Back to skill

Security audit

带脚本的论文摘要生成

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed paper-preprocessing and summarization workflow that downloads arXiv PDFs or reads user-provided files, with some ordinary document-processing risks but no evidence of hidden or malicious behavior.

Install only if you are comfortable with it downloading arXiv PDFs, reading the local paper files you provide, and leaving PDFs, extracted text, and manifests in the chosen output directory. Avoid processing sensitive private documents or unusually large/untrusted files unless you have sandboxing or resource limits in place.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
references/prompts.md:22
Finding

Untrusted paper content is inserted into generation prompts without instruction isolation

Content
View full analysis
Remediation
View remediation
{{cleaned_text}} ``` 3. Apply equivalent isolation to `summary_text`, `detailed_text`, and `contribution_text` during quality judgment because those values may already contain injected instructions. 4. Keep trusted instructions in a higher-priority message than document data where the runtime supports role-separated messages. 5. Add pre-generation detection for common injection patterns and surface a warning when suspicious directives are found. Detection should supplement, not replace, prompt isolation. 6. Restrict tool use during summarization so document text cannot induce network calls, file access, command execution, or unrelated actions. 7. Add adversarial tests using PDFs, DOCX files, and plain-text papers containing embedded role changes and “ignore previous instructions” payloads. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/process_papers.py:169
Finding

Unbounded file download, decompression, and document parsing permit resource-exhaustion attacks

Content
View full analysis
str: data = path.read_bytes() for encoding in ("utf-8", "utf-8-sig", "latin-1"): try: return data.decode(encoding) except UnicodeDecodeError: continue raise ProcessingError(f"cannot decode text file: {path}") ``` `scripts/process_papers.py:75-80`: ```python def extract_docx_text(path: Path) -> str: try: with zipfile.ZipFile(path) as zf: xml_bytes = zf.read("word/document.xml") except Exception as exc: raise ProcessingError(f"cannot open docx: {exc}") from exc ``` `scripts/process_papers.py:102-111`: ```python try: reader = PdfReader(str(path)) pieces = [] for page in reader.pages: pieces.append(page.extract_text() or "") text = ensure_text("\n\n".join(pieces)) if not text: raise ProcessingError("pdf contains no extractable text") return text except Exception as exc: ``` `scripts/process_papers.py:169-181`: ```python def download_arxiv_pdf(source: str, downloads_dir: Path, index: int) -> tuple[Path, list[str]]: arxiv_id, notes = extract_arxiv_id(source) url = f"https://arxiv.org/pdf/{arxiv_id}.pdf" request = urllib.request.Request(url, headers={"User-Agent": "paper-summary-script/1.0"}) try: with urllib.request.urlopen(request, timeout=30) as response: headers = dict(response.headers.items()) content_type = headers.get("Content-Type", "").lower() if "pdf" not in content_type and not url.lower().endswith(".pdf"): raise ProcessingError("arX ...[truncated 2488 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code matches the preprocessing portion of the description well: it accepts arXiv URLs/IDs and local files, downloads PDFs from arXiv, extracts text from supported formats, cleans text, and outputs structured intermediate artifacts. However, the declared purpose goes materially further by claiming a complete Dify-style four-stage summarization workflow with generated outputs in the user's requested language. This script does not perform any LLM calls, summarization, contribution extraction, consistency checking, or language-conditioned generation. The --language argument is merely stored in the manifest. Therefore the description overstates the implemented behavior in a material way, so this is a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to perform network access, local file reads, and writes to local storage, but it declares no explicit tool scope or permissions boundary. In practice, this can lead to overbroad execution in environments where capability declarations are used for sandboxing, user consent, or policy enforcement, increasing the risk of unintended file access or downloads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill behavior includes downloading remote PDFs to local storage and reading local paper files, but the user-facing description does not prominently warn about those data handling operations. This weakens informed consent and can expose sensitive local documents or create unexpected local persistence of downloaded content, especially in shared or regulated environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template says 'Use the user's requested language' on L04, but the output structure from L15-L38 is fixed in Chinese. That creates a language/locale policy inconsistency because the skill appears to force Chinese labels without explicit user opt-in or a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example command specifies --language "zh-CN" as the default usage, which imposes a specific language/locale in the skill documentation. The file does not indicate that language is optional, user-selectable, or justified as region-specific, so this appears to violate the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill description is broadly framed as a paper summarization workflow but does not define clear activation boundaries, such as when it should or should not be invoked, what sources are allowed, or what safeguards apply to local file handling. In an agent setting, vague triggering can cause the skill to be selected in unintended contexts, increasing the chance of processing untrusted inputs or performing unnecessary file/network actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains natural-language prompt instructions exclusively in Chinese, including a fixed persona and mandatory formatting directions. While the output language is parameterized via {{language}}, the instruction language itself is forced and no opt-in or alternative locale is offered, which can violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.