandates that the final file has exactly one H1 and specifies it in Chinese, enforcing a language choice for generated content. Under the policy, locale or language constraints should either be optional for the user or clearly justified as part of a region-specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger conditions are partially defined with Chinese-language request phrases, but the document does not state that the skill is intentionally region- or language-specific, nor does it offer users an alternative language option. This can amount to a language/locale policy violation because activation appears to depend on a specific language without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad, colloquial requests such as '用于汇报' and '做 PPT' that can easily appear in ordinary user prompts without a clear request for this specific high-depth mode. That creates unintended activation risk, causing the agent to enter a more expansive workflow than the user asked for, which can increase cost, verbosity, and downstream tool/data exposure if other modules are chained automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example content strongly enforces Chinese as the default output language across the workflow, with no visible mechanism for preserving the user's requested language. This can override user intent, create unsafe misunderstandings in multilingual contexts, and cause incorrect or inaccessible outputs when the user, surrounding system, or downstream integration expects another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L85 contains a Chinese-only summary string and the file does not indicate that the skill is region-specific or that the user can choose the language. This creates a natural-language policy issue because it imposes a locale/language choice without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The quick-mode trigger phrases are broad colloquial requests such as '快速看一下这篇论文的 Results' and '大概拆一下', which can match casual user language without clearly signaling the reduced-analysis mode. This can cause the agent to enter a lighter workflow when the user did not explicitly consent to abbreviated analysis, increasing the risk of incomplete coverage, missed caveats, or mode confusion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are specified only in Chinese and the example output throughout the file is presented in Chinese, suggesting a language-specific experience. There is no visible indication that users may choose another language or opt in to this locale constraint.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.