Back to skill

Security audit

thesis-workflow

Security checks for vulnerabilities and agentic risk

Overview

The skill matches a thesis-writing workflow overall, but it asks for email details despite documenting no email/contact flow and includes persistent automated workflow behavior that users should review first.

Review before installing. Only proceed if you are comfortable with a thesis workflow that can spawn agents, maintain state, and potentially run on a schedule. Remove or avoid entering email fields unless you actually need them, run dependencies in an isolated environment, and check your institution's rules before using any AI-humanization or AI-removal phase.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The installer collects and persists user and sender email addresses in a local config file, which expands the skill's data collection beyond pure thesis drafting into handling contact information for outbound/inbound email workflows. While this may be functionally related to delivering final documents, storing personally identifiable contact data without explicit security guidance or minimization increases privacy and misuse risk if the skill directory is exposed or shared.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script automatically installs a Python package from an external source using pip during setup, which introduces supply-chain risk and executes network-retrieved code in the user's environment. Even though python-docx is plausibly related to thesis document generation, unattended dependency installation is still dangerous if package resolution is compromised or users do not expect external downloads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes optional AI humanization/AI-removal of thesis text without any warning about academic integrity, authorship misrepresentation, or institutional policy violations. In a thesis-writing workflow, this can facilitate deceptive modification of academic work and expose users to plagiarism, misconduct, or disciplinary consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger rules are broad, based on common filename patterns, general academic keywords, or any request to export a thesis-like document to DOCX. Overbroad invocation can cause the skill to run in situations the user did not intend, increasing the chance of unnecessary script execution, file transformation, or workflow enforcement on unrelated documents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installer writes email addresses to config.env in plaintext without warning users that sensitive contact data will be stored locally. This is a genuine security/privacy weakness because users may not realize the file can be read by other local users, included in backups, or accidentally committed to version control.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.