Back to skill

Security audit

Article2Book

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local content-planning helper, with some ordinary handling risks around reading untrusted documents and generating CSV files.

Install only if you are comfortable letting the agent read the chosen content directory and write planning outputs under it. Use a narrow source folder, avoid mixed-trust documents, and be careful opening generated CSV inventories in spreadsheet apps unless formula-like cells have been sanitized.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_article_inventory.py:174
Finding

Spreadsheet Formula Injection in Generated CSV Inventory

Content
View full analysis
None: fieldnames = [ "id", "relative_path", "title", "source_type", "processing_status", "extension", "has_frontmatter", "frontmatter_keys", "publish_status", "chars", "lines", "h1_count", "preview", ] with path.open("w", encoding="utf-8", newline="") as handle: writer = csv.DictWriter(handle, fieldnames=fieldnames) writer.writeheader() writer.writerows(records) ``` ### Technical Analysis Several record fields are derived from files in the scanned source directory, including filenames, relative paths, document titles, frontmatter keys and values, and document previews. These values are passed directly to `csv.DictWriter` without neutralizing spreadsheet formula prefixes. CSV quoting performed by Python protects the structural integrity of the CSV file, but it does not stop spreadsheet software from interpreting cells beginning with `=`, `+`, `-`, or `@` as formulas. A malicious source document can therefore place a formula in its t ...[truncated 1944 chars]
Remediation
View remediation
object: if not isinstance(value, str): return value stripped = value.lstrip() if stripped.startswith(DANGEROUS_CSV_PREFIXES): return "'" + value return value ``` Sanitize all fields rather than only titles or previews: ```python safe_records = [ {key: sanitize_csv_cell(value) for key, value in record.items()} for record in records ] writer.writerows(safe_records) ``` Additional hardening measures should include: 1. Treat filenames, paths, frontmatter, titles, and document bodies as untrusted input. 2. Account for leading spaces, tabs, carriage returns, and line feeds before formula prefixes. 3. Document that CSV output is intended to contain text rather than executable spreadsheet formulas. 4. Add regression tests covering values beginning with `=`, `+`, `-`, and `@`. 5. Test malicious values in filenames, titles, frontmatter values, frontmatter keys, publication status, and preview text. 6. Preserve the unsanitized values in JSONL only if consumers are clearly informed that the content is untrusted. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:175
Finding

Mandatory Processing of Untrusted Documents Without Prompt-Injection Isolation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明的核心能力是对内容资产进行用途判断与策划输出;而代码的核心功能是建立内容资产 inventory。虽然生成清单可作为后续分析的辅助步骤,但当前代码本身没有实现所声明的主要目标,只完成了素材发现、简单清洗、元数据提取和多格式导出。因此主目的与实际行为存在实质性不一致,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to read from a user-provided source directory and create output files under that directory, but it declares no tool scope or permissions boundaries. In an agent platform, that omission can lead to overbroad file read/write access, increasing the chance of unintended access to unrelated local files or modification of arbitrary paths if the runtime does not enforce stricter defaults.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description says the skill should be used whenever the user mentions reorganizing existing content into a book, course, or knowledge product, but it does not provide clear trigger boundaries or exclusion phrasing there. Because the examples cover broad everyday editorial requests like turning articles or notes into a product, this could cause unintended invocation overlap with other writing, summarization, or course-design skills.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 382)May include surrounding context.

md
| 依赖 | 安装方式 |
|------|----------|
| `python3` | macOS: 系统自带或 `brew install python`<br>Linux: `sudo apt-get install python3` |

### Python 包

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

标题“书稿策划输出模板”及全文均以中文固定描述输出结构,未见任何允许用户选择语言或说明仅适用于中文场景的文字。根据规则,强制特定语言且无用户 opt-in 属于自然语言政策违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file is entirely written as normative guidance in Chinese, beginning with the title and purpose statement, with no indication that other languages are supported or that the user may choose a preferred language. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses Chinese throughout, including the title and all change entries, with no indication that the skill is intended only for a Chinese-speaking or region-specific audience. Under the language/locale policy, forcing a specific language without user opt-in or explicit justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file begins with and continues in Chinese, effectively imposing a specific language on readers and users of the skill documentation. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific purpose, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This plain-text file contains natural-language content mixing a Chinese label and contact detail in line L03. Under the policy provided, forcing or assuming a specific language without user opt-in can be a locale-policy concern, and there is no explanation here that the file is intended for a Chinese-only audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into another language. Under the policy, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is entirely presented in Chinese and begins with a Chinese-only title, with no indication that language choice is optional or limited to a justified region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.