Back to skill

Security audit

Journal Deep Intel Extractor

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but a crafted journal name can make it write outside its disclosed output folder and overwrite local files.

Install only if you trust the publisher and can run it in a constrained environment. Use normal journal names only, avoid passing untrusted or generated journal strings, and prefer a fixed output directory plus filename sanitization before broad use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
main.py:68
Finding

User-Controlled Output Path Allows Directory Traversal and File Overwrite

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Third-Party Dependencies Are Not Version-Pinned

Content
View full analysis
Remediation
View remediation
\ --hash=sha256: beautifulsoup4== \ --hash=sha256: lxml== \ --hash=sha256: ``` Actual versions and hashes should be generated from tested artifacts rather than copied from an unverified source. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares an executable Python entrypoint that performs network access and writes files locally, but the manifest does not define any permission scope or allowed-tools boundary. This creates an unnecessary trust gap: a host may execute the skill with broader capabilities than users expect, increasing the risk of data exfiltration, unsafe filesystem writes, or future code changes silently expanding behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The user-facing description and operational guidance are entirely in Chinese, which imposes a specific language/locale on users without any opt-in or alternative. Under the stated policy, locale constraints should either be optional or clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description suggests a tool that supports major journals directly, but the implementation performs a PubMed search filtered by journal name and publication type. This is a narrower behavior than implied, because the actual data source is PubMed pages rather than direct support for each named journal platform.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The stated purpose emphasizes automated retrieval and extraction as a data source, but does not disclose persistent local file output. Saving results to ~/Documents/Journal_Intel is additional behavior beyond mere extraction and may matter for user expectations about side effects.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency 'requests' is not version-pinned, which makes builds non-reproducible and can cause the environment to resolve to a vulnerable or incompatible release over time. In a network-scraping skill that fetches external content, this increases supply-chain uncertainty and makes it harder to verify whether known fixes for Requests CVEs are present.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests
beautifulsoup4
lxml

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

Requests has multiple published advisories, and because no version is pinned, there is no way to verify from this manifest whether a safe or vulnerable release will be installed. In a tool that performs outbound HTTP requests to retrieve journal content, this uncertainty is meaningful because HTTP client flaws can affect credential handling, TLS verification behavior, or request routing.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency 'beautifulsoup4' is unpinned, so installations may pull different versions at different times, reducing reproducibility and increasing supply-chain risk. While not inherently exploitable by itself, leaving parsing libraries floating can expose the skill to future vulnerable releases or breaking changes during automated deployment.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
requests
beautifulsoup4
lxml

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

The dependency 'lxml' is unpinned, which is risky because lxml is a complex parser with a history of security advisories. Given this skill processes scraped journal content from external sites, an uncontrolled lxml version raises the chance of deploying a release with parser-related vulnerabilities or unexpected behavior.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
requests
beautifulsoup4
lxml

Unverifiable Dependency: lxml has 14 known advisory(ies) (CVE-2021-43818 (lxml's HTML Cleaner allows crafted and SVG embedded scripts to pass through); CVE-2014-3146 (lxml Cross-site Scripting Via Control Characters); CVE-2021-28957 (lxml vulnerable to Cross-Site Scripting ) +11 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
97% confidence
Finding

lxml has a notable advisory history, and the manifest does not pin a version, so the deployed parser could be an affected release without visibility. This is more relevant in this skill because it ingests and parses remotely fetched HTML/XML from journal sites, making parser security and version control important.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.