Back to skill

Security audit

Book to Mentor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed book-to-mentor generator that reads user-provided documents, creates local mentor files, optionally checks GitHub for updates, and keeps local learning records.

Install only if you are comfortable letting it read the specific book or document paths you provide and write a local mentor directory plus learning records. Avoid pointing it at broad private folders unless you intend those supported documents to be extracted. The update check contacts GitHub only when requested.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code chunk does not implement the main declared functionality of transforming a book/document into a tutor skill. Instead, it solely checks for software updates by reading a local version file and making an HTTP request to the GitHub releases API. While the description mentions checking book-to-mentor updates as one possible use case, this code supports only that narrow maintenance function and none of the core mentor-generation behavior. Because the actual code’s primary purpose is materially different from the declared overall skill description, this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code chunk is a standalone extractor, not a system that transforms a book into a mentor skill. Its functions focus on parsing document formats, validating extracted text, handling file/glob inputs, collecting supported files, estimating tokens, and writing extraction outputs and diagnostics. While text extraction could be a supporting step in a larger book-to-mentor pipeline, the declared description centers on creating an educational mentor skill with explanations, practice, and records, none of which appear in this code. Therefore the description materially overstates and misrepresents the actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code is narrowly focused on learning-record persistence: it validates observation events, writes state/state.json and learnings.md, supports initialization, recording, and display, and includes file-locking/symlink protections. While 'learning records' are mentioned in the declared description, the overall declared purpose is a much broader book-to-mentor conversion workflow driven by a book path and requests to create/update a mentor skill. None of that functionality appears here: there is no book parsing, no mentor-skill generation, no source-grounded tutoring content creation, and no document update checking. This is therefore a material description-behavior mismatch, not merely an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a skill whose purpose is to convert a book or document into a dedicated mentor/tutor skill. The supplied code does not implement conversion or generation behavior. Instead, it is a validator for a mentor directory's loadable structure and state, as reinforced by the module docstring and returned scope string stating it covers 'structure and state only.' This is a materially different primary purpose, not just a supporting detail of conversion, because the code only audits an output artifact and does not process a book/document into a mentor skill.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
- `SKILL.md`: single-line `name` and `description` frontmatter, source-supported concepts/frameworks, activation conditions, chapter routing, teaching engine, a

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

python /scripts/mentor_state.py init --language <en|zh-CN>

text

Chinese uses `zh-CN`; English and other languages use `en` for generated record labels. Event notes and lessons can use the learner's language. Existing records keep their stored language; records without a language field retain legacy Chinese labels. Never reset history to change presentation.

`state/state.json` is authoritative and `learnings.md` is derived. Follow the schema: distinguish real observations from simulations and hinted answers from independent application, delayed recall, and unassessed understanding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill explicitly instructs the agent to read and write files and to perform a network update check, yet it declares no tool scope such as permissions or allowed-tools. That creates an authorization gap where consumers cannot reliably tell that the skill may access the filesystem and external network, increasing the chance of unintended data exposure or policy bypass.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L28 says the extractor's terminal prompts still remain in Chinese. This imposes a specific language on users and operators without indicating any opt-in, configurability, or region-specific justification, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/check_update.py (reported line 12)May include surrounding context.

python
REPOSITORY = 'gengwenhao/book-to-mentor'
RELEASES = f'https://github.com/{REPOSITORY}/releases'
API = f'https://api.github.com/repos/{REPOSITORY}/releases/latest'


def version_tuple(value):

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/extract.py (reported line 36)May include surrounding context.

python
def _try_import(name):
    try:
        __import__(name)
        return True
    except Exception:
        return False

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code applies a default language of zh-CN when validating state, and the rest of the script renders user-facing output based on that setting. Because the default locale is imposed rather than selected by the user, it constitutes a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L28 states that extraction diagnostics currently remain Chinese, which imposes a specific language behavior in the skill documentation. The file does not indicate any user choice, opt-in, or region-specific justification for this locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains hardcoded user-facing strings in Chinese, such as the availability report header and status text, without any user opt-in or configurable locale selection. That can violate a language/locale policy when the skill is expected to be generally usable across users or environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The unsupported-format error is emitted only in Chinese, and similar Chinese-only CLI help strings appear elsewhere in the file. Without opt-in, fallback, or documentation that this is a Chinese-language tool, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argument help text and missing-argument error message are presented only in Chinese. Because the file does not offer a language option or explain a region-specific restriction, this can conflict with organizational expectations around language neutrality or user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.