Back to skill

Security audit

赛博鲁班日记

Security checks for vulnerabilities and agentic risk

Overview

This diary skill does what it says, but it sends sensitive diary content and a long-lived Feishu-linked token to an external service with limited privacy and credential-handling disclosure.

Review this carefully before installing. Use it only if you are comfortable sending diary entries, dates, AI-analysis requests, and a Feishu-linked long-lived token to image.yezishop.vip. Avoid submitting secrets or highly sensitive personal information, rotate the token if exposed, and look for privacy, retention, deletion, and AI-provider details from the service operator.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:31
Finding

Long-Lived Authentication Token Exposed in Request URLs

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:27
Finding

Private Diary Content Transmitted to an External Service Without Adequate Privacy Disclosure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to send diary content and a token-authenticated request to a third-party remote service without a prominent privacy warning or data-handling disclosure. Because diary entries are inherently sensitive personal data, users may unknowingly transmit private information off-platform, creating confidentiality and consent risk even if the transmission is the intended function.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This command explicitly transmits diary contents and an account-linked token to an external internet service. External transmission is expected for this skill, but it is still security-relevant because highly sensitive personal content is leaving the local environment and the token is embedded in the request URL, which can increase exposure through logs, history, or intermediaries.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

When the user wants to save or push a diary entry for a specific date:

bash
curl -s -X POST "https://image.yezishop.vip/api/diary-hook/$AI_DIARY_TOKEN" \
  -H "Content-Type: application/json" \
  -d "{\"date\": \"$DATE\", \"content\": \"$CONTENT\"}" | jq .

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The analysis feature sends stored diary content to an AI-powered endpoint but does not clearly warn users that sensitive personal writings will be processed by AI. This creates a meaningful privacy risk because users may expect local retrieval or simple metadata processing, not secondary analysis of intimate content by an external model-backed service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill's manifest name and heading are presented only in Chinese, while the rest of the description is in English, with no indication that the skill is intentionally region-specific or that users may choose their preferred language. This can conflict with language/locale policy expectations when a skill imposes a language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.