Back to skill

Security audit

Content Swarm

Security checks for vulnerabilities and agentic risk

Overview

This content workflow is mostly coherent, but it asks agents to write persistent files and potentially publish externally without enough declared permissions, scoping, or approval controls.

Review before installing. Use this skill only if you want a Chinese-language content workflow with local task archives and platform distribution. Require explicit confirmation before any public posting, restrict writable paths to a dedicated workspace, sanitize topic names, and align permissions with actual file-write behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:88
Finding

Unsanitized Topic Allows Path Traversal and File Overwrite

Content
View full analysis
~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF' # 任务计划 - 内容生产 ## 🎯 目标 完成 {主题} 的多平台内容生产+分发 ## 📋 步骤 - [ ] Phase 1: 选题策划(优先级:高) - 输入:主题/关键词 - 处理:热点追踪+爆款公式 - 输出:内容框架 - [ ] Phase 2: RAG检索(优先级:高) - 输入:内容框架 - 处理:IMA知识库检索 - 输出:历史爆款参考 - [ ] Phase 3: 内容创作(优先级:高) - 输入:内容框架+RAG结果 - 处理:content-factory - 输出:多平台内容 - [ ] Phase 4: 封面设计(优先级:中) - 输入:内容标题 - 处理:guizang-social-card - 输出:多平台封面图 - [ ] Phase 5: 多平台分发(优先级:中) - 输入:内容+封面 - 处理:social-auto-upload - 输出:发布链接 ## ✅ 验收标准 1. AI痕迹检测通过(anti-ai-slop) 2. 平台尺寸合规 3. 含行动号召(转化预期) 4. 品牌调性一致 ## 📅 时间线 - 创建时间:{ISO8601} - 预计完成:{日期} - 实际完成:{日期} EOF touch ~/.workbuddy/tasks/"$TASK_NAME"/research-findings.md cat > ~/.workbuddy/tasks/"$TASK_NAME"/progress-log.md << 'EOF' # 进度日志 - 内容生产 ## ✅ 已完成 (任务启动后填充) ## 🔄 进行中 - [ ] Phase 1: 选题策划(预计 $(date +%Y-%m-%d) 完成) ## 🚨 阻塞 (如有问题和解决方案,在此记录) ## 📍 下一步 1. 选题策划 2. RAG检索 3. 内容创作 4. 封面设计 5. 多平台分发 EOF ``` ### Technical Analysis The externally influenced `TOPIC` value is incorporated directly into `TASK_NAME`, which is then used as a directory component for multiple filesystem operations. Although quoting the variable prevents ordinary shell metacharacter injection, it does not prevent pathname traversal. A topic containing slash characters and `..` components can cause the constructed path to resolve outside the intended `~/.workbuddy/tasks` directory. The commands then: - Recursively create directories using `mkdir -p`. - Create or update `research-findings.md` using `touch`. - Truncate and overwrite `task-plan.md` and `progress-log.md` using `cat >`. The fixed `content-` prefix and date suffix constrain which paths can be selected, but they do not eliminate traversal. An ...[truncated 1907 chars]
Remediation
View remediation
&2 exit 1 } TASK_NAME="content-${SAFE_TOPIC}-$(date +%Y%m%d)" ``` 2. **Validate the canonical destination** - Canonicalize both the task root and destination before writing. - Verify that the destination remains a descendant of the canonical task root. - Abort if canonicalization reveals traversal outside that root. 3. **Use a securely created task directory** - Prefer `mktemp -d` under the trusted task root rather than constructing a directory solely from user-controlled text. - Use the sanitized topic only as a descriptive component. ```bash TASK_ROOT="$HOME/.workbuddy/tasks" mkdir -p -- "$TASK_ROOT" TASK_DIR=$(mktemp -d "$TASK_ROOT/content-${SAFE_TOPIC}-$(date +%Y%m%d)-XXXXXX") ``` 4. **Prevent unintended overwrites** - Enable no-clobber behavior with `set -o noclobber`, or explicitly test for existing files before redirecting. - Require confirmation before replacing any existing task record. - Open files using mechanisms that reject symbolic links where supported. 5. **Apply least privilege** - Run the Skill with access limited to its designated workspace. - Align the declared permissions with actual behavior, because the documented workflow performs filesystem writes even though the metadata only declares `file-read` and `network-access`. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Scope Creep

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill declares only file-read permission, but its documented workflow explicitly creates directories and writes multiple files under ~/.workbuddy/tasks, and also prescribes output archival under ~/WorkBuddy/content. This is a real capability/permission mismatch that can mislead operators and agents into performing unauthorized local writes, creating persistent artifacts and possibly overwriting user data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The when_to_use field contains very broad, common content-related trigger phrases such as writing copy, making content, and multi-platform distribution. Overly generic activation criteria increase the chance that the skill is invoked in unrelated contexts, which can unexpectedly steer an agent into persistence, RAG, or publishing workflows the user did not intend.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that external publishing requires confirmation, but later operational steps instruct direct publishing to Douyin, Xiaohongshu, Bilibili, and Kuaishou without an enforced approval checkpoint. This inconsistency is dangerous because an automated agent could treat the publish steps as authorized and post externally without human review, causing reputational or compliance harm.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger section repeats ambiguous phrases like 写文案, 做内容, and 生成内容 without clear boundaries or scoping. In a skill with network access and documented publication steps, ambiguous activation materially raises the risk of accidental execution of broader workflows than the user requested.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding identifies the same persistence behavior: creating ~/.workbuddy/tasks and writing task-plan.md, research-findings.md, and progress-log.md. In the context of a content-generation workflow, these files may capture commercially sensitive plans and publishing history, making unintended retention more dangerous than a purely transient drafting tool.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

bash
TASK_NAME="content-${TOPIC}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 内容生产

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicate finding identifies the same persistence behavior: creating ~/.workbuddy/tasks and writing task-plan.md, research-findings.md, and progress-log.md. In the context of a content-generation workflow, these files may capture commercially sensitive plans and publishing history, making unintended retention more dangerous than a purely transient drafting tool.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

bash
TASK_NAME="content-${TOPIC}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 内容生产

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a fixed Chinese-language workflow, with no indication that users may choose another language or locale. Under the policy, a fixed language without opt-in can be a natural-language policy violation unless explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Throughout the skill file, headings, deliverables, trigger phrases, and workflow instructions are all specified in Chinese, and no section offers users a language or locale choice. This creates a default language constraint that is not presented as optional or region-justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.