Back to skill

Security audit

Paper Deep Reading Teaching Explainer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned, but its packaging and validation helpers can read or include files outside the intended workspace, which users should review before installing.

Install only if you trust the paper workspace inputs. Before running the bundling or validation scripts, remove symlinks, avoid attacker-supplied manifests, and use a dedicated project directory with no secrets or unrelated files. Treat external image generation as opt-in because it may send paper-derived content to an API.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/build_paper_deep_reading_bundle.py:292
Finding

Archive generation follows symlinks and can disclose files outside the workspace

Content
View full analysis
dict[str, object]: errors = validate_workspace_dir(workspace_dir) output_zip.parent.mkdir(parents=True, exist_ok=True) with zipfile.ZipFile(output_zip, "w", compression=zipfile.ZIP_DEFLATED) as zf: for path in sorted(workspace_dir.rglob("*")): if path.is_dir(): continue zf.write(path, arcname=path.relative_to(workspace_dir).as_posix()) ``` `scripts/init_paper_deep_reading_scaffold.py:950-956`: ```python def build_zip(workspace_dir: Path, output_zip: Path) -> None: output_zip.parent.mkdir(parents=True, exist_ok=True) with zipfile.ZipFile(output_zip, "w", compression=zipfile.ZIP_DEFLATED) as zf: for path in sorted(workspace_dir.rglob("*")): if path.is_dir(): continue zf.write(path, arcname=path.relative_to(workspace_dir).as_posix()) ``` `scripts/package_clawhub_skill.py:29-37`: ```python with zipfile.ZipFile(zip_path, "w", zipfile.ZIP_DEFLATED) as zf: for path in skill_dir.rglob("*"): rel = path.relative_to(skill_dir.parent) if any(part in ignore for part in rel.parts): continue if path.suffix.lower() in {".zip", ".pdf", ".png", ".jpg", ".jpeg", ".webp", ".gif", ".pptx", ".docx", ".xlsx"}: continue if path.is_file(): zf.write(path, rel.as_posix()) ``` ### Technical Analysis The archive builders recursively enumerate workspace entries and pass each file directly to `ZipFile.write()`. They do not reject symbolic links and do ...[truncated 1723 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_paper_deep_reading_bundle.py:71
Finding

Manifest-controlled paths can escape the workspace during validation

Content
View full analysis
Path | None: raw = str(raw).strip() if not raw or raw.lower() == "string" or raw.startswith("[fill"): return None candidate = Path(raw) if candidate.is_absolute(): return candidate return root / candidate ``` The resulting path is consumed by manifest validation, including: ```python report_md = resolve_relative_path(workspace_dir, item.get("authoritative_report_md", "")) report_pdf = resolve_relative_path(workspace_dir, item.get("authoritative_report_pdf", "")) focus_spec = resolve_relative_path(workspace_dir, item.get("focus_spec_json", "")) intermediate = resolve_relative_path(workspace_dir, item.get("intermediate_json", "")) if not report_md: errors.append(f"{label}: missing authoritative_report_md") elif not report_md.exists(): errors.append(f"{label}: missing authoritative_report_md -> {item.get('authoritative_report_md', '')}") else: errors.extend(validate_report_structure(report_md, required_headings, label)) ``` `scripts/validate_detailed_report_structure.py:38-48`: ```python def discover_reports(workspace_dir: Path) -> list[Path]: manifest_path = workspace_dir / "metadata" / "paper_batch_manifest.json" reports: list[Path] = [] if manifest_path.exists(): payload = json.loads(manifest_path.read_text(encoding="utf-8-sig")) for item in payload.get("papers", []): report_md = str(item.get("authoritative ...[truncated 3104 chars]
Remediation
View remediation
Path | None: raw = str(raw).strip() if not raw or raw.lower() == "string" or raw.startswith("[fill"): return None candidate = Path(raw) if candidate.is_absolute(): raise ValueError(f"Absolute artifact paths are not allowed: {raw}") workspace = root.resolve() resolved = (workspace / candidate).resolve(strict=False) if not resolved.is_relative_to(workspace): raise ValueError(f"Artifact path escapes workspace: {raw}") return resolved ``` 4. Reject symlinks for security-sensitive manifest artifacts, or validate their final resolved targets using the same containment rule. 5. Apply the helper consistently to report, PDF, focus-specification, intermediate, source-record, status, directory-description, and handoff-artifact paths. 6. Validate expected file types and expected directory prefixes for each field. 7. Add regression tests for absolute paths, `../` traversal, nested traversal, symlink escapes, and valid workspace-relative paths. ]]>

T08 · Insecure Dependencies

Note
Location
scripts/assemble_storyboard_pdf.py:15
Finding

Runtime guidance installs an unpinned third-party dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (45)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Report validation, completeness checking, and ICLR-specific review-bundle checks are not inherently unsafe, but they are materially different from directly analyzing paper content. The danger comes from disguising QA/orchestration behavior as scholarly analysis, which can mislead users about data access and the trust they should place in outputs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Report validation, completeness checking, and ICLR-specific review-bundle checks are not inherently unsafe, but they are materially different from directly analyzing paper content. The danger comes from disguising QA/orchestration behavior as scholarly analysis, which can mislead users about data access and the trust they should place in outputs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Report validation, completeness checking, and ICLR-specific review-bundle checks are not inherently unsafe, but they are materially different from directly analyzing paper content. The danger comes from disguising QA/orchestration behavior as scholarly analysis, which can mislead users about data access and the trust they should place in outputs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Report validation, completeness checking, and ICLR-specific review-bundle checks are not inherently unsafe, but they are materially different from directly analyzing paper content. The danger comes from disguising QA/orchestration behavior as scholarly analysis, which can mislead users about data access and the trust they should place in outputs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Report validation, completeness checking, and ICLR-specific review-bundle checks are not inherently unsafe, but they are materially different from directly analyzing paper content. The danger comes from disguising QA/orchestration behavior as scholarly analysis, which can mislead users about data access and the trust they should place in outputs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Report validation, completeness checking, and ICLR-specific review-bundle checks are not inherently unsafe, but they are materially different from directly analyzing paper content. The danger comes from disguising QA/orchestration behavior as scholarly analysis, which can mislead users about data access and the trust they should place in outputs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Report validation, completeness checking, and ICLR-specific review-bundle checks are not inherently unsafe, but they are materially different from directly analyzing paper content. The danger comes from disguising QA/orchestration behavior as scholarly analysis, which can mislead users about data access and the trust they should place in outputs.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 643)May include surrounding context.

md
| Author Defender | rebuttal and best-paper pitch | strongest acceptance argument and weakest vulnerable claim |
| Teacher | whether a non-specialist can follow | analogy, prerequisite list, teachback questions |

### Talk / PPT blueprint rule

Do not create a separate final report that competes with the authoritative detailed report. If a talk or slide blueprint is needed, make it a derivative artifact that cites the authoritative report as its source.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill contains conflicting instructions: one part prohibits reopening external retrieval, while another directs external OpenReview lookup. Contradictory policy inside a skill is dangerous because an agent may follow the broader or more action-oriented instruction, resulting in unapproved network access and inconsistent provenance guarantees.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This changelog includes extensive natural-language requirements and user-facing workflow instructions in Chinese, such as required user phrases and recovery prompts, but it does not offer users a language/locale option. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to resume stateless sessions with a Chinese-only example prompt, which can function as a required interaction pattern. Later lines also mandate a specific Chinese phrase for continuation, with no opt-in or alternative language path, creating a language-policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This line says the prompt must explicitly tell the user to say 生成多张连续的卡通图, which imposes a fixed language requirement. Because no language choice or justification is provided, this is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented resume prompt pattern and fallback prompt are both written only in Chinese. Without stating that these are optional examples or providing other language options, the file effectively prescribes a specific language for use of the skill.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares broad operational behavior including file reads, file writes, and shell-script usage, but does not define an explicit tool permission boundary. In an agent setting, missing scope declarations increase the risk of overbroad execution against project files or local environments because the runtime cannot enforce least privilege from the skill contract itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown repeatedly tells users to resume or invoke the skill using Chinese-only prompt templates such as "使用这个skill,根据状态...". Because the file does not offer an alternative language or explicitly make Chinese optional, it imposes a locale/language requirement in natural-language instructions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill authorizes fallback to external image-generation APIs even though the core skill framing is research reading and reporting. External API use expands data-sharing scope and may transmit paper content, derived summaries, or user data to third parties without a tightly justified need in the base workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill requires authoritative reports to include specific Chinese-titled sections, which effectively constrains output language/locale. There is no accompanying statement that users may request another language or that these section names can be localized.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The scaffold and handoff rules require files named *_detailed_cn.md and later pass forward the same Chinese-suffixed outputs. This indicates the skill expects Chinese-language deliverables by default, but the markdown does not provide user choice or justify a fixed locale.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to find OpenReview forums via title/year lookup reintroduces external retrieval despite a stated no-new-retrieval rule. This inconsistency is risky because it can cause uncontrolled network access, provenance drift, and data handling outside the uploaded bundle's trust boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The artifact names use a _cn suffix, indicating outputs in a specific language/locale. In this manifest, there is no accompanying note that this locale is optional, user-selected, or justified by a region-specific purpose, which creates a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The contract forces Chinese-language filenames and section content without exposing a user language choice or documenting a hard locale requirement. This can override user intent, reduce usability, and create silent policy mismatches in multilingual workflows; in agent settings, hard-coded output constraints can also cause downstream routing or integration failures when other components expect language-neutral or user-selected outputs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The contract hard-codes example files on a specific local Windows drive (E:/论文调研/...) as normative reference material. This creates an unnecessary dependency on host-local resources outside the declared uploaded/regenerated bundle, which can cause data boundary violations, environment-specific behavior, and unintended access attempts to local files if an agent follows the instruction literally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The schema hard-codes report filenames ending in _detailed_cn.md, and the required/mandatory headings are predominantly in Chinese. This indicates a language-specific policy baked into the skill configuration without any visible user opt-in or documented reason that the skill must operate only in Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Multiple required artifact names use the _cn suffix, which naturally indicates Chinese-language outputs as the expected default. The file does not offer a language choice or explain why Chinese is required, so this appears to force a specific locale without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template instructs repackaging and uploading generated artifacts back into the current project's sources, which introduces a state-changing data movement capability not clearly aligned with a paper-reading/explainer skill. This can cause unauthorized persistence of derived or sensitive content in project sources, expand the skill's effective privileges, and enable confusing or unsafe workflow chaining if triggered without explicit user consent and scope checks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.