Back to skill

Security audit

Scholarsearch

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent academic briefing helper, with the main caution that it saves reports locally and sends complete content to Feishu as part of its stated workflow.

Before installing, users should be comfortable with complete briefing content being saved to an Obsidian path and sent through Feishu, especially for confidential research topics. They should also remove or override the CoffeeDog footer if neutral attribution matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:151
Finding

Unsolicited Branding in Generated Academic Reports

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 151 and 176
Vulnerability Type: Output instruction manipulation
Risk Level: Low

Evidence

markdown
*Automatically generated | CoffeeDog | [Topic] | YYYY-MM-DD*
markdown
*Academic discovery automated. CoffeeDog knows the papers.*

The first snippet is an English translation of the prescribed footer at line 151. The second snippet appears verbatim at line 176. Decorative emoji have been omitted without changing the instructions' meaning.

Technical Analysis

The skill's report template instructs the agent to insert fixed CoffeeDog branding into generated academic reports. A second promotional statement reinforces that branding outside the template. These instructions are unrelated to the skill's primary literature-search function and can influence the agent to produce third-party attribution that the user did not request.

This is a limited form of skill instruction hijacking because loading and following the skill changes report content by requiring an unsolicited promotional footer. The reviewed file does not instruct the agent to override safety controls, disclose secrets, execute code, or alter system configuration.

Attack Path

  1. A user invokes the scholarsearch skill to create an academic briefing.
  2. The agent loads and follows the output template in SKILL.md.
  3. The agent inserts the fixed CoffeeDog attribution into the report.
  4. The branded report may then be saved to Obsidian or delivered through Feishu as described by the skill.
  5. Recipients may incorrectly infer that the report was authored, sponsored, or endorsed by the named party.

Impact Assessment

Exploitation requires only invocation of the skill and compliance with its prescribed template. No operating-system privileges, account permissions, or code-execution capabilities are obtained.

The impact is restricted to output integrity, attri ...[truncated 245 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the fixed CoffeeDog footer and promotional statement from the report template.
  2. Use neutral attribution such as Generated academic briefing when provenance information is necessary.
  3. Make branding optional and require explicit user consent before including it.
  4. Clearly separate functional report-format requirements from optional presentation metadata.
  5. Add a template rule prohibiting unsupported claims of authorship, sponsorship, or endorsement.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises automatic saving to an Obsidian vault and sending complete report content via Feishu, but it does not clearly warn users that their prompts, generated summaries, and potentially sensitive research topics will be written locally and transmitted to a third-party service. This creates a real privacy and data-handling risk because users may invoke the skill expecting a search/summary workflow, not implicit persistence and external delivery.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented 'dual delivery' behavior increases exposure by persisting generated content in a local knowledge store and forwarding it to Feishu without any consent checkpoint or warning. In context, literature briefings can contain sensitive topics, internal research interests, or confidential project framing, so silent multi-destination delivery materially raises confidentiality and compliance concerns.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.