Back to skill

Security audit

academic-pipeline-suite

Security checks for vulnerabilities and agentic risk

Overview

The suite is a legitimate academic workflow package, but it includes overbroad browser control and credential-handling paths that need careful review before installation.

Install only if you are comfortable with a suite that can replace multiple local skills, access IMA notes and knowledge bases using your API credentials, and automate your regular Chrome session. Avoid enabling Chrome remote debugging for your daily browser profile, do not set IMA_BASE_URL or pass custom baseUrl values, review any update instructions as untrusted text, and follow your institution's AI-use disclosure rules before using the humanizer stages for academic submissions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
skills/ima-skills/ima_api.cjs:110
Finding

Remote Update Response Is Treated as Trusted Agent Instruction

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/ima-skills/ima_api.cjs:65
Finding

IMA API Credentials Can Be Redirected to an Arbitrary Server

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
skills/academic-search/scripts/cdp-proxy.mjs:379
Finding

Unauthenticated Local CDP Proxy Grants Privileged Control of the User's Browser

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills/academic-search/scripts/cdp-proxy.mjs:525
Finding

Screenshot Endpoint Allows Arbitrary File Overwrite

Content
View full analysis
&file=
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (238)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

A mandatory '去 AI 化处理' stage is explicitly presented as part of the pipeline and cannot be skipped, which strongly suggests intentional concealment of AI-generated authorship rather than transparent editing assistance. In the context of academic writing, this is especially dangerous because it can facilitate academic misconduct, policy evasion, and deceptive submission of machine-generated work as human-authored content.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The described browser automation via CDP proxy, local HTTP API testing, screenshot capture, file interaction, navigation, and process spawning are privileged behaviors not aligned with the skill's stated purpose. Such mismatches are dangerous because they can mask broad local-control functionality behind an innocuous installation narrative.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The script performs recursive deletion with rm -rf on a path rooted in $HOME without first ensuring the parent target directory exists, is the expected location, and is safe to modify. If $TARGET_DIR is a symlink, points somewhere unexpected, or the workspace path has been manipulated, the installer could delete unintended directories for each listed skill.

Content

Scanner excerpt · install.sh (reported line 44)May include surrounding context.

sh
for skill in "${DEPENDENCIES[@]}"; do
    if [ -d "$SKILLS_DIR/$skill" ]; then
        echo "   安装 $skill..."
        rm -rf "$TARGET_DIR/$skill"
        cp -r "$SKILLS_DIR/$skill" "$TARGET_DIR/"
        echo "   ✅ $skill 安装成功"
    else

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · skills/academic-pipeline/agents/pipeline_orchestrator_agent.md (reported line 112)May include surrounding context.

md
- "skip" -> validate skip safety; proceed if allowed

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · skills/academic-pipeline/agents/state_tracker_agent.md (reported line 470)May include surrounding context.

md
---

## Dashboard Output Rules

1. Produce full version when user explicitly requests it
2. **Append simplified version to checkpoint notification after each stage completion**

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · skills/academic-search/SKILL.md (reported line 178)May include surrounding context.

已知 DOI 或 arXiv ID 时,直接用 Semantic Scholar 精确查询:

bash
# DOI 查询
curl -s "https://api.semanticscholar.org/graph/v1/paper/DOI:{doi}?fields=title,authors,year,abstract,citationCount,openAccessPdf"

# arXiv ID 查询
curl -s "https://api.semanticscholar.org/graph/v1/paper/ARXIV:{arxiv_id}?fields=title,authors,year,abstract,citationCount,openAccessPdf"

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

This pattern combines network interaction with piping data into Node for processing while creating a target in a local CDP proxy tied to the user's browser. In context, the higher risk is not the JSON parsing itself but that the recipe operationalizes browser-session automation against external sites, enabling an agent to pivot into a trusted browser context.

Content

Scanner excerpt · skills/academic-search/references/api-cookbook.md (reported line 279)May include surrounding context.

md
bash ~/.claude/skills/academic-search/scripts/check-deps.sh

# 2. 打开 Google Scholar 搜索页
TARGET=$(curl -s "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/new?url=https://scholar.google.com" | node -p "JSON.parse(require('fs').readFileSync(0, 'utf8')).targetId")

# 3. 用搜索框搜索(GUI 方式,最稳定)
curl -s -X POST "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/eval?target=$TARGET" \

External Script Fetching

High
Category
Supply Chain
Confidence
93% confidence
Finding

This opens CNKI through a local CDP proxy and processes the returned target identifier, setting up automation over a potentially authenticated browser session. Because CNKI access may rely on institutional credentials, the context makes this materially more dangerous than ordinary external fetches.

Content

Scanner excerpt · skills/academic-search/references/api-cookbook.md (reported line 330)May include surrounding context.

md
bash ~/.claude/skills/academic-search/scripts/check-deps.sh

# 2. 打开知网检索页(KNS8 新版界面)
TARGET=$(curl -s "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/new?url=https://kns.cnki.net/kns8/defaultresult/index" \
  | node -p "JSON.parse(require('fs').readFileSync(0, 'utf8')).targetId")

# 3. 等待页面加载(JS 渲染较慢)

External Script Fetching

High
Category
Supply Chain
Confidence
92% confidence
Finding

The eval-based CDP commands execute arbitrary JavaScript in the target page context after establishing browser control. In an agent skill, this is a strong capability that can read page state and potentially be extended to act on behalf of the user, especially dangerous when the target may be behind login or institution-based access.

Content

Scanner excerpt · skills/academic-search/references/api-cookbook.md (reported line 337)May include surrounding context.

md
sleep 3

# 4. 填入搜索词
curl -s -X POST "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/eval?target=$TARGET" \
  -d 'document.querySelector("#txt_SearchText").value = "大语言模型 时序预测"'

# 5. 点击检索按钮

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · skills/academic-search/references/site-patterns/cnki.net.md (reported line 44)May include surrounding context.

bash
# 1. 打开 KNS8 检索页
TARGET=$(curl -s "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/new?url=https://kns.cnki.net/kns8/defaultresult/index" \
  | node -p "JSON.parse(require('fs').readFileSync(0, 'utf8')).targetId")

# 2. 等待 JS 渲染(知网首次加载较慢)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · skills/academic-search/references/site-patterns/scholar.google.com.md (reported line 21)May include surrounding context.

bash
# 从首页搜索框操作,不直接构造 /scholar?q= URL
TARGET=$(curl -s "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/new?url=https://scholar.google.com" | node -p "JSON.parse(require('fs').readFileSync(0, 'utf8')).targetId")

# 等待页面加载后输入搜索词
curl -s -X POST "http://127.0.0.1:${CDP_PROXY_PORT:-3456}/eval?target=$TARGET" \

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script exposes a local HTTP API that can attach to the user's regular Chrome instance via the DevTools Protocol and then create tabs, navigate, click, upload files, take screenshots, and execute arbitrary JavaScript. In the context of an academic-search skill, that is far broader than necessary and creates a powerful browser-control bridge to the user's authenticated browsing session, enabling access to sensitive sites and data if any local agent or process can reach the proxy.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The /eval endpoint executes arbitrary JavaScript in the context of the selected browser tab using Runtime.evaluate, with no authentication, confirmation, or action restriction. Because the proxy operates against the user's real Chrome session, this can read page contents, interact with authenticated applications, and trigger privileged actions on websites the user is logged into.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · skills/deep-research/agents/ethics_review_agent.md (reported line 56)May include surrounding context.

md
| **Low** | Unlikely misuse, minimal harm potential | General education research |
| **Moderate** | Could be misused in specific contexts | Surveillance tech analysis, social manipulation studies |
| **High** | Clear potential for harm if misused | Vulnerability research, weapons-related |
| **Critical** | Should not be published without safeguards | Specific exploitation methods |

For Moderate or above: Include explicit "Responsible Use" statement

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · skills/deep-research/agents/ethics_review_agent.md (reported line 104)May include surrounding context.

md
| **Low** | Unlikely misuse, minimal harm potential | General education research |
| **Moderate** | Could be misused in specific contexts | Surveillance tech analysis, social manipulation studies |
| **High** | Clear potential for harm if misused | Vulnerability research, weapons-related |
| **Critical** | Should not be published without safeguards | Specific exploitation methods |

For Moderate or above: Include explicit "Responsible Use" statement

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · skills/deep-research/agents/source_verification_agent.md (reported line 99)May include surrounding context.

md
- [ ] The source is suspiciously perfect (exactly supports the claim with no caveats)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The activation text is extremely broad and includes common everyday phrases like '帮我记一下' and general references to notes, files, and knowledge search. This can cause unintended invocation of a credentialed skill and route unrelated user content into external API operations, increasing the risk of data exfiltration, privacy violations, and unauthorized actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill documentation describes note creation flows but does not require a warning, preview, or explicit confirmation before persisting user-provided content. Without this safeguard, the agent may be manipulated into storing sensitive data, hallucinated content, or prompt-injected material, turning transient conversation into durable private records.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The create-note triggers include broad phrases such as 'generate note' or 'save this content as a note,' which can cause a write action from loosely phrased user input. Write operations are higher risk because an agent can persist unintended, sensitive, or prompt-injected content into the user's notes without a strong confirmation boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The append flow lacks an explicit confirmation requirement even though it changes existing stored data. This makes the skill susceptible to prompt injection, accidental modification, and data integrity issues because a casual or ambiguous instruction can become a permanent alteration to a user note.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Append operations modify existing user data, and the trigger examples are too broad for such a sensitive action. An agent could append injected, mistaken, or privacy-sensitive text to the wrong note based on ambiguous phrasing, causing integrity loss and unintended persistence of harmful content.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
skills/ima-skills/ima_api.cjs:31

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
skills/ima-skills/knowledge-base/scripts/cos-upload.cjs:96