Back to skill

Security audit

IMA Wiki 编译器

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Tencent IMA knowledge-base organizer that can read and edit a user's IMA content, with no artifact evidence of hidden code execution or persistence.

Install only if you intend to let the agent use your IMA API credentials to read, upload, move, tag, append, and update IMA knowledge-base or note content. Review proposed changes before approving tag deletion/rename, file moves, cascade updates, or note writes, and avoid using it with knowledge bases containing content you do not want sent to Tencent IMA/COS APIs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (64)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-reference.md (reported line 171)May include surrounding context.

6.2 move_knowledge

bash
curl -s -X POST "https://ima.qq.com/openapi/wiki/v1/move_knowledge" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/troubleshooting.md (reported line 30)May include surrounding context.

md
")

# 2. 用完整标题作为 item_name
curl -s -X POST "https://ima.qq.com/openapi/wiki/v1/tag_add" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/troubleshooting.md (reported line 219)May include surrounding context.

bash
# 测试 API 连通性:调用 search_knowledge_base(注意没有 list_knowledge_bases)
curl -s -X POST "https://ima.qq.com/openapi/wiki/v1/search_knowledge_base" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/api-reference.md (reported line 231)May include surrounding context.

1.2 创建笔记

bash
curl -s -X POST "https://ima.qq.com/openapi/note/v1/import_doc" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/write-and-verify.md (reported line 24)May include surrounding context.

1.2 创建笔记

bash
curl -s -X POST "https://ima.qq.com/openapi/note/v1/import_doc" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/write-and-verify.md (reported line 36)May include surrounding context.

bash
# 列出笔记本(端点是 list_notebook 单数,不是 list_notebooks)
curl -s -X POST "https://ima.qq.com/openapi/note/v1/list_notebook" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/write-and-verify.md (reported line 43)May include surrounding context.

md
-d '{"cursor": "0", "limit": 20}' | python3 -m json.tool

# 创建笔记本(端点是 add_notebook,不是 create_notebook)
curl -s -X POST "https://ima.qq.com/openapi/note/v1/add_notebook" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/write-and-verify.md (reported line 52)May include surrounding context.

1.4 短内容直接写入

对于 < 3KB 的内容,直接使用 import_doc + curl -d @filepath 写入,跳过 COS 中间环节:

bash
curl -s -X POST "https://ima.qq.com/openapi/note/v1/import_doc" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/write-and-verify.md (reported line 52)May include surrounding context.

1.4 短内容直接写入

对于 < 3KB 的内容,直接使用 import_doc + curl -d @filepath 写入,跳过 COS 中间环节:

bash
curl -s -X POST "https://ima.qq.com/openapi/note/v1/import_doc" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/write-and-verify.md (reported line 108)May include surrounding context.

bash
# 注意:端点是 list_note(单数),不是 list_notes
curl -s -X POST "https://ima.qq.com/openapi/note/v1/list_note" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad, everyday phrases such as '建知识库', '整理资料库', and '按标签分类', which can plausibly appear in ordinary conversation outside the narrow intended workflow. In an agent system, over-broad activation can cause the skill to run on unintended requests, leading to unnecessary access to user files, URLs, tags, or note-editing operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This reference document provides authenticated API examples for reading, exporting, moving, uploading, and modifying knowledge-base and note content, but it does not include an explicit warning that these operations may disclose private data to external services or change user data. In a skill that organizes user knowledge repositories, the omission increases the risk that an agent or operator invokes destructive or privacy-sensitive operations without informed user consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 243)May include surrounding context.

6.6 append_doc 追加内容

bash
curl -s -X POST "https://ima.qq.com/openapi/note/v1/append_doc" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 171)May include surrounding context.

bash
# 移动到目标文件夹(src_kb_id == dst_kb_id 表示知识库内移动)
curl -s -X POST "https://ima.qq.com/openapi/wiki/v1/move_knowledge" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/folder-organization.md (reported line 109)May include surrounding context.

bash
# 移动到目标文件夹(src_kb_id == dst_kb_id 表示知识库内移动)
curl -s -X POST "https://ima.qq.com/openapi/wiki/v1/move_knowledge" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document title and all authoring instructions are written as mandatory Chinese-language conventions, and the template repeatedly states that all guides must follow this format. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is explicit and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The command sends a note export request to a remote API using privileged headers, then fetches the returned content URL and prints the exported note content. This creates an external transmission path for potentially sensitive note data and also encourages handling exported content in shell pipelines, increasing the chance of unintended disclosure through logs, terminal history, or downstream tooling.

Content

Scanner excerpt · references/incremental-update.md (reported line 9)May include surrounding context.

bash
# 导出旧版本笔记内容
curl -s -X POST "https://ima.qq.com/openapi/note/v1/export_note" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs operators to export note content and retrieve knowledge-base listings via remote API calls, but it does not explicitly warn that note data, metadata, and access credentials are being transmitted to an external service. In a skill context, that omission can lead users or downstream agents to exfiltrate sensitive knowledge-base content without informed consent or scope checks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The command transmits knowledge-base and folder identifiers to an external API and retrieves a file list, which may expose internal structure, document titles, and organizational metadata. In this skill, the risk is elevated because the operation is part of an automated update workflow, so repeated unattended execution could leak repository structure at scale without explicit review.

Content

Scanner excerpt · references/incremental-update.md (reported line 31)May include surrounding context.

获取文件夹最新文件列表,与旧版本对比:

bash
curl -s -X POST "https://ima.qq.com/openapi/wiki/v1/get_knowledge_list" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language instructions, headings, examples, and operational guidance are all presented in Chinese, with no indication that the user can choose another language. This can violate language/locale policy when a skill implicitly forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs use of web search and URL import as data sources without warning that content, queries, or URLs may be transmitted to external services. In a knowledge-ingestion context, this can expose sensitive topics, internal research interests, or proprietary links, especially when users may assume all processing stays within the knowledge base platform.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

This step sends search requests and authentication headers to an external IMA API endpoint. In context, such transmission is expected for the product's function, but it still constitutes a real data-transfer surface because query contents and identifiers may leave the local environment, creating privacy and credential-handling risk if users are not clearly informed.

Content

Scanner excerpt · references/ingest.md (reported line 45)May include surrounding context.

bash
# 在目标文件夹搜索标题包含"主题导览"的笔记
curl -s -X POST "https://ima.qq.com/openapi/note/v1/search_note" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This example uploads content to a remote note API using client credentials, which is an intentional but genuine external transmission path. In a knowledge-base ingestion skill, that is core functionality, yet it remains security-relevant because sensitive note content may be transmitted or stored remotely without an explicit privacy/security warning in the surrounding guidance.

Content

Scanner excerpt · references/ingest.md (reported line 135)May include surrounding context.

6.1 选项 A:新建笔记(最简单)

bash
curl -s -X POST "https://ima.qq.com/openapi/note/v1/import_doc" \
  -H "ima-openapi-clientid: $IMA_OPENAPI_CLIENTID" \
  -H "ima-openapi-apikey: $IMA_OPENAPI_APIKEY" \
  -H "Content-Type: application/json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes broad write operations and cascading updates to multiple existing guides, but does not present a prominent upfront warning that one ingest may modify several notes. Even though the sample algorithm includes a later confirmation step, the overall workflow normalizes multi-document mutation and increases the chance of unintended mass edits or overbroad changes in a user's knowledge base.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow report says an update results in version progression (for example, v1.5 to v1.6) even though earlier sections say append_doc mode does not update version fields. That inconsistency can mislead users and systems into trusting a change log or version state that does not actually exist, weakening change control and making unauthorized or erroneous edits harder to detect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.