Back to skill

Security audit

论文精读翻译

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese ArXiv translation workflow, but it directs persistent uploads to Tencent Docs and IMA while using broad triggers and an unsafe temporary file pattern.

Install only if you intend to use this for Chinese translations of public ArXiv papers and are comfortable uploading the results to Tencent Docs and IMA. Before use, add a confirmation step for uploads, avoid private documents, and replace /tmp/args.json with a unique restricted temporary file that is deleted after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:99
Finding

Predictable Shared Temporary File Enables Local File Overwrite and Data Exposure

Content
View full analysis
/tmp/args.json mcporter call tencent-docs create_smartcanvas_by_mdx --args "$(cat /tmp/args.json)" ``` The same fixed-path workflow is repeated in `references/platform-compat.md:54-58`. ### Technical Analysis The documented workflow writes translated document content to the predictable shared path `/tmp/args.json`. Shell output redirection opens this path without exclusive creation, ownership verification, or an explicit restrictive permission mode. In a multi-user environment, another local account can anticipate the filename and attempt to pre-create it as a symbolic link or otherwise manipulate the path before the workflow runs. If operating-system symbolic-link protections do not block the operation, redirection follows the link and truncates or overwrites the linked file with the privileges of the user running the Skill. The generated file contains the complete Markdown document passed through `--rawfile mdx "$FILE"`. Its permissions depend on the process umask. An insufficiently restrictive umask may therefore expose translated content to other local users. The workflow also does not remove the temporary file after upload, leaving document content on disk. This issue does not itself grant arbitrary elevated privileges. The attacker is limited to files writable by the victim process, and successful symbolic-link exploitation may be constrained by platform protections such as Linux `fs.protected_symlinks`. ### Attack Path 1. An attacker with local access observes or infers that the Skill always uses `/tmp/args.json`. 2. Before the victim executes the upload workflow, ...[truncated 1281 chars]
Remediation
View remediation
"$ARGS_FILE" || exit 1 mcporter call tencent-docs create_smartcanvas_by_mdx \ --args "$(cat -- "$ARGS_FILE")" ``` Additional hardening measures: 1. Replace every documented use of `/tmp/args.json`, including the duplicate workflow in `references/platform-compat.md`. 2. Use `mktemp` rather than constructing a temporary filename manually. 3. Set `umask 077` before creation so only the current user can read or modify the file. 4. Install a cleanup trap so sensitive document content is deleted on success, failure, or interruption. 5. Check the exit status of `jq` and stop before invoking the upload command if JSON generation fails. 6. If supported by the upload tool, pass JSON through standard input and avoid writing document content to disk entirely. 7. Where a temporary file remains necessary, verify that it is a regular file owned by the current user before reading it. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的核心能力是“论文中文翻译 + 同步到外部知识库/文档平台”,而代码仅对已存在的 Markdown 文件做静态校验,属于翻译后质检工具。虽然校验逻辑与论文翻译工作流相关,可视为辅助环节,但它并不能完成描述中最主要的翻译和同步任务,因此主用途存在实质性不符。代码也没有网络访问、外部 API 调用、文件上传或文档同步行为,和声明中的外部集成能力明显不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
72% confidence
Finding

The skill instructs use of local files and scripts such as {SKILL_DIR}/scripts/validate_translation.py and local reference documents, but it does not declare an explicit tool scope or permissions boundary. In an agent environment, undeclared file access increases the chance of over-broad filesystem reads or execution against unintended local content, especially because all skill content must be treated as potentially adversarial.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad phrases like '帮我翻译' and 'translate paper', which can cause the skill to activate in contexts beyond ArXiv paper translation. Over-broad invocation can route unrelated user content into a workflow that fetches remote content and uploads results to external services, increasing the risk of unintended data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states that translated content will be uploaded to IMA knowledge base and Tencent Docs, but it does not require a user-facing warning or consent step before transmitting data to third-party platforms. If invoked on private, unpublished, or sensitive documents, this could result in unintentional external disclosure and persistent storage outside the primary system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file is entirely written as mandatory operational guidance in Chinese, beginning with the title and continuing with imperative instructions such as '强制流程'. This creates a natural-language locale constraint without any user opt-in or explanation that the skill is region-specific, which matches the policy's language/locale violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The docstring and validation criteria are written entirely in Chinese and define checks such as Chinese section names and translation-note markers, indicating the skill is designed around a fixed language/locale. The file does not present this as an optional or user-selectable setting, which is a natural-language locale policy concern under the rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script checks specifically for the marker **[译注]** and warns when none are present, which imposes a Chinese-language convention on users. Because no alternative markers or language choice are offered, this is a locale-specific requirement embedded in natural language behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.