T09 · Insecure Skill Coding Practices
- Location
scripts/build_paper_deep_reading_bundle.py:293- Finding
Recursive archive creation can disclose files referenced by symbolic links
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a disclosed paper-reading and storyboard workflow, but it needs Review because its local bundle-building helpers can package more workspace data than intended, including files reached through symlinks, before upload or sharing.
Install only if you are comfortable with a Chinese-first paper workflow that writes local workflow metadata and bundles project files. Before running the bundle builders, use a dedicated clean workspace, remove symlinks and unrelated files, keep the output ZIP outside the input tree, and inspect the ZIP before uploading or sharing it. Do not place credentials, private keys, or unrelated sensitive documents in the workspace.
scripts/build_paper_deep_reading_bundle.py:293Recursive archive creation can disclose files referenced by symbolic links
Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.
Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.
Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.
Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.
Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.
Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.
Workflow/status JSON management with filesystem read/write is operational behavior that should be explicitly disclosed and permissioned. Otherwise, a user invoking a reading/reporting skill may unknowingly permit state mutation, artifact overwrites, or persistence of data into project metadata files.
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
| Author Defender | rebuttal and best-paper pitch | strongest acceptance argument and weakest vulnerable claim |
| Teacher | whether a non-specialist can follow | analogy, prerequisite list, teachback questions |
### Talk / PPT blueprint rule
Do not create a separate final report that competes with the authoritative detailed report. If a talk or slide blueprint is needed, make it a derivative artifact that cites the authoritative report as its source.
The README hard-codes Chinese-language resume prompts without indicating that the user may choose another language, which can cause the agent to privilege embedded prompt text over the user's language preference. While not directly enabling code execution, this can create prompt-routing ambiguity and reduce user control, especially in multilingual environments where exact trigger wording affects behavior.
The resume trigger phrase is generic enough that ordinary user text could accidentally invoke the skill's resumptive behavior, causing the agent to continue prior workflow state when the user may have intended a fresh request. In an agent setting, broad trigger phrases increase prompt-collision risk and can lead to unintended execution paths or disclosure of intermediate workflow state.
The skill declares executable capabilities such as file read/write and shell-related workflows but does not define an explicit tool-scope boundary. In an agent environment, this can lead to overbroad authority, making it easier for later prompts or chained instructions to trigger filesystem modification, packaging, or script execution beyond what users expect from a paper-reading skill.
The markdown repeatedly instructs users to resume or invoke the skill using Chinese-only prompt templates such as '使用这个skill,根据状态...'. Because these are framed as required reminder text and restart-safe commands, the skill imposes a specific language/locale convention without documenting user choice or an explicit justification for restricting prompts to Chinese.
The listed example user inputs are exclusively in Chinese, which imposes a specific language expectation in the manifest without any opt-in or documented locale constraint. This is a natural-language policy issue because the skill does not indicate that other languages are supported or that Chinese is required for a justified region-specific purpose.
This markdown contract repeatedly requires _detailed_cn report outputs and uses Chinese-titled mandatory sections, which imposes a specific language/locale on skill behavior. The file does not provide an opt-in, alternative language path, or a documented reason that the skill must be Chinese-only, matching the natural-language locale policy violation criteria.
This JSON schema includes authoritative report patterns ending in _detailed_cn.md and extensively mandates Chinese section headings throughout the required and mandatory sections. That constitutes a natural-language locale constraint embedded in config values, but the file does not indicate user opt-in, multilingual alternatives, or a documented region-specific justification.
The prescribed output layout repeatedly requires _cn filenames such as <paper-slug>_detailed_cn.md, teaching_outline_cn.md, and other Chinese-designated artifacts. This imposes a specific language/locale in the skill specification, and the file does not indicate user choice, opt-in, or a documented region-specific justification.
The user-facing instructions are written entirely in Chinese and require a specific reply phrase, which imposes a language choice without offering an alternative or opt-in. This is a natural-language policy issue because it constrains the interaction locale regardless of user preference.
The output policy hard-codes _cn teaching artifacts and earlier guidance mixes Chinese into the required teaching format, which implies a specific language/locale requirement. The file does not offer a user choice of language or explain why Chinese-only outputs are required, so this is a natural-language locale policy violation.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def refresh_project_directory_index(workspace_root: Path) -> None:
script_path = Path(__file__).resolve().parents[1] / "scripts" / "update_project_directory_index.py"
subprocess.run(
[
sys.executable,
str(script_path),
The scaffold template begins with Chinese headings such as 详细精读, and later embeds Chinese-only suggested user inputs for the next stage. Because the file provides no alternative language path or user-selectable locale, it imposes a specific language on downstream use.
The generated report filename is hard-coded to _detailed_cn.md, and the report stub content is written in Chinese, indicating the skill expects Chinese output by default. This is reinforced elsewhere in the file by Chinese-only next-step prompts, with no visible mechanism for the user to select another language.
This script recursively enumerates the entire workspace, classifies every file and directory, and writes inventory artifacts describing the project structure. The manifest describes a skill for deep-reading papers and producing source-grounded teaching/comic-storyboard outputs; maintaining a generic project directory index is an internal workspace-management capability that is not part of that stated end-user purpose.
The manifest emphasizes understanding research papers and producing teaching reports plus storyboard workflows, but the executed behavior here is to scan a workspace and generate JSON/Markdown directory indexes. That behavior is materially different from the described user-facing functionality and goes beyond an obvious implementation detail of paper comprehension or storyboard preparation.
The manifest describes a skill for deep-reading papers and producing grounded teaching reports and comic-storyboard workflows. This script instead creates directories and updates a generic routing/status JSON file, which is orchestration/state-management infrastructure rather than a direct capability needed for paper understanding or storyboard preparation.
The workflow hard-codes a Chinese-language user-facing reminder (如果开启新会话...) without offering a language choice or adapting to the user's language. This can cause user confusion, reduce accessibility, and create misleading or unusable guidance for non-Chinese-speaking users, especially because the text is framed as a required status-turn instruction.
No suspicious patterns detected.