Back to skill

Security audit

knowledge-engineering

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent RAG document-slicing skill, but it needs Review because it can automatically install packages and rewrite or overwrite generated knowledge-base files without strong consent or rollback safeguards.

Install only if you are comfortable with a skill that writes and repairs many Markdown files in a chosen output directory and may install sentence-transformers or download a local embedding model during retrieval evaluation. Run it in a project-specific or disposable Python environment, review the planned output directory first, keep backups of existing knowledge-base slices, and avoid using --fix or --renumber on valuable directories without reviewing changes.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

The script automatically executes pip install sentence-transformers at runtime when the dependency is missing. This introduces unauthorized code execution and supply-chain risk in a tool whose stated purpose is offline retrieval evaluation, because it changes the host environment and fetches third-party code without explicit user consent.

Content

Scanner excerpt · scripts/evaluate_retrieval.py (reported line 77)May include surrounding context.

python
import subprocess
        try:
            pip_cmd = "pip" if _PINFO.is_windows else "pip3"
            subprocess.run([pip_cmd, "install", "sentence-transformers"],
                           capture_output=True, check=True, timeout=120)
            # 安装成功 → 重新导入
            from sentence_transformers import SentenceTransformer

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The helper wraps arbitrary command execution and, on Windows, forces shell=True even when the command is provided as a list. If any caller passes attacker-influenced input into this wrapper, it can become a command injection sink and expands the module from simple platform detection into general process execution capability.

Content

Scanner excerpt · scripts/platform_detect.py (reported line 308)May include surrounding context.

python
if info.is_windows:
        kwargs.setdefault("shell", True)
        kwargs.setdefault("encoding", "utf-8")
    return subprocess.run(cmd, **kwargs)


# ── 模块自测 ──

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no permissions, but its instructions clearly require reading source files, writing many output files, invoking Python/scripts, and potentially using shell-like execution paths. This mismatch is dangerous because operators and policy engines may grant trust based on the manifest while the runtime behavior still performs broad local file and command actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose is RAG slicing, but the skill also instructs automatic package installation, file mutation to repair content, index renumbering/renaming, and platform capability probing. That scope creep increases the attack surface and can lead users to approve a benign-seeming document-processing skill that actually modifies the environment and existing artifacts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation expands from document chunking into environment/package management, including automatic dependency handling. Even if not overtly malicious, this broadens the operational scope from data transformation to host modification, which can violate least-privilege expectations and enterprise change-control requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Automatic package installation is not necessary to perform the primary job of slicing text, especially when the skill already describes degraded fallback behavior. Unjustified installation can alter the host, pull unreviewed code from package repositories, and create supply-chain and reproducibility risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

--fix is documented as generating an audit report, but in practice it also rewrites slice files through auto_fix_cross_refs. This creates an integrity and trust-boundary problem: users may invoke an apparently report-only mode on valuable knowledge-base content and unintentionally alter source material, potentially corrupting references through fuzzy matching or broad string replacement.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI help text says --fix only generates an audit report, but the code path also performs automatic repair of cross-references. This misleading interface can cause operators or higher-level agents to grant the tool write access under false assumptions, increasing the risk of unintended file modification in automation pipelines.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The evaluator attempts self-installation of a new package and may trigger model downloads, which exceeds the expected behavior of a retrieval scoring utility. In a security-sensitive or controlled environment, this can violate change-control boundaries, enable supply-chain compromise, and cause unexpected network access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The header documentation says --fix generates a report, but the implementation also rewrites markdown slice files by altering embedding_hint values. This is a dangerous integrity issue because users may invoke the flag expecting read-only reporting and instead suffer silent modification of source knowledge-base content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The CLI help text for --fix advertises report generation only, while execution under that flag also performs automatic remediation that rewrites user markdown files. Misleading interface semantics increase the chance of unintended destructive changes because operators cannot accurately assess side effects from the documented command.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This wrapper provides a reusable arbitrary command execution primitive that is not obviously justified by the stated purpose of a knowledge-engineering slicing tool. Combined with shell=True on Windows, it materially increases the chance that future callers introduce command injection or unintended execution flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The quickstart tells users to run a document-splitting command that will create output files, but it does not clearly warn that the agent will write to disk, where the files will go by default, or that existing contents may be affected. In a file-processing skill, implicit writes increase the risk of unintended data creation, confusion about output location, and accidental overwrite or disclosure through generated artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The README explicitly describes agent-driven creation, movement, and modification of many files, including changing classifications and auto-skipping/resuming work, but does not clearly warn users about overwrite behavior, destination scoping, or the risk of modifying existing content. In an agent context, vague filesystem side effects increase the chance of unintended data loss or writes outside the user's intended workspace, especially when natural-language commands are used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation states that existing same-name slices will be overwritten, which can cause silent data loss if users point the tool at a populated directory or reuse a Source-ID. Because the skill is designed to perform filesystem writes during normal operation, overwrite behavior without a strong safety interlock is materially dangerous in context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance to clean old slices before regenerating encourages deletion of existing output data without a prominent warning, dry-run, or scoped safeguard. In a workflow that operates on user-supplied paths, this increases the risk of accidental removal of valuable files or incomplete recovery from prior runs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states missing dependencies will be installed automatically, but it does not require a clear consent checkpoint immediately before altering the system. Silent or implicit installation is dangerous because it changes the execution environment, may fetch remote packages, and can surprise users in restricted or production contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Auto-fix rewrites files in place, renames originals to .bak, and then deletes the backup, all without durable rollback or clear user warning. Combined with heuristic filename matching and broad replacement logic, this can permanently damage or silently change knowledge slices, especially in unattended batch runs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Under --fix, the script rewrites markdown slices in place without any confirmation prompt, backup, or transactional safeguard. This can cause unintended content corruption or integrity loss across a knowledge base, especially because the edits are generated heuristically from parsed content rather than validated by the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.