Back to skill

Security audit

Eudic Vocab

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for Eudic vocabulary quizzes and word management, but it needs review because it documents unsafe token handling and destructive deletion without clear safeguards.

Review before installing. Use a dedicated Eudic token with the minimum permissions available, do not place the token directly in command lines or crontab entries, store quiz output in a private directory, and manually confirm any word deletion because the skill performs real remote changes to your Eudic account.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:22
Finding

API token exposure through command-line arguments and cron configuration

Content
View full analysis
--count 5 ``` ## Usage ### Generate a quiz manually ```bash python3 scripts/quiz_generator.py --token --count 5 ``` ### Delete a mastered word ```bash python3 scripts/vocab_manager.py --token --action delete --word-id ``` ### List all words ```bash python3 scripts/vocab_manager.py --token --action list ``` ``` The corresponding scripts accept credentials from command-line arguments: ```python parser.add_argument( "--token", help="API Token; if omitted, read from the EUDIC_TOKEN environment variable" ) args = parser.parse_args() token = args.token or os.environ.get("EUDIC_TOKEN") if not token: print("Error: provide --token or set EUDIC_TOKEN") sys.exit(1) ``` ### Technical Analysis Command-line arguments are not an appropriate channel for long-lived credentials. Depending on the operating system and local security configuration, command arguments may be exposed through: - Process inspection interfaces such as `ps` or `/proc//cmdline`. - Shell history files. - Process monitoring and auditing services. - Scheduler logs and diagnostic output. - Persistent crontab entries readable by administrators or other privileged services. The documented cron command is particularly problematic because it directs the user to store the Eudic API token in persistent scheduler configuration. This exceeds the minimum necessary exposure because all three scripts al ...[truncated 1401 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/daily_quiz.py:13
Finding

Predictable scheduled output permits symlink file clobbering and insecure data storage

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:58
Finding

Documentation introduces an unnecessary unpinned third-party dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

描述将该技能定位为“生词本管理与每日测试”综合工具,重点包括自动出题、管理单词、删除已掌握词汇。实际代码片段的核心用途则是一个每日测试生成脚本:读取 token、生成若干题目、打印题目并保存题目和答案到本地 JSON 文件。就该片段可见行为而言,它只覆盖了“每日测试/自动出题”的一部分,未体现任何对词汇条目的增删改管理,也没有删除已掌握词汇的逻辑,因此描述明显比代码能力更广,且主要能力存在缺失。同时,代码还会额外将测试和答案写入文件,这属于描述中未提及的行为。综合判断,描述与实际代码行为存在实质不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码片段的核心行为是调用 EudicVocabManager 读取单词列表,提取释义,随机生成选择题,并在命令行打印题目和答案。这与声明中的“自动从欧路词典收藏夹出题”大体一致(虽然代码使用的是 category_id/language 的生词本读取接口,而非明确的收藏夹概念),但声明还明确包含“管理单词、删除已掌握词汇”等能力,而在本代码中没有任何新增、编辑、删除、标记已掌握或同步回写欧路词典的实现。因此描述比实际代码宽,存在能力声明不准确的情况。另有实现细节问题(如未导入 os/sys),但这不影响目的判断。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

描述与代码部分重合在“管理单词、删除词汇”这一点上,但核心宣称的“每日测试”“自动从欧路词典收藏夹出题”在代码中完全没有实现。代码的实际主功能是调用欧路词典 API 进行生词本和分类的 CRUD 管理,而不是测试/出题工具。此外,代码还包含分类管理、详情查询、批量删除等未在描述中说明的能力。虽然这些额外能力与生词本管理相关,不算完全无关,但由于声明中的主要用途之一(测试出题)缺失,且实际主用途更偏向管理器,因此应判定为描述与行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
76% confidence
Finding

The skill documentation describes use of environment-stored tokens, local file output, and outbound network access, but it does not declare any explicit tool scope or permissions boundary. That creates an authorization transparency gap: users and hosting platforms cannot easily assess or constrain what the skill may access, increasing the risk of unintended secret use or data egress.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to delete mastered words and provides a delete command, but it gives no warning that the action is destructive or potentially irreversible. In a vocabulary-management context this can lead to accidental data loss, especially if users invoke deletion through an automated agent without confirmation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

All user-facing text in the docstring, argument descriptions, prompts, and status messages is in Chinese, with no indication that another language is supported or that Chinese is a required locale. This can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and all user-facing prompts are written in Chinese and describe extracting concise Chinese definitions, indicating the skill is designed to operate in Chinese by default. Because there is no natural-language opt-in or documented locale justification in this file, this creates a language-policy concern under the rule for forced language or locale.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
import urllib.error
from typing import List, Dict, Optional

BASE_URL = "https://api.frdic.com/api/open/v1"

class EudicVocabManager:
    def __init__(self, token: str):

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/vocab_manager.py (reported line 13)May include surrounding context.

python
import urllib.error
from typing import List, Dict, Optional

BASE_URL = "https://api.frdic.com/api/open/v1"

class EudicVocabManager:
    def __init__(self, token: str):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code sends user-provided words, meanings, category IDs, and an authorization token to an external service via HTTP requests. Although the file has brief docstrings and some progress prints, it does not clearly disclose to the user that their vocabulary content and token will be transmitted to a third-party API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script includes deletion methods for categories and words, and the CLI delete action invokes remote deletion immediately once given an ID. There is no confirmation prompt or explicit warning that the operation is destructive and may be irreversible.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill description and user-facing instructions are presented only in Chinese, and the workflow later instructs the user to tell the assistant which words were remembered in that language context. The policy allows locale constraints when they are opt-in or clearly justified, but this file does not offer a language choice or explain why Chinese-only interaction is required.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest describes a daily Eudic vocabulary-book quiz and word management skill, but this script additionally retrieves credentials from the process environment via EUDIC_TOKEN. While token use itself is expected for API access, environment-variable credential harvesting is not justified by the stated end-user purpose in the manifest and expands the skill's capability surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code accesses the sensitive environment variable EUDIC_TOKEN to authenticate the quiz generator. While the CLI help mentions the variable, there is no runtime warning, comment about credential handling, or broader user disclosure about the script's use of stored credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes generating quizzes from Eudic favorites, managing words, and deleting mastered vocabulary, but it does not mention local file persistence. This script saves both quiz content and answer keys to JSON files, which is additional behavior beyond the described user-facing scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The script writes quiz data to args.output and also creates a separate .answers.json file containing the answer key. Although the output argument name implies file creation, there is no explicit runtime disclosure that both files will be created and persisted locally, including the answer file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The help text and inline comment state that the token can be read from environment variables, and the code attempts to use os.environ and sys.exit accordingly. However, this file never imports os or sys, so the documented credential-loading and exit behavior contradicts the actual runnable behavior of the script.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The module docstring and CLI description present this file as a test-question generator, but the code also retrieves an API token from the process environment via EUDIC_TOKEN. Accessing environment-held credentials is not described in this file's stated purpose and is a broader capability than pure local quiz generation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring says the tool supports managing categories, which implies category modification capabilities. However, the executable interface in main only exposes list/add/delete/categories/detail actions for words and category listing, with no action paths for add_category, rename_category, or delete_category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Natural-language strings in the module docstring and CLI messages are presented only in Chinese, which can impose a language choice on users without opt-in. The file does not state that the skill is region-specific or provide an alternative language option.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes a skill for managing an Eudic vocabulary list and daily testing, but this script additionally pulls credentials from the host environment via EUDIC_TOKEN. While common as a CLI convenience, environment-variable access is not part of the stated user-facing purpose and represents a host capability beyond simple word-list operations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.