Back to skill

Security audit

Bookmark Organizer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but its optional dead-link check can send network requests to every bookmark, including private or internal URLs, without meaningful safety controls.

Install only if you are comfortable processing bookmark files locally and storing the resulting browsing-history reports on disk. Avoid using --check-links on private, enterprise, or untrusted bookmark exports unless you are comfortable contacting every saved URL from your machine. Do not feed generated Markdown into an AI agent or publish it without reviewing it, because bookmark titles and URLs are written with limited sanitization.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/organize.py:33
Finding

Server-Side Request Forgery Through Unrestricted Bookmark Link Checking

Content
View full analysis
= 400: return (url, status_code, None) except Exception as e: return (url, None, str(e)) return None ``` ```python if args.check_links: urls_to_check = [link['url'] for link in unique_links] print(f"Checking {len(urls_to_check)} links for availability (this may take several minutes)...") with ThreadPoolExecutor(max_workers=10) as executor: future_to_url = {executor.submit(check_url, url): url for url in urls_to_check} for i, future in enumerate(as_completed(future_to_url)): print(f"Progress: {i + 1}/{len(urls_to_check)}", end='\r', file=sys.stderr) result = future.result() if result: dead_links_report.append(result) ``` ### Technical Analysis When `--check-links` is enabled, every URL imported from the bookmark file is passed to `curl`. The only earlier protocol check is `url.startswith('http')`, which does not prevent access to: - Loopback addresses such as `127.0.0.1` or `[::1]` - Private network ranges - Link-local addresses - Cloud metadata services - Internal hostnames - Nonstandard ports - Public URLs that redirect to internal destinations The `-L` option instructs `curl` to follow redirects. Therefore, validating only the original URL would still be insufficient: an apparently public URL can redirect the request to a protected internal address. The command u ...[truncated 1608 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/organize.py:117
Finding

Output Directory Escape Through Unsanitized Category Names

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/organize.py:108
Finding

Unsafe Markdown Generation From Untrusted Bookmark Fields

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation instructs users to optionally probe all bookmarked URLs over the network via --check-links but does not warn that this will generate outbound requests to every saved site. That can leak sensitive browsing interests, internal hostnames, or private service URLs to third parties or trigger access to internal-only resources, especially if bookmark exports contain enterprise or personal links.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

When --check-links is enabled, the script sends every bookmarked URL to remote servers, which can disclose a user's browsing interests, internal hostnames, intranet URLs, or token-bearing links. In this context, bookmark files are often personal or sensitive, so optional link validation without an explicit privacy warning or filtering makes the feature more dangerous.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/organize.py (reported line 38)May include surrounding context.

python
def check_url(url):
    command = ['curl', '-L', '-s', '-o', '/dev/null', '-w', '%{http_code}', '-m', '15', url]
    try:
        result = subprocess.run(command, capture_output=True, text=True, timeout=20)
        if result.returncode != 0:
            return (url, None, f"curl exit code {result.returncode}")
        status_code = int(result.stdout.strip())

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script creates an output directory and writes several markdown files containing bookmark titles, URLs, folders, duplicate groups, and domain frequency summaries. Although file writing is part of the script's purpose, there is no user-facing warning or confirmation that sensitive personal browsing data, including an 'adult-or-sensitive' category, will be materialized into readable reports on disk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The keyword lists contain many highly generic terms such as "art", "image", "music", "audio", "api", "docs", "news", "group", and single-character Chinese tokens like "画" and "图". If these rules are used to trigger skills or classify browsing/activity, they can cause frequent unintended activations or misclassification, which may route user actions into the wrong capability set and undermine safety or permission boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script emits headings and labels such as '共', '文件夹', '书签库索引', and '常用网站推荐清单(基于你的书签)' directly into generated files. This imposes a specific locale on all users without any opt-in, configuration, or documentation indicating that the tool is intentionally region- or language-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.