Back to skill

Security audit

Get笔记·六步抄作业版

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Getnote knowledge-management workflow, but it also directs broad note collection, local memory reading, duplicate deletion, and Feishu sharing without enough scoping or approval controls.

Review this skill before installing. Use it only with tightly scoped Getnote and Feishu credentials, confirm the knowledge base and destination before writes, avoid the Cron workflow unless you explicitly want all knowledge bases and local memory included, and require a preview before deletion or external sharing.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:340
Finding

Local Agent Memory Is Aggregated and Exported to External Services

Content
View full analysis
--title "日志简报 YYYY-MM-DD | 张公子" --tag 日志简报` → write to `eYzMmvnm` | | Feishu document | Create a docx document, write the content, and synchronize its link to a Feishu group | | Feishu knowledge base | Create a corresponding node in the personal knowledge-base wiki | **Seventh step: Send completion notification** Send a notification through the Feishu group containing data statistics, a summary of core findings, and links to the three destinations. ``` ### Technical Analysis The cron workflow explicitly directs the Agent to read persistent local memory files and combine their contents with remote knowledge-base information. It then archives the aggregate report in Getnote and Feishu and distributes summaries and links through a Feishu group. The workflow does not require: - Explicit consent before accessing local memory. - Validation that the selected memory files are relevant to the requested task. - Detection or redaction of credentials, personal data, or confidential conversation context. - Verification of the Getnote or Feishu destination and recipients. - A preview and approval step before external publication. Persistent Agent memory can contain sensitive conversation context, operational information, personal data, internal URLs, or secret ...[truncated 1065 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:316
Finding

Cron Workflow Mandates Account-Wide Knowledge-Base Enumeration

Content
View full analysis
--all -o json` for every knowledge base, filtering notes for the target date. 2. **`getnote search` must supplement global search**: Using only `kb --all` searches specific knowledge bases, and notes may be distributed among different knowledge bases. The workflow must use `getnote search "YYYY-MM-DD" --limit 20 -o json` as a supplementary global search. 3. **Write the result to the "Get" knowledge base**: The final daily briefing is written to `eYzMmvnm`, with the output note tagged `日志简报`. ``` ```bash # First step: obtain all knowledge bases getnote kbs -o json # Second step: execute for every knowledge base getnote kb --all -o json # Third step: supplementary global search getnote search "YYYY-MM-DD" --limit 20 -o json ``` ### Technical Analysis The Skill declares one knowledge base, `eYzMmvnm`, as its default operating context. The cron instructions nevertheless mandate enumerating every knowledge base, downloading all notes from each one, and performing an additional global search. This violates least-privilege and purpose-limitation principles. A daily briefing does not inherently require complete account-wide access, and the instructions provide no knowledge-base allowlist, access-boundary check, sensitivity classification, or user confirmation before crossing repository boundaries. The global search also creates a second discovery path that may retrieve records outside the intended knowledge base. ### Attack Path 1. The cron workflow invokes ...[truncated 925 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:272
Finding

Unpinned Getnote CLI Is Installed Globally

Content
View full analysis
` or check environment variables | ``` ### Technical Analysis The recovery instruction installs the current registry version of `@getnote/cli` globally. It does not specify a reviewed version, integrity hash, lockfile, registry allowlist, package provenance requirement, or lifecycle-script policy. An npm installation may execute package lifecycle scripts during installation. A malicious, compromised, or unexpectedly changed package release can therefore execute code with the privileges of the user running the Agent. Global installation also modifies the user's shared executable environment and can affect unrelated sessions. The audit found no evidence that the named package itself is malicious. The vulnerability is the unsafe and non-reproducible installation procedure. ### Attack Path 1. The `getnote` executable is unavailable. 2. The Agent follows the documented recovery procedure. 3. npm resolves the latest available `@getnote/cli` release from its configured registry. 4. Package code or lifecycle scripts execute during installation. 5. If the resolved release or registry path has been compromised, attacker-controlled code executes with the installing user's privileges. 6. The package remains globally available and may be invoked in future workflows. ### Impact Assessment A compromised dependency could read or modify files accessible to the Agent user, access environment variables such as Getnote credentials, make network requests, or install persistent user-level artifacts. The scope is the local user environment in which the global npm installation occurs. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:92
Finding

User-Controlled Values Are Interpolated into Shell Command Templates

Content
View full analysis
--desc ``` ```text Help me create a "Content Material Library" knowledge base for "collecting cases, data, and viewpoints used in content production." ``` ```bash getnote kb create Content Material Library --desc Collect cases, data, and viewpoints used in content production ``` ```bash # Save a URL, text, or image path getnote save --tag -o json ``` Other affected command templates include: ```bash getnote tag add getnote search "" --kb --limit -o json getnote save "" --title "" --tag AI,沉淀 -o json ``` ### Technical Analysis Knowledge-base names, descriptions, URLs, note text, image paths, tags, note identifiers, search terms, titles, and limits can originate from user input or retrieved note content. The Skill presents these values as substitutions in shell command strings but does not require: - Execution through a no-shell argument-array API. - Correct escaping for the active shell. - Strict validation of identifiers and numeric values. - Constraints on URL schemes or local file paths. - Length and character restrictions for titles, tags, and search terms. Quoting selected placeholders is not a complete defense when a command is assembled as a shell string. Embedded quotes, command substitutions, separators, redirections, or newline characters may terminate the intended argument and introduce additional shell operations. ### Attack Path 1. An attacker supplies a crafted knowledge-base name, description, title, tag, search term, URL, or p ...[truncated 986 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs deletion of duplicate notes while presenting it as a normal cleanup rule, but it does not require warning, review, or confirmation. Destructive actions based on title/source heuristics can permanently remove valid records, provenance, or the wrong note, causing data loss and integrity issues.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Cron section materially expands the skill from Getnote knowledge management into unrelated capabilities: local file access, Feishu document/wiki creation, and group notifications. This increases the data exposure surface and creates a pathway for broad collection and onward transfer of user content to additional systems without clear scope limitation or consent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Cron workflow performs broad aggregation across all knowledge bases, supplements it with global search, reads local memory, and then republishes the results to multiple destinations. This is a classic bulk-collection and onward-sharing pattern that amplifies privacy and confidentiality risk because it centralizes more data than necessary and distributes it further.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Adding Feishu group messaging and wiki/document management enables exfiltration and replication of knowledge-base content into external collaboration channels not justified by the skill manifest. This is especially risky because the workflow automates onward sharing after aggregation, making accidental disclosure of private data much easier.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation conditions are broad enough to match ordinary requests about organizing notes, saving content, or knowledge workflows. Overbroad triggers can cause the skill to activate in contexts where users did not intend multi-step automation or access to the default knowledge base, increasing the chance of unintended writes and data processing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill states a default single knowledge-base context, but the Cron rules later require enumerating all knowledge bases and performing global searches. This mismatch can cause users and reviewers to underestimate the actual collection scope, leading to overbroad access and aggregation beyond expected boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Single-word routing such as '整理', '搜', or '报告' is ambiguous and lacks scope constraints, making unintended command execution more likely. In a skill that can search, retag, save, and perform multi-step automation, ambiguous routing creates a real risk of actions being taken against the wrong knowledge base or with broader scope than intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs access to local memory files under ~/.openclaw/workspace/memory, which is outside the stated Getnote-only workflow. Reading local files introduces unauthorized access risk because those files may contain unrelated sensitive notes, credentials, or historical context not needed for the requested action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Cron workflow writes aggregated content to local files, Getnote, Feishu docs, Feishu wiki, and group notifications without any user-facing privacy warning or approval step. Multi-destination replication significantly raises the chance of oversharing sensitive internal content and makes later containment harder.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to save links, free-form text, analyses, and reports into Get笔记 via CLI/API, but it does not clearly disclose that this content will be transmitted to and stored by an external third-party knowledge service. Users may provide sensitive notes, proprietary documents, or private URLs under the assumption of local processing, creating a privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

Forcing a default knowledge base without clear user selection can lead to accidental storage or retrieval in the wrong repository. While less severe than direct exfiltration, it can still violate user expectations, mix personal and work data, and increase exposure if that repository is broader than intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.