Back to skill

Security audit

second-brain-digest

Security checks for vulnerabilities and agentic risk

Overview

This is a prompt-only Chinese knowledge-card workflow with no hidden file access or persistence, though users should be aware of broad activation wording and an unpinned npx install command.

Install this if you want a Chinese-language personal knowledge-card workflow. Prefer a trusted or pinned installer path, and treat the skill's outputs as generated note suggestions unless you explicitly choose to export or save them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:66
Finding

Unpinned npm CLI Package Is Retrieved and Executed During Installation

Content
View full analysis

Vulnerability Details

File Location: README.md, line 66
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable code snippet:

bash
npx @skill-hub/cli install second-brain-digest --agent claude

Technical Analysis

The installation instructions invoke @skill-hub/cli through npx without specifying an exact package version or integrity value. Depending on npm and npx configuration, this can retrieve the package version currently selected by the registry and execute its command-line entry point on the user's system.

The reviewed skill therefore does not determine the exact installer code that users will execute. If the package, a maintainer account, or the package registry distribution channel is compromised after this skill is reviewed, the same documented command could retrieve and run altered code. npm lifecycle scripts and the CLI entry point may execute with the privileges of the user running the command.

No evidence was found that the current package is malicious. The vulnerability is the mutable, unpinned execution path and the resulting supply-chain exposure.

Attack Path

  1. An attacker compromises the @skill-hub/cli package, a package maintainer account, or its publication pipeline.
  2. The attacker publishes a malicious version that is selected when the unversioned package name is resolved.
  3. A user follows the README and runs the documented npx command.
  4. npx downloads the attacker-controlled package version from the configured npm registry.
  5. Package lifecycle code or the CLI entry point executes under the user's account.
  6. The malicious package can access resources available to that account, subject to operating-system controls and the environment in which the command was run.

Impact Assessment

Successful exploitation can result in arbitrary code execution with the privileges of the invoking user. Depending on those p ...[truncated 635 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the installer to a specific reviewed version:

    bash
    npx --yes @skill-hub/cli@1.2.3 install second-brain-digest --agent claude
    
  2. Document the expected package provenance and publish the package's integrity digest or signed release information through a trusted channel.

  3. Prefer a lockfile-backed installation workflow where feasible, and use npm ci so the resolved dependency graph is reproducible.

  4. Enable npm package provenance and release signing, and instruct users to verify signatures or checksums before execution.

  5. Review the pinned installer version, including its lifecycle scripts and transitive dependencies, before recommending it.

  6. Run installation with a non-privileged account in an isolated environment without unnecessary credentials or sensitive environment variables.

  7. Establish an update process in which the pinned version is changed only after the new release and its dependency tree have been reviewed.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are extremely broad and include common requests like summarizing, organizing, or making notes from pasted text. This can cause the agent to invoke the skill in many unrelated contexts, overriding more appropriate behaviors and potentially routing arbitrary user content into a workflow that assumes storage, knowledge-base integration, and inferred linkage to prior notes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is primarily written in Chinese and presents the workflow and instructions in that language without indicating multilingual support or allowing the user to choose a preferred language. This can violate language/locale policy when a skill implicitly requires a specific language without opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The metadata hard-codes 'language: zh-CN', which indicates a fixed language/locale requirement. The file does not offer the user a language choice or explain why the locale restriction is necessary, creating a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example skill content is entirely in Chinese and presents required usage/output patterns without offering any language choice or opt-in. This can exclude users who do not understand Chinese, increase the risk of misinterpretation of stored knowledge artifacts, and cause the agent to respond in an unexpected language, which is especially problematic for note-taking and knowledge-base workflows where accuracy matters.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are very broad and match common user requests such as '帮我整理/提炼这段内容' or '做成笔记', which can cause the skill to activate in many everyday contexts where a narrower tool or a plain answer would be more appropriate. Over-broad activation boundaries increase the chance of unintended invocation, misrouting user data into the skill workflow, and applying storage or knowledge-base behaviors when the user did not explicitly intend that outcome.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The export trigger '帮我导出成 Obsidian 格式' is underspecified and lacks activation boundaries, so a generic formatting request could invoke export behavior without clear confirmation of destination, format details, or whether prior card generation exists. In a knowledge-management skill, ambiguous export behavior can lead to unintended transformation or disclosure of structured notes, especially if users assume this is only a local formatting change.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions and templates exclusively in Chinese, with no indication that users can choose another language or that the locale restriction is intentional. Under the policy rule for natural-language constraints, forcing a specific language without user opt-in is a language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.