Back to skill

Security audit

知识星球帖子抓取助手

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated purpose, but it automatically falls back to an embedded Knowledge Planet access token and handles sensitive session tokens without enough disclosure or safeguards.

Review this before installing. Remove and revoke the embedded token, require only your own token through a secure local secret or environment variable, and avoid saving cookie tokens in plaintext files. Treat ZSXQ_TOKEN as account access: do not paste it into chats, logs, screenshots, or repositories. Be aware that listing groups or fetching posts can reveal private memberships and restricted community content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
fetch_topics.js:23
Finding

Hardcoded Access Token and Insecure Plaintext Credential Fallback

Content
View full analysis
persistent file > default token if (process.env.ZSXQ_TOKEN) { return process.env.ZSXQ_TOKEN; } // Attempt to read from a file try { if (fs.existsSync(TOKEN_FILE)) { const data = JSON.parse(fs.readFileSync(TOKEN_FILE, 'utf-8')); if (data.token && data.token.trim()) { console.error('[zsxq] loaded token from token.json'); return data.token; } } } catch (err) { console.error(`[zsxq] failed to load token file: ${err.message}`); } // Use the default token console.error('[zsxq] using default persisted token'); return DEFAULT_TOKEN; } function saveToken(token) { try { fs.writeFileSync( TOKEN_FILE, JSON.stringify({ token, updated_at: new Date().toISOString() }, null, 2), 'utf-8' ); console.error('[zsxq] token saved to token.json'); } catch (err) { console.error(`[zsxq] failed to save token: ${err.message}`); } } ``` The selected credential is then placed in an authentication cookie: ```js const ZSXQ_TOKEN = loadToken(); if (!ZSXQ_TOKEN) { console.error(JSON.stringify({ error: 'ZSXQ_TOKEN not configured' })); process.exit(1); } const BASE_URL = 'https://api.zsxq.com/v2'; const HEADERS = { 'Cookie': `zsxq_access_token=${ZSXQ_TOKEN}`, 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36', 'Origin': 'https://wx.zsxq.com', 'Referer': 'https://wx.zsxq.com/', 'Accept': 'application/json', 'X-Timestamp': String(Math.floor(Da ...[truncated 2902 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明的大部分核心功能与代码行为一致:支持抓取帖子、精华筛选、按链接/ID 获取单帖,也能面向多个星球使用。 但代码还执行了若干未在描述中体现的能力,且其中部分较为敏感:1) 认证方面不仅读取环境变量,还会读取本地 token.json,并在无配置时回退到硬编码默认 token;2) 代码定义了 saveToken(),可将令牌持久化写入本地文件,属于未声明的凭证存储能力;3) 额外提供 groups 子命令,可枚举当前账号加入的所有星球,这超出了“抓取指定星球帖子”的描述范围。 因此应判定为存在描述与实际行为不完全一致,属于有未声明能力的 mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

根据提供的代码片段,实际行为仅限于安装前置检查和运行环境验证,不包含任何与知识星球 API、网页抓取、帖子检索、详情获取或配置管理相关的逻辑。虽然这类安装脚本可以作为 Skill 的辅助组成部分,但题目要求比较“所 supplied code chunk 实际做什么”与声明描述是否一致。该代码片段本身并未体现声明中的核心能力,且其直接目的与声明的主要用途存在明显差异,因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions tell users to extract an access token directly from browser cookies via developer tools, but do not emphasize that this token is a credential equivalent to account access. This normalizes insecure credential handling and can lead to token theft, accidental logging, or reuse in unsafe contexts, granting access to private account-scoped data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code embeds a default access token and automatically uses it when no user-supplied token is present. This can grant built-in access to a real Knowledge Planet account without user authorization, causing unauthorized data access and exposing the token to anyone who can read or reuse the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README instructs users to extract and store a live zsxq_access_token but does not clearly warn that this credential is sensitive, equivalent to account access, and must never be shared, logged, or committed. Because the skill fetches potentially private Knowledge Planet content, mishandling this token could expose account data and unauthorized access to joined groups.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation example is broad enough that ordinary user conversation about checking recent Knowledge Planet content could automatically trigger this skill, causing unintended external data access. In an agent environment, overbroad activation can lead to unnecessary use of stored credentials and retrieval of private group content without the user making an explicit request to use this integration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill explicitly requires and uses the sensitive environment variable ZSXQ_TOKEN, but the manifest does not declare any tool scope or permission boundary for environment access. That weakens reviewability and increases the chance an agent can access credentials without clear user-visible authorization semantics.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is designed to fetch account-scoped posts and summarize or output them, but it does not warn users that content may be private, subscription-restricted, or sensitive. In this context, omission of privacy guidance increases the risk of unintended disclosure of paid-community content, member activity, or private discussions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The line 所有输出使用**中文** forces a specific language for all outputs. This is a natural-language locale policy violation because the skill does not provide user opt-in or a documented justification for requiring Chinese only.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Instructing users to open browser developer tools and copy the zsxq_access_token cookie is a direct natural-language credential collection pattern. In the context of a skill that can read account-scoped community content, this is especially dangerous because the token can be reused to impersonate the user and access private groups and posts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented groups capability enumerates all joined groups, which may reveal private memberships, organization affiliations, and access to non-public communities, yet the skill provides no warning about that exposure. Combined with post-detail retrieval, this can disclose sensitive account metadata and content beyond what a user intended to share in the current interaction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes fetching latest posts, filtering by digest/all, and retrieving a single post by link or ID. The documented and implemented groups subcommand lists all joined 星球, which is a separate account-discovery capability not mentioned in the skill description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The comments state that the token will only be read automatically from token.json, but the implementation also writes tokens to that file. This discrepancy undermines informed consent and can cause users to unknowingly leave reusable credentials on disk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill writes authentication tokens to token.json on local disk, even though the described purpose is content retrieval. Persisting bearer-style credentials increases the chance of credential theft through local file disclosure, backups, shared workspaces, or accidental commit to source control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Credential persistence occurs silently with no warning, confirmation, or consent mechanism. Silent storage of authentication material is dangerous because users may not realize secrets are being retained locally and available to other processes or users with filesystem access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · fetch_topics.js (reported line 64)May include surrounding context.

js
process.exit(1);
}

const BASE_URL = 'https://api.zsxq.com/v2';

const HEADERS = {
  'Cookie': `zsxq_access_token=${ZSXQ_TOKEN}`,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 15)May include surrounding context.

md
process.exit(1);
}

const BASE_URL = 'https://api.zsxq.com/v2';

const HEADERS = {
  'Cookie': `zsxq_access_token=${ZSXQ_TOKEN}`,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script sends the user's ZSXQ access token in the Cookie header on every HTTPS request to the remote API. Although the script's purpose is to fetch remote topics, the top-level comments do not explicitly warn that authentication data will be transmitted to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document instructs users to manually extract a live authentication token from browser cookies and send it in requests, but provides no warning about token sensitivity, storage, reuse, or leakage risks. In the context of a content-fetching skill, this can normalize unsafe credential handling and enable account/session compromise if the token is exposed in logs, prompts, screenshots, or shared configs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language comments, usage descriptions, and user-facing messages are written in Chinese only, with no indication that another language can be used. This can violate language or locale policy when a skill imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language strings in comments and user-facing echo output are entirely in Chinese, including usage and error messages. For a general install script, this imposes a specific language on users without opt-in or justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file's natural-language instructions and labels are exclusively in Chinese, which can amount to a language policy constraint if users are not given an explicit language or locale option. No justification is provided that this skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.