Back to skill

Security audit

Skillhub Cn Daily

Security checks for vulnerabilities and agentic risk

Overview

The skill is broadly coherent and disclosed, but it deserves Review because it reads local memory, runs authenticated CLI tools, writes/publishes reports externally, and has weak scoping around dependency install and output paths.

Install only if you want China-focused SkillHub recommendations and are comfortable with local memory keyword processing, authenticated SkillHub CLI use, and optional external publishing. Prefer a pinned local skillhub CLI, verify the IMA/Feishu destinations and credentials, use --skip-push unless you want external uploads, and avoid passing untrusted --date values until path validation is fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.en.md:45
Finding

Unpinned Globally Installed SkillHub CLI Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
``` 2. Prefer a project-local dependency over a global installation and commit the generated lockfile: ```bash npm ci npx --no-install skillhub ... ``` 3. Record and verify package integrity through `package-lock.json` or an equivalent lockfile. 4. Review the pinned package and its transitive dependencies before upgrading. 5. Disable unnecessary npm lifecycle scripts where compatible with the package: ```bash npm ci --ignore-scripts ``` 6. Do not run npm installation with administrator or root privileges. 7. Invoke the expected project-local binary rather than relying on whichever `skillhub` executable appears first in `PATH`. 8. Document a controlled upgrade process that includes dependency review, integrity validation, and regression testing before changing the pinned version. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_skillhub_cn.py:220
Finding

Unvalidated Date Argument Enables Path Traversal and Arbitrary JSON or Markdown File Writes

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (27)

Tainted flow: 'req' from os.environ.get (line 109, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skillhub_cn_daily_executor.py (reported line 120)May include surrounding context.

python
method="POST",
        )

        with urllib.request.urlopen(req, timeout=30) as resp:
            result = json.loads(resp.read().decode("utf-8"))
            note_id = result.get("note_id") or result.get("data", {}).get("note_id")

Tainted flow: 'req2' from os.environ.get (line 135, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · skillhub_cn_daily_executor.py (reported line 146)May include surrounding context.

python
method="POST",
        )

        with urllib.request.urlopen(req2, timeout=30) as resp2:
            result2 = json.loads(resp2.read().decode("utf-8"))

        print(f"  [IMA] OK: note_id={note_id}, kb_id={IMA_KB_ID[:20]}...")

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 84)May include surrounding context.

md
| IMA FIM 知识库 | 两步流程(create_note + add_knowledge) | IMA_OPENAPI_CLIENTID / IMA_OPENAPI_APIKEY / IMA_KB_ID |
| 飞书云文档 | lark-cli / lark-doc skill | 飞书授权 |

> **凭证安全**:所有凭证通过环境变量传递,不硬编码在代码中。请确保环境变量仅在本地配置,不要写入 .env 文件并提交到版本控制。

## 与 ClawHub Daily 互补

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The code substantially matches the recommendation-generation core: it reads local memory files, extracts only keywords for matching, performs 7-day deduplication, computes dimensions such as China-first, active developers, memory collision, and optional evaluation/reports, and writes local recommendation outputs. However, the declared description says this skill calls the skillhub CLI to obtain SkillHub.cn leaderboard and search data and stores the briefing in local files and external services (Obsidian/IMA/Feishu). In this code chunk, candidate skills are not fetched from the network at all; they are loaded from a local snapshot file under data/snapshots. Also, there is no implementation for pushing results to any external service or using the related credentials. These are material description-versus-behavior gaps. The code is therefore a partial implementation of the declared skill rather than an accurate match to the full described behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code matches only a narrow subset of the declared description: it uses the skillhub CLI, performs rankings and search collection, and writes local output files. However, the declared skill is a personalized daily recommendation engine with memory-keyword extraction, deep evaluation/report lookups, safety/quality scoring, and multi-destination publishing. None of those core behaviors are present in this code chunk. Instead, the script behaves as a snapshot fetcher/aggregator for SkillHub.cn data using fixed built-in keywords. This is a material description-behavior mismatch because several headline capabilities and resource accesses in the description are absent, and the actual primary purpose of this chunk is dataset collection rather than recommendation generation and distribution.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
2. python scripts/daily_recommend.py --data-dir data --skip-eval

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises and requires sensitive capabilities including environment-variable access, local file read/write, network access, and shell/CLI execution, but it does not declare an explicit tool scope or permission boundary. That creates an authorization and review gap: operators and users cannot verify which actions are intended, and a runtime may overgrant powerful capabilities to a skill that processes local memory and writes to external destinations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

"claimable": false, "created_at": 1773023560715, "updated_at": 1783822732293, "homepage": "https://api.skillhub.cn/zhengxinjipai/self-improving-agent-cn" }

text

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The output specification labels the generated brief as a '中文结构化简报', which indicates the skill is designed to produce Chinese-language output. The document does not offer an opt-in, alternative locale, or user choice, so this appears to impose a language preference unilaterally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script reads local memory files containing potentially sensitive project and profile data and mines them for keywords without runtime consent, notice, minimization controls, or scoping checks beyond a path variable. Even if only keywords are surfaced, the act of processing private memory can expose interests, technologies, or business context and may violate user expectations or deployment policy.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script derives matched keywords from user memory and uses the count and recommendation rationale to influence output artifacts written to disk. Even without dumping raw memory text, this can leak sensitive behavioral or project signals through inference, especially if recommendation files are synced to external systems like Obsidian, IMA, or Feishu as described in the skill metadata.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/daily_recommend.py (reported line 242)May include surrounding context.

python
def fetch_evaluation(slug):
    """调用 skillhub skill evaluation 获取 AI 质量评估"""
    try:
        result = subprocess.run(
            [SKILLHUB_BIN, "skill", "evaluation", slug, "--json"],
            capture_output=True, text=True, timeout=30
        )

Tainted flow: 'SKILLHUB_BIN' from os.environ.get (line 16, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
95% confidence
Finding

The code allows SKILLHUB_BIN to be taken from an environment variable and then executes it directly. If an attacker can influence the environment or PATH in the runtime context, they can cause the script to run a malicious binary, resulting in arbitrary code execution under the privileges of the skill process.

Content

Scanner excerpt · scripts/daily_recommend.py (reported line 242)May include surrounding context.

python
def fetch_evaluation(slug):
    """调用 skillhub skill evaluation 获取 AI 质量评估"""
    try:
        result = subprocess.run(
            [SKILLHUB_BIN, "skill", "evaluation", slug, "--json"],
            capture_output=True, text=True, timeout=30
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/daily_recommend.py (reported line 268)May include surrounding context.

python
def fetch_reports(slug):
    """调用 skillhub skill reports 获取双实验室安全审计"""
    try:
        result = subprocess.run(
            [SKILLHUB_BIN, "skill", "reports", slug, "--json"],
            capture_output=True, text=True, timeout=30
        )

Tainted flow: 'SKILLHUB_BIN' from os.environ.get (line 16, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
95% confidence
Finding

This call repeats the same unsafe trust boundary: an executable path sourced from environment configuration is invoked without validation. In environments where users, wrappers, or other skills can set environment variables, this becomes a straightforward arbitrary-command execution vector.

Content

Scanner excerpt · scripts/daily_recommend.py (reported line 268)May include surrounding context.

python
def fetch_reports(slug):
    """调用 skillhub skill reports 获取双实验室安全审计"""
    try:
        result = subprocess.run(
            [SKILLHUB_BIN, "skill", "reports", slug, "--json"],
            capture_output=True, text=True, timeout=30
        )

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings and function descriptions explicitly generate a Chinese briefing and present China-first behavior as the default, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language content in the module docstring and printed status messages is exclusively Chinese, which effectively forces a specific language for users of the skill file. There is no indication of opt-in, locale selection, or a documented justification that this script is intentionally restricted to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

The script executes an external program via subprocess.run, and the executable path is influenced by dynamic resolution. In this skill's context, that means the code will trust and run whichever 'skillhub' binary is found first in PATH or supplied indirectly, creating a code-execution boundary on the local machine. Because this skill is designed to run regularly and has network/file permissions, a hijacked or trojaned CLI binary would execute with the user's privileges.

Content

Scanner excerpt · scripts/fetch_skillhub_cn.py (reported line 43)May include surrounding context.

python
"""执行 skillhub CLI 命令"""
    cmd = [SKILLHUB_BIN] + args
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout)
        return result.stdout.strip(), result.returncode
    except Exception as e:
        return "", 1

Tainted flow: 'cmd' from os.environ.get (line 41, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
97% confidence
Finding

SKILLHUB_BIN is derived from os.environ.get("SKILLHUB_BIN", "skillhub"), so an attacker who can influence environment variables or PATH can redirect execution to an arbitrary binary. That becomes direct arbitrary code execution when subprocess.run launches the constructed command. In an agent skill that reads local memory and writes local artifacts, this significantly increases risk because the malicious replacement gains access to the same local context and permissions.

Content

Scanner excerpt · scripts/fetch_skillhub_cn.py (reported line 43)May include surrounding context.

python
"""执行 skillhub CLI 命令"""
    cmd = [SKILLHUB_BIN] + args
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout)
        return result.stdout.strip(), result.returncode
    except Exception as e:
        return "", 1

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language interface, including the title and usage examples, is entirely in Chinese. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · skillhub_cn_daily_executor.py (reported line 42)May include surrounding context.

python
print(f"  STEP: {name}")
    print(f"{'='*60}")
    start = time.time()
    result = subprocess.run(cmd, cwd=str(PROJECT_ROOT), capture_output=False, text=True)
    elapsed = time.time() - start
    if result.returncode != 0:
        print(f"  [FAIL] {name} ({elapsed:.1f}s)")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · skillhub_cn_daily_executor.py (reported line 167)May include surrounding context.

python
try:
        # 使用 lark-cli 创建文档
        cmd = ["lark-cli", "doc", "create", "--title", title, "--content-stdin"]
        result = subprocess.run(
            cmd,
            input=content,
            capture_output=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The document frames the skill as 'China-Focused' and emphasizes 'China adaptation' as a primary selection criterion. This is a natural-language locale preference, and the README does not indicate that users can opt in or choose a different locale context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The generated briefing presents security audits and AI evaluation as a standard property of the output even when --skip-eval is used or calls fail. This can mislead users into trusting recommendations as audited when they were not, creating a security-signaling integrity issue that may influence risky adoption decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The data-explanation section states that deep evaluation and security audit are part of the report regardless of execution outcome. That overstates the assurance level and can cause consumers to rely on nonexistent review data, especially problematic in a tool recommending third-party skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.