Security checks for vulnerabilities and agentic risk
Overview
The skill fits its dashboard purpose, but it should be reviewed because generated dashboards can execute unsafe script from knowledge-base content and the optional content-reading permission is broader than the default structure view.
Review before installing. Use it only with ima libraries whose contents and collaborators you trust, avoid shared or externally populated knowledge bases until the template escapes data and stops using unsafe innerHTML, and understand that the optional relationship mode can read full card content. The dashboard is read-only toward ima, but the generated HTML currently deserves caution when opened in a browser.
Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)
T09 · Insecure Skill Coding Practices
Error
Location
scripts/build_dashboard.py:73
Finding
Stored Script Injection Through Unsafe JSON Embedding
Content
View full analysis
Vulnerability Details
File Location: scripts/build_dashboard.py:73-80; associated injection context at assets/template.html:100 Vulnerability Type: Stored HTML/JavaScript injection Risk Level: High
Vulnerable Code
python
def render(data, template_path, out_path):
with open(template_path, "r", encoding="utf-8") as f:
tpl = f.read()
placeholder = "/*DATA_PLACEHOLDER*/"
if placeholder not in tpl:
raise ValueError("模板中未找到 %s 注入点" % placeholder)
# 用紧凑但可读的中文 JSON 注入;ensure_ascii=False 保留中文
injected = json.dumps(data, ensure_ascii=False, indent=2)
html = tpl.replace(placeholder, injected)
The serialized data is inserted into this executable script context:
html
<script>
const DATA = /*DATA_PLACEHOLDER*/;
Technical Analysis
The renderer serializes knowledge-base data with json.dumps() and directly substitutes the result into an HTML <script> element. JSON serialization makes values valid JavaScript strings, but it does not make them safe for embedding in HTML source.
In particular, a string containing </script> terminates the surrounding script element at the HTML parser level, regardless of whether the sequence occurs inside a JavaScript string. An attacker can append a new <script> element or another active HTML construct after that terminator.
Relevant input fields include library names, folder names, item names, notes, titles, and other metadata collected from the ima knowledge base. When a shared or externally populated knowledge base allows another contributor to create or rename content, that contributor can supply the malicious value. The generated HTML is then presented to the user and opened in a browser.
Attack Path
An attacker who can contribute content to a knowledge base used by the victim creates a folder, document, or metadata value containing a payload such as:
html
Build tree nodes and panels by appending trusted elements with appendChild() or replaceChildren() rather than assigning generated strings to innerHTML.
Do not use untrusted lib.id values directly in element IDs or CSS selectors. Generate internal IDs from a trusted counter or encode them safely.
If selected fields intentionally support formatting, sanitize them with a strict allowlist that rejects scripts, event attributes, dangerous URLs, SVG, MathML, and other active content.
Keep labels, names, notes, titles, and item names text-only by default.
Add regression tests for event-handler elements, SVG payloads, malformed attributes, nested markup, and values containing quotes or angle brackets.
Deploy a restrictive Content Security Policy as defense in depth, while retaining output encoding and safe DOM construction as the primary controls.
Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)
Tp2
High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Content
No source excerpt is available for this finding.
Tp2
High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Content
No source excerpt is available for this finding.
Tp2
High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
Content
No source excerpt is available for this finding.
Lp1
High
Category
MCP Least Privilege
Confidence
75% confidence
Finding
The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Content
No source excerpt is available for this finding.
Lp1
High
Category
MCP Least Privilege
Confidence
75% confidence
Finding
The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.
Content
No source excerpt is available for this finding.
Description-Behavior Mismatch
Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding
The skill advertises a read-only structure dashboard, but the documented advanced mode expands scope to reading full card/media content via fetch_media_content to extract relationship fields. That creates a privacy and data-minimization gap: a user asking for a folder dashboard could end up with broader content access capabilities than the manifest implies, increasing exposure of sensitive knowledge-base contents.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
The HTML root sets lang="zh-CN", and the visible UI text throughout the template is fixed in Simplified Chinese. This indicates a language/locale constraint without any user opt-in or documented justification, which matches the policy category for forced language/locale behavior.
Content
No source excerpt is available for this finding.
Intent-Code Divergence
Low
Category
Not specified by scanner
Confidence
82% confidence
Finding
The documentation reassures users that the skill is 'not bound to any personal library', but the actual tool permissions include arbitrary content reads through fetch_media_content. This mismatch can mislead users about data access scope and reduce informed consent, especially in a personal knowledge-base context where stored cards may contain sensitive notes.