Back to skill

Security audit

zotero-paper

Security checks for vulnerabilities and agentic risk

Overview

This Zotero paper-saving skill is mostly coherent, but it needs Review because it can automatically fetch a URL-derived PDF and upload it to Zotero using the user's API credentials.

Review this skill before installing. Use a least-privilege Zotero API key, expect it to create Zotero items and upload attachments, and avoid processing untrusted paper URLs unless the PDF download logic is tightened to accept only canonical HTTPS arxiv.org URLs with size and content validation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/save_paper.py:97
Finding

Insufficient URL Validation Enables Server-Side Request Forgery and Unintended Data Upload

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/save_paper.py:2
Finding

Unpinned Runtime Dependency Permits Unreviewed Supply-Chain Changes

Content
View full analysis
=3.10" # dependencies = ["pyzotero>=1.6.0"] # /// ``` ### Technical Analysis The dependency declaration permits any current or future `pyzotero` version greater than or equal to 1.6.0. The documented `uv run` execution flow may therefore resolve and install a package version that was not present or reviewed when the skill was audited. There is no exact version constraint, dependency lockfile, or package hash in the audited project. This weakens build reproducibility and leaves future executions dependent on the continuing integrity and compatibility of the package repository and all permitted releases. This finding does not establish that the current `pyzotero` package is malicious. The risk is that a compromised, malicious, or unexpectedly incompatible future release could be selected automatically. ### Attack Path 1. The user executes the documented `uv run` command. 2. The package manager resolves `pyzotero>=1.6.0`. 3. A newer unreviewed release is selected from the configured package repository. 4. The package is installed and imported by the script. 5. Import-time or runtime package code executes with the privileges and environment of the skill process. 6. Such code could access `ZOTERO_CREDENTIALS`, user-supplied metadata, local files readable by the process, and available network resources. ### Impact Assessment A compromised dependency would execute with the same operating-system and network privileges as the user running the skill. It could potentially read the Zotero API credentials from the environment, modify Zotero library content, access files available to the process, or transmit sensitive information. The issue does not independently provide elevated system privileges. Its scope is bounded by the p ...[truncated 78 chars]
Remediation
View remediation
=3.10" # dependencies = ["pyzotero=="] # /// ``` The placeholder should be replaced with an actual audited release, and the complete resolved dependency graph should be locked. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises behavior that requires environment-variable access and network communication, but it does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens transparency and policy enforcement, making it harder for users or the platform to understand that credentials will be read and data will be transmitted to Zotero.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code forces a specific language in its command-line description and help text, which is a natural-language policy concern when no user opt-in or locale justification is provided. The same pattern continues in runtime messages, indicating the skill assumes Chinese-only interaction by default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script behavior exceeds the declared skill scope by automatically downloading a PDF from arXiv and uploading it to Zotero as an attachment. This creates an integrity and trust problem: users or calling agents may believe the skill only saves metadata, while it also performs external network retrieval and content ingestion, which can introduce unreviewed files into a user's library and trigger unexpected data transfer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to store Zotero credentials in ZOTERO_CREDENTIALS, but it does not clearly warn that those credentials will be used to authenticate outbound requests that transmit paper metadata and possibly summaries to Zotero. This is a disclosure/consent weakness: users may provide secrets without fully understanding the external data flow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All user-facing natural-language content in the manifest description and markdown instructions is in Chinese, and there is no indication that users may interact in another language or that the locale restriction is intentional. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.