Back to skill

Security audit

进击的知识库

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its stated knowledge-base purpose, but it uses unsafe command execution and under-discloses external link processing that could expose user data or allow local command injection.

Review this skill carefully before installing. Only use it in a constrained environment with trusted links and files, least-privilege Tencent Docs authorization, and awareness that content will be uploaded to Tencent Docs/COS. Avoid using agent.py until shell=True command construction is fixed, and require explicit consent before sending WeChat Channels links to the external parser endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
agent.py:62
Finding

<![CDATA[Arbitrary Command Execution Through Shell-Interpolated User Input]]>

Content
View full analysis
str: r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=timeout) if r.returncode != 0: raise RuntimeError(f"命令失败: {cmd[:80]}\n{r.stderr[:300]}") return r.stdout.strip() ``` User-controlled URLs are interpolated into commands: ```python dump = json.loads(run(f'yt-dlp --dump-json --no-playlist "{url}"', timeout=30)) ``` ```python cmd = f'yt-dlp -f bestvideo+bestaudio/best --merge-output-format mp4 -o "{out_tmpl}" --no-playlist "{url}"' out = run(cmd, timeout=300) ``` ```python title = run(f'yt-dlp --get-title "{url}"', timeout=30).strip() ``` ```python author = run(f'yt-dlp --get-uploader "{url}"', timeout=30).strip() ``` User-controlled paths and filenames are also interpolated: ```python md5 = run(f'certutil -hashfile "{file_path}" MD5 ^| find /v "MD5" ^| find /v "^$"').replace(" ", "") print(f" [上传] {file_path.name} ({size // 1024}KB)...") # pre_import pre = json.loads(run(f'mcporter call tencent-docs manage.pre_import --args {{"file_name":"{file_path.name}","file_size":{size},"file_md5":"{md5}"}}')) ``` Index records are serialized and then inserted into an unquoted shell command: ```python args = json.dumps({"file_id": INDEX_FILE_ID, "sheet_id": INDEX_SHEET_ID, "records": [{"fields": record}]}) run(f'mcporter call tencent-docs smartsheet.add_records --args {args}') ``` ### Technical Analysis The common `run()` helper invokes `subprocess.run()` with `shell=True`. Several callers construct command strings using URLs, file paths, filenames, environment-derived identifiers, or JSON records. Wrapping a value in double quotes is not sufficient shell escaping. An attacker can include a closing quote followed by platform-spec ...[truncated 1900 chars]
Remediation
View remediation
str: result = subprocess.run( cmd, shell=False, capture_output=True, text=True, timeout=timeout, check=False, ) if result.returncode != 0: raise RuntimeError( f"Command failed: {cmd[0]}\n{result.stderr[:300]}" ) return result.stdout.strip() ``` 2. Pass every argument as a separate list element: ```python dump = json.loads(run( ["yt-dlp", "--dump-json", "--no-playlist", url], timeout=30, )) ``` 3. Pass serialized JSON as one process argument: ```python payload = json.dumps(args, ensure_ascii=False) run([ "mcporter", "call", "tencent-docs", "smartsheet.add_records", "--args", payload, ]) ``` 4. Replace the shell-based `certutil` pipeline with Python's `hashlib`, as already implemented in `upload_to_docs.py`. 5. Validate source URLs before invoking `yt-dlp`. Permit only `https` and the explicitly supported platform hostnames. 6. Validate file paths and require the target to be a regular file in an expected user-selected location. 7. Add regression tests containing quotes, command separators, variable expansions, newlines, and platform-specific shell metacharacters. ]]>

other

Warning
Location
parsers/sph.py:16
Finding

<![CDATA[Undisclosed Disclosure of User-Supplied Share URLs to an External Parser Service]]>

Content
View full analysis
dict: """调用解析 API 获取视频信息""" payload = json.dumps({"url": url}).encode("utf-8") request = urllib.request.Request( PARSER_ENDPOINT, data=payload, headers={ "Content-Type": "application/json", "User-Agent": "KnowledgeBase-Skill/2.1", }, method="POST", ) with urllib.request.urlopen(request, timeout=timeout) as resp: return json.loads(resp.read().decode("utf-8")) ``` ### Technical Analysis Every WeChat Channels share URL processed by this parser is sent in full to `sph.litao.workers.dev`, a separately operated Cloudflare Workers endpoint. The Skill documentation describes the component as a self-developed parsing solution, but it does not clearly disclose that complete user-supplied URLs are transmitted to this specific external recipient. It also does not state who controls the service, what information is logged, how long it is retained, or whether query parameters are removed. Share URLs may disclose viewing activity, content identifiers, tracking parameters, invitation identifiers, or access-bearing query values. HTTP request metadata, such as the source IP address and time of access, will also be visible to the endpoint operator. The network operation is related to the Skill's video-download functionality, but using this particular third-party parser is not inherently the minimum privilege needed. A local parser, an official service, or a user-configurable provider would reduce the trust placed in an undeclared external system. ### Attack Path 1. A user asks the Skill to process a WeChat Channels share link. 2. `downloa ...[truncated 885 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
parsers/sph.py:44
Finding

<![CDATA[Server-Side Request Forgery Through Externally Controlled Video URLs]]>

Content
View full analysis
Remediation
View remediation
MAX_VIDEO_BYTES: raise RuntimeError("Video exceeds the permitted size") f.write(chunk) ``` 8. Delete partial files when validation fails or the download exceeds the size limit. 9. Add tests covering loopback addresses, private IPv4 and IPv6 ranges, DNS rebinding scenarios, redirect chains, unexpected content types, and oversized responses. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a full ingestion pipeline: receive links, detect platform/content type, download or fetch content, extract metadata/captions, upload to Tencent Docs, and archive into a smart sheet. The actual code chunk is much narrower: it is a helper script that writes a single record into a Tencent Docs smart sheet using pre-supplied metadata. This is related to the final indexing/archive step, but it does not implement the core advertised behaviors such as link handling, media/article download, metadata extraction, or document upload. Therefore the supplied code chunk does not accurately represent the declared end-user functionality and is a material mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad, multi-platform knowledge-base ingestion and archival system with downstream upload to Tencent Docs and support for articles, multiple file formats, and metadata extraction from platforms like Douyin and Xiaohongshu. The supplied code chunk only implements one narrow component: downloading WeChat Channels videos via a custom parser endpoint and saving the resulting MP4 locally. While this is consistent with one sentence of the description mentioning a self-developed sph-download solution for 视频号, the code does not itself perform the skill's primary declared end-to-end behavior of cross-platform recognition, uploading to Tencent Docs, or knowledge-base archiving. Therefore, the code chunk materially underimplements and differs from the declared purpose, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a true tool-parameter abuse issue because the generic shell wrapper is reused for multiple external tools and receives attacker-influenced values. In the context of an agent skill that downloads remote content and uploads local files, successful injection could lead to arbitrary command execution, data theft, or tampering with indexed documents.

Content

Scanner excerpt · agent.py (reported line 63)May include surrounding context.

python
def run(cmd: str, timeout: int = 300) -> str:
    r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=timeout)
    if r.returncode != 0:
        raise RuntimeError(f"命令失败: {cmd[:80]}\n{r.stderr[:300]}")
    return r.stdout.strip()

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The Douyin download path constructs shell commands using the user-supplied URL and executes them via the vulnerable run() wrapper. Even though the URL is wrapped in quotes, shell interpolation remains dangerous across platforms and enables command injection or argument-smuggling when special characters are present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The design explicitly automates downloading user-supplied links/files and transmitting the resulting content into Tencent Docs/COS, but the document does not specify an explicit user notice, consent step, or trust boundary warning before exfiltrating content to third-party storage. In a skill whose purpose is cross-platform ingestion and archiving, this omission materially increases the risk of users unintentionally sending private, copyrighted, or sensitive content to external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly promotes ingesting links and local files, downloading third-party content, and uploading it into Tencent Docs, but it does not warn about privacy, consent, copyright, retention, or handling of sensitive local files. In this skill context, that omission is meaningful because the feature is designed to move potentially private or regulated content across platforms automatically, increasing the chance of unintended disclosure or non-compliant data transfer.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly describes capabilities requiring shell execution, network access, file writes, and environment-variable use, yet it declares no tool scope or permission boundaries. That creates an over-privileged and opaque execution model where users and the platform cannot easily constrain what the skill may access or do, increasing the blast radius of compromise or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include very generic requests such as '帮我存这个', '丢链接', and '下载这个视频/文章', which can match ordinary conversation. In an agent environment, overly broad triggers can cause unintended activation, leading to silent downloading of user-supplied content, local storage, and uploads to Tencent Docs without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill processes externally supplied links/files by downloading them locally and uploading them to Tencent Docs, but the user-facing description does not prominently warn about these data flows and their privacy implications. This can cause accidental exfiltration of sensitive or copyrighted content, especially because the skill handles multiple platforms and supports one-click archival.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s user-facing natural language begins with Chinese-only docstring text and usage instructions, which forces a specific language for users without opt-in. Under the policy, language constraints should either offer a choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · add_to_sheet.py (reported line 76)May include surrounding context.

python
}
    
    # 调用 mcporter
    result = subprocess.run(
        [mcporter, "call", "tencent-docs", "smartsheet.add_records", "--args", json.dumps(args)],
        capture_output=True,
        text=True

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The argparse description and argument help strings are all presented only in Chinese, so the tool’s interaction model assumes a single language. This is a natural-language policy issue unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a unified skill that can automatically recognize, download, and archive content from 视频号、抖音、小红书、公众号, including article transfer and multi-format ingestion. In this file, actual executable commands exist only for Douyin downloading, Tencent Docs upload, and parsing already-saved HTML files for XHS/WeChat; there is no direct downloader/fetcher for 视频号、小红书视频、公众号文章 as claimed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language usage instructions and descriptions in the module docstring are exclusively in Chinese, which effectively forces a specific language for users of the skill. There is no indication of language choice, opt-in, or a documented justification for the locale restriction.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The helper executes arbitrary shell strings with shell=True, and several callers interpolate untrusted inputs such as URLs, file names, JSON, and paths directly into those strings. This creates command-injection risk: a crafted argument containing shell metacharacters can execute arbitrary local commands in the agent's environment.

Content

Scanner excerpt · agent.py (reported line 63)May include surrounding context.

python
def run(cmd: str, timeout: int = 300) -> str:
    r = subprocess.run(cmd, shell=True, capture_output=True, text=True, timeout=timeout)
    if r.returncode != 0:
        raise RuntimeError(f"命令失败: {cmd[:80]}\n{r.stderr[:300]}")
    return r.stdout.strip()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This function reads a local file and uploads its full contents to a remote Tencent Docs endpoint, but there is no explicit warning about data transmission or privacy impact. The docstring says it uploads, yet it does not clearly disclose that file bytes and metadata are sent over the network to a third-party service.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · parsers/douyin.py (reported line 40)May include surrounding context.

python
def _extract_description(url: str) -> str:
    """通过 yt-dlp --dump-json 提取视频描述(文案旁白)"""
    try:
        r = subprocess.run(
            ["yt-dlp", "--dump-json", "--no-playlist", url],
            capture_output=True, text=True, timeout=30
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sends a user-supplied WeChat share link to a third-party endpoint (sph.litao.workers.dev) for parsing, which exposes user content and metadata to an external service. In this skill’s context, users are encouraged to submit private or semi-private social-media links for archival, so silent transmission to an untrusted external parser creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · parsers/douyin.py (reported line 66)May include surrounding context.

python
url,
    ]
    try:
        r = subprocess.run(meta_cmd, capture_output=True, text=True, timeout=30)
        lines = [l.strip() for l in r.stdout.strip().split("\n") if l.strip()]
        title = lines[0] if len(lines) > 0 else "xiaohongshu_note"
        author = lines[-1].split("|||")[-1] if "|||" in lines[-1] else "unknown"

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · parsers/xiaohongshu.py (reported line 43)May include surrounding context.

python
url,
    ]
    try:
        r = subprocess.run(meta_cmd, capture_output=True, text=True, timeout=30)
        lines = [l.strip() for l in r.stdout.strip().split("\n") if l.strip()]
        title = lines[0] if len(lines) > 0 else "xiaohongshu_note"
        author = lines[-1].split("|||")[-1] if "|||" in lines[-1] else "unknown"

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · parsers/douyin.py (reported line 93)May include surrounding context.

python
url,
    ]
    print(f"  [yt-dlp] 下载中...")
    r = subprocess.run(dl_cmd, capture_output=True, text=True, timeout=300)

    if r.returncode != 0:
        # 尝试简化方案

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · parsers/xiaohongshu.py (reported line 62)May include surrounding context.

python
url,
    ]
    print(f"  [yt-dlp] 下载中...")
    r = subprocess.run(dl_cmd, capture_output=True, text=True, timeout=300)

    if r.returncode != 0:
        # 尝试简化方案

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · parsers/douyin.py (reported line 98)May include surrounding context.

python
# 尝试简化方案
        print(f"  [yt-dlp] 首次尝试失败,尝试简化方案...")
        dl_cmd2 = ["yt-dlp", "-o", outtmpl, "--no-playlist", url]
        r = subprocess.run(dl_cmd2, capture_output=True, text=True, timeout=300)

    if r.returncode != 0:
        raise RuntimeError(f"yt-dlp 下载失败: {r.stderr[:300]}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · parsers/xiaohongshu.py (reported line 68)May include surrounding context.

python
# 尝试简化方案
        print(f"  [yt-dlp] 首次尝试失败,尝试简化方案...")
        dl_cmd2 = ["yt-dlp", "-o", outtmpl, "--no-playlist", url]
        r = subprocess.run(dl_cmd2, capture_output=True, text=True, timeout=300)

    if r.returncode != 0:
        raise RuntimeError(f"yt-dlp 下载失败: {r.stderr[:300]}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script description and all user-facing CLI output are written in Chinese, and there is no indication that users may select another language or locale. This creates a natural-language policy concern if skills are expected not to force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.