Back to skill

Security audit

Learning Notes Explorer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed personal-notes search helper with limited local read behavior and no evidence of persistence, exfiltration, or destructive actions.

Install this only if you want the agent to search and summarize your personal learning notes. Keep the configured note file limited to material you are comfortable exposing in agent responses, and be aware that broad note-related prompts may activate the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes capabilities that require reading from note storage, including local files, Obsidian vaults, or Notion, but it does not declare an explicit tool scope such as allowed tools or permissions. This creates an authorization ambiguity where the runtime may over-grant file access or invoke the skill without clear least-privilege boundaries, increasing the risk of unintended exposure of sensitive personal notes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger language is broad enough to match generic note-related or learning-related requests, which can cause the skill to activate when the user did not intend to search a personal knowledge base. In this context, unintended activation is more dangerous because the skill is designed to access potentially sensitive personal notes, so over-selection can lead to unnecessary data retrieval or privacy-invasive responses.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · handler.py (reported line 118)May include surrounding context.

python
matched_sections[note_id] = []
                    matched_sections[note_id].append(f"...{context}...")
        
        # Sort by score and create results
        sorted_notes = sorted(scores.items(), key=lambda x: x[1], reverse=True)
        results = []
        for note_id, score in sorted_notes[:limit]:

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description uses very broad activation cues such as note organization, review, knowledge search, and query across topics, which can overlap with many ordinary user requests and cause the skill to be invoked outside a narrowly intended scope. Because this skill interfaces with a personal knowledge base, over-broad routing increases the chance of unintended access, summarization, or exposure of private notes in response to generic prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The description and trigger examples prominently prescribe Chinese phrases for use of the skill, which can imply a language-specific interaction model. The file does not explicitly state that users may choose their preferred language or that Chinese is optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The code explicitly states support for English and Chinese and tokenizes only those languages, while the bundled demo content and generated outputs include Chinese text. This creates a locale preference baked into the skill without any user opt-in or documented language-selection behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest description presents activation examples in Chinese ('笔记整理、学习回顾、知识搜索、笔记查询') without stating that the skill supports other languages or that Chinese is optional. This can amount to an implicit language preference in the skill's natural-language policy surface.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.