Back to skill

Security audit

Save Link & Web Clipper

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real YouMind link-saving skill, but it uses broad command permissions and vague triggers that deserve user review before installation.

Install only if you intend to use YouMind for saved links. Review or restrict the broad youmind * and node -e * permissions if your platform allows it, approve the global npm install yourself, keep the API key out of chat, and do not submit confidential or tokenized URLs unless you are comfortable storing them in YouMind.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger set is broad and includes common phrases like 'bookmark', 'save this', and 'clip this', which can cause the skill to activate in situations where the user did not intend to send a URL to YouMind. In this skill's context, accidental activation matters because URLs and associated page data are transmitted to an external service, creating privacy and consent risks.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The description encourages use on generic requests like 'save link' or 'bookmark' without clearly stating that the skill will send the URL to YouMind's external service. Ambiguous activation guidance increases the chance of unintended invocation and external data disclosure when users may have meant a local save/bookmark action instead.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill does not provide an upfront privacy warning that user-submitted URLs and potentially fetched page content are sent to YouMind. In a web clipper context, users may share sensitive internal links, private documents, or authenticated resources, so failing to disclose third-party transmission creates a meaningful privacy and consent risk.

Static analysis

No suspicious patterns detected.