Back to skill

Security audit

XReading

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language book-processing workflow, with some disclosed local file search and online lookup behavior users should understand before use.

Install this if you want a Chinese XReading workflow that reads book files, may use web search to verify claims, and writes Markdown notes into your workspace. Prefer giving an explicit file path, and ask the agent not to search Downloads/Books or go online if you want to keep book interests and local files private.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared purpose is a content-processing skill for turning a book into an XReading card from user-provided book inputs. The supplied code does something materially different: it audits the composition of existing card markdown files by section title and length percentages, enforcing a rough 60/30/10-style structure. This is not merely an implementation detail of the declared behavior; it omits the core promised functionality and substitutes a separate validation/checking function with filesystem-based markdown inputs rather than book sources. Therefore the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill clearly instructs the agent to read local files and additional reference documents, but it does not declare any explicit tool scope or permission boundary. That creates an authorization gap where the runtime may allow broader file access than users expect, increasing the risk of accidental overreach or misuse by downstream tooling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L019 states that all formal output must be in Chinese. This is a language-policy constraint expressed in natural language, and the file does not indicate user choice, opt-in, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill directs the agent to perform online verification of book details and controversy checks without clearly scoping or declaring that network use. Network access can leak user interest data, document titles, or excerpts to external services and expands the attack surface beyond a local book-processing workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the agent to search the current directory, ~/Downloads, and ~/Books for files when the user has not provided a path. That is broader filesystem discovery than necessary and can expose unrelated personal documents or metadata, especially if multiple matching files exist or directory contents are surfaced back to the model.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Even if local file search were functionally useful, the skill does not require a user-facing warning before scanning common directories. This undermines informed consent and can surprise users by causing the agent to inspect filesystem locations that may contain sensitive personal material.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown template is entirely written in Chinese and instructs the user to produce content in that language, but it does not provide any language or locale opt-in mechanism. Under the policy rule, forcing a specific language without user choice is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire file is written as mandatory operational guidance in Chinese, with no indication that the user may choose another language or locale. Under the policy rule, a skill that effectively imposes a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains all user-facing guidance in Chinese and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-language audience. That can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's classification logic relies on Chinese section names and Chinese keyword matching, which effectively forces a specific language/locale in order for the script to function correctly. There is no natural-language indication of user opt-in, alternative locale support, or justification for the restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.