Back to skill

Security audit

Moji Vocab

Security checks for vulnerabilities and agentic risk

Overview

The skill is aimed at Moji vocabulary study, but it needs review because it handles live session credentials and can delete persistent Moji favorites without strong safeguards.

Review this carefully before installing. Treat MOJI_TOKEN/sessionToken and MOJI_DEVICE_ID as secrets, avoid passing them on the command line, and do not share logs or screenshots containing them. Use dry-run first and avoid deletion actions unless you have confirmed exactly what will be removed from your Moji account. The package does not show malware or unrelated exfiltration, but its credential handling, broad remote deletion authority, and inaccurate documentation need caution.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/moji_manager.py:186
Finding

Session Token Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/moji_manager.py:186,196; also present in scripts/moji_quiz.py:150,154
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

Evidence

scripts/moji_manager.py:186,196:

python
parser.add_argument("--token", help="sessionToken, or set the MOJI_TOKEN environment variable")
token = args.token or os.environ.get("MOJI_TOKEN")

scripts/moji_quiz.py:150,154:

python
parser.add_argument("--token", help="sessionToken, or set the MOJI_TOKEN environment variable")
token = args.token or os.environ.get("MOJI_TOKEN")

Technical Analysis

Both command-line interfaces permit the MojiDict session token to be supplied with --token. Command-line arguments may be exposed through shell history, process inspection facilities, job-control systems, diagnostic reports, CI/CD logs, or command auditing.

The token is subsequently used as an authenticated MojiDict credential. In scripts/moji_manager.py, it is transmitted as _SessionToken, x-moji-session-id, and x-moji-token. Accepting the token through process arguments is not necessary because the scripts already support the MOJI_TOKEN environment variable.

No evidence indicates that the token is sent to an unrelated domain. The network transmission itself is directed to the declared MojiDict HTTPS API and is necessary for authenticated functionality. The vulnerability is the avoidable local disclosure channel created by the command-line option.

Attack Path

  1. A user starts either script with a command such as python3 scripts/moji_manager.py --token SECRET --device-id DEVICE --action stats.
  2. The complete command is recorded in shell history, process telemetry, an automation log, or another process-accessible command-line interface.
  3. A local user, administrator, monitoring service, or party with access to those logs retrieves the token.
  4. T ...[truncated 691 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the --token option from both scripts.
  2. Retrieve the token from a protected credential store, a narrowly scoped environment variable, or an interactive hidden prompt implemented with getpass.getpass().
  3. If command-line support must remain for compatibility, display a prominent warning and require explicit opt-in before accepting a token this way.
  4. Ensure application and CI logs redact values associated with MOJI_TOKEN, _SessionToken, x-moji-session-id, and x-moji-token.
  5. Avoid printing request headers, payloads, or exception objects that might later include authentication data.
  6. Document token revocation and rotation procedures for users who may previously have supplied credentials through command-line arguments.

T08 · Insecure Dependencies

Note
Location
SKILL.md:88
Finding

Unnecessary and Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:88-90
Vulnerability Type: Unnecessary supply-chain exposure
Risk Level: Low

Evidence

bash
pip install requests

Technical Analysis

The setup instructions direct users to install requests without a pinned version or package hash. However, the reviewed Python scripts use the standard-library module urllib.request; they do not import or use requests.

This dependency therefore provides no functionality required by the Skill while unnecessarily expanding its supply-chain and installation-time attack surface. An unpinned installation resolves whatever package version and transitive dependencies are available from the configured package index at installation time. Package installation can also execute build or installation logic with the privileges of the invoking user.

The audit found no evidence that the current requests package is malicious. Exploitation would depend on compromise or manipulation of the configured package source, package resolution process, upstream release, or network/package-index trust configuration.

Attack Path

  1. A user follows the documented setup instructions and runs pip install requests.
  2. pip resolves an unpinned release and any applicable dependencies from the user's configured package index.
  3. If the index, resolution configuration, upstream package, or retrieved artifact has been compromised, attacker-controlled installation code or package content is downloaded.
  4. Installation-time logic executes with the privileges of the user running pip.
  5. The malicious component can access files, environment variables, and network resources available to that user.

Impact Assessment

A successful supply-chain compromise could execute code with the invoking user's privileges and access that user's data and credentials. In this Skill's expected environment, exposed information could include MOJI_TOKEN ...[truncated 219 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the pip install requests instruction because the implementation uses urllib.request and has no demonstrated need for requests.
  2. Explicitly document that the current scripts require only the Python standard library.
  3. If a third-party dependency is introduced later, declare it in a reviewed dependency manifest.
  4. Pin exact audited versions and cryptographic hashes, for example through a lock file or a hash-verified requirements file.
  5. Install dependencies in an isolated virtual environment under a non-privileged account.
  6. Use a trusted package index and incorporate dependency vulnerability and provenance checks into release review.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明中将该技能定位为“生词本管理与每日测试技能”,核心包含测试/出题能力。但实际代码仅是一个命令行管理器,主要调用 Moji API 获取收藏夹内容、按页抓取、统计词条及 JLPT 标签,并支持批量删除。虽然“读取日语收藏夹”“按时间排序(早期单词优先)”与代码中的 sortType=5 基本一致,但声明中的关键测试功能完全缺失。此外,删除功能并不是依据‘已掌握’状态,而是依据传入的 JLPT 等级过滤后批量删除,因此与描述不完全一致。综合来看,描述高估并部分误述了代码实际能力,属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个兼具生词本管理与每日测试的技能,重点包含排序策略、混合出题模式和删除已掌握词汇等管理能力。但代码仅是一个“每日词汇测试生成器”:通过 MojiVocabManager 加载单词后,提取释义、随机生成干扰项,输出‘某词是什么意思’的选择题,并附带罗马音与 JLPT 等级展示。代码中没有任何基于收藏时间的排序逻辑;没有以读音为题干或释义+读音双模式的出题机制;也没有删除、更新、标记已掌握单词等管理操作。因此声明显著高估了实际能力,构成描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
python3 scripts/moji_manager.py --action stats

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
python3 scripts/moji_manager.py --action stats

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill requires access to environment variables containing API credentials and makes network requests to a third-party service, but the manifest does not declare any explicit tool scope or permissions. This weakens reviewability and consent because users cannot clearly see that the skill needs secret access and outbound network capability before use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation advertises deletion of saved words without clearly warning that this operation is destructive and affects the user's persistent Moji favorites/bookmark list. In this context, the skill manages real user vocabulary data, so an unclear delete flow can cause unintended data loss and irreversible account changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill tells users how to extract sessionToken and deviceId from browser storage and export them as environment variables, but gives no warning that these are sensitive authentication secrets. Anyone with access to those values could potentially authenticate to the user's Moji account API, read private saved content, or modify/delete favorites.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/moji_manager.py (reported line 17)May include surrounding context.

python
APP_ID = "E62VyFVLMiW7kvbtVq3p"
INSTALL_ID = "60c39bef-8039-4b07-9669-64d1bb0327d7"
BASE_URL = "https://api.mojidict.com/parse/functions"

class MojiVocabManager:
    def __init__(self, token: str, device_id: str):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script reads MOJI_TOKEN and MOJI_DEVICE_ID and sends them to a remote API as authentication headers. While this is functionally required, the file does not include a user-facing warning or explanatory comment near the CLI entry points to disclose that credentials will be sent to the external service.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for notebook management and daily quizzes, including mixed-mode questioning by meaning and reading. This file implements retrieval, statistics, and deletion workflows only; there is no quiz generation, testing logic, or mixed-mode prompt handling anywhere in the code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

This endpoint performs destructive external actions by sending authenticated batch deletion requests to a third-party service. In context, the danger comes not from network use alone but from combining credentialed transmission with irreversible remote deletion, which can cause loss of user vocabulary data if invoked unintentionally or with overly broad selection criteria.

Content

Scanner excerpt · scripts/moji_manager.py (reported line 130)May include surrounding context.

python
payload = json.dumps({"itemIds": ids}).encode()
        req = urllib.request.Request(
            "https://api.mojidict.com/app/mojidict/api/v1/folder/batchUnfollow",
            data=payload, headers=self._delete_headers()
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script can perform irreversible deletion of vocabulary items immediately once invoked, without an interactive confirmation prompt or explicit safety gate. In a skill that manages user study data, this increases the risk of accidental or unintended destructive actions resulting in data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script accepts sensitive credentials via command-line flags, which can expose them through shell history, process listings, audit logs, or job-control tooling on shared systems. In this skill, the credentials are real session/authentication values for a third-party account, so disclosure could let another local user or monitoring system reuse them to access the victim's Moji data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The module docstring and user-facing CLI descriptions are exclusively Chinese, with no indication that the tool is intentionally limited to Chinese-speaking users or that alternative language support is unavailable. The policy requires avoiding forced language/locale constraints unless opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill manifest describes user-facing vocabulary notebook management and testing, but does not mention environment-based credential handling. While authentication is needed for the remote API, sourcing secrets from process environment is an additional operational capability not reflected in the stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

User-facing descriptions, prompts, and status messages are hard-coded in Chinese throughout the file. Under the language/locale policy, this is a natural-language policy issue because the skill does not offer the user any language choice or opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes reading a Moji favorites list and generating daily vocabulary quizzes, but this script also pulls authentication material from process environment variables. Accessing environment-stored secrets is not part of the user-facing vocabulary-management intent and expands the skill's capability beyond quiz logic itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.