Back to skill

Security audit

kmdr - Kmoe Manga Downloader

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Kmoe manga downloader, but it asks users to install a mutable pre-release package and allows password-based login through the agent.

Review this skill before installing. Prefer running login yourself in a terminal and avoid sending passwords through chat or command arguments. Install the downloader only in an isolated environment, and consider pinning or reviewing the exact package version before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned Pre-release Dependency Installation

Content
View full analysis
=1.4.0.a3,<2.0.0" ``` ### Technical Analysis The skill instructs users to install a third-party Python package with the `--pre` option and a broad version constraint. It does not pin an exact audited release or require package hashes. Consequently, later pre-release versions satisfying `>=1.4.0.a3,<2.0.0` may be installed without having been reviewed as part of this project. Python packages can execute code during installation or when their installed command-line entry points are invoked. The effective executable behavior therefore depends on mutable external package releases rather than solely on the audited skill files. No evidence establishes that the named package is currently malicious. The vulnerability is the unsafe dependency-installation policy and its exposure to package-repository, publisher-account, or upstream dependency compromise. ### Attack Path 1. An attacker compromises the package publisher, package repository, or an upstream dependency. 2. The attacker publishes a malicious pre-release version satisfying the documented version range. 3. A user follows the skill's installation command at a time when that release is selected by `pip`. 4. The malicious package is installed and its code executes during installation or subsequent `kmdr` invocation. 5. The code operates with the privileges of the user running `pip` or `kmdr`. ### Impact Assessment Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions, an attacker could access local files, Kmoe credentials, downloader configuration, downloaded content, environment variables, and network-accessible resources. The project does not direct users to ins ...[truncated 114 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:27
Finding

Optional Login Workflow Exposes Passwords in Conversation and Process Arguments

Content
View full analysis
[-p ]` in a terminal so credentials are not exposed to the agent. - Alternative: The user provides credentials and the agent executes `kmdr --mode toolcall login -u -p `; the credentials will appear in conversation history. ``` ### Technical Analysis The documentation correctly identifies interactive user-side login as the preferred method, but it also explicitly permits users to submit their username and plaintext password to the agent. The agent is then instructed to place the password directly in a command-line argument. This workflow creates multiple credential-exposure channels: - The password becomes part of retained conversation history. - Tool-call or command-execution logs may record the full command. - Shell history, telemetry, debugging output, or audit systems may retain the argument. - Other local processes or users may be able to inspect process arguments while the command is running, depending on operating-system configuration. The warning does not eliminate the vulnerability because the unsafe alternative remains an approved operational path. There are no hardcoded credentials in the repository, and exploitation requires a user to select this alternative workflow. ### Attack Path 1. A user chooses the documented alternative login method. 2. The user sends a Kmoe username and password through the conversation. 3. The agent invokes `kmdr` with the plaintext password supplied through the `-p` argument. 4. The secret is retained in one or more locations, such as conversation records, tool logs, process listings, telemetry, or command ...[truncated 797 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documents a fallback flow that passes the password via -p on the command line and only warns about exposure in chat history. This is dangerous because command-line secrets may also be exposed through shell history, process listings, terminal logging, or audit systems, causing credential leakage beyond the model conversation and potentially compromising the Kmoe account or credential pool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest-style JSON contains user-facing natural-language fields such as description, error text, and usage notes entirely in Chinese. Under the policy, forcing a specific language without user opt-in or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill reference is written only in Chinese, with no indication that users may choose another language or that the file is intended solely for a Chinese-speaking or region-specific audience. This creates a natural-language locale constraint without opt-in or documented justification, which matches the policy-violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language fields in this manifest, including the description and note, are presented exclusively in Chinese. For a general-purpose skill file, this can violate language/locale policy because it forces a specific language without user opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON manifest/example uses the description "获取下载计划示例" (roughly, "get download plan example"), which is broad and does not specify concrete trigger phrases, scope, or exclusion conditions. In a manifest-like file, such vague wording can overlap with many ordinary requests about downloads and make activation boundaries unclear.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON file is a manifest/example file, so vague-trigger review applies. The description "搜索漫画示例" is minimal and does not clarify invocation scope, exclusions, or any specific trigger phrases, which makes activation intent ambiguous if this description is used for discovery or routing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Natural-language policy review applies to all file types. The description and command example are Chinese-only, but the file does not state that the skill is intended specifically for Chinese-speaking users or offer a language/locale choice, which can conflict with policies against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L58 states that if no language tag is present, the item is treated as a Chinese translated version. This encodes a language default in natural-language documentation without indicating user opt-in or offering a locale choice, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.