Back to skill

Security audit

zero-one-two-three知识变现架构师

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real knowledge-management toolkit, but it needs Review because it combines mailbox automation, business fulfillment, sensitive local indexing, and weak security defaults.

Install only if you are comfortable giving it mailbox and local-note access. Do not use the automatic mailbox fulfillment flow for real payments without separate verified payment-provider checks, avoid putting secrets in the project tree, upgrade pinned dependencies, and treat the encryption/share features as convenience protection rather than strong confidentiality until the KDF, backup, overwrite, and disclosure issues are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
knowledge_lock.py:321
Finding

Weak Password-Based Key Derivation Enables Efficient Offline Password Guessing

Content
View full analysis

Vulnerability Details

File Location: knowledge_lock.py:321-324
Vulnerability Type: Weak cryptographic key derivation
Risk Level: High

Vulnerable Code

python
def derive_key(password: str) -> bytes:
    """Derive a Fernet-compatible 32-byte key from a user password."""
    digest = hashlib.sha256(password.encode('utf-8')).digest()
    return base64.urlsafe_b64encode(digest)

Technical Analysis

The encryption key is derived by applying a single, unsalted SHA-256 operation to the supplied password. SHA-256 is intentionally fast and is not suitable as a password-based key derivation function.

A .locked file contains a Fernet token that provides an authentication result for each attempted key. Consequently, possession of the encrypted file allows an attacker to perform offline password guessing without interacting with the application or triggering rate limits.

The password policy requiring eight characters, uppercase and lowercase letters, and a digit does not guarantee sufficient entropy. Human-selected passwords that satisfy these requirements may still be recovered using dictionaries and mutation rules.

Attack Path

  1. The attacker obtains a .locked file through local access, an exposed archive, backup leakage, or file sharing.
  2. The attacker extracts the Fernet ciphertext from the file.
  3. Candidate passwords are generated from password dictionaries or brute-force rules.
  4. Each candidate is hashed once with SHA-256 and converted into a Fernet key.
  5. Fernet authentication identifies the correct password offline.
  6. The attacker decrypts the protected knowledge content.

Impact Assessment

Successful exploitation discloses the complete encrypted portion of the protected document. No operating-system privilege escalation occurs, but the confidentiality boundary promised by the asset-protection feature is compromised for files protected by guessable passwords.

Remediation
View remediation

Remediation Suggestions

  • Replace the direct SHA-256 derivation with Argon2id, scrypt, or PBKDF2-HMAC using security-reviewed parameters.
  • Generate a cryptographically random salt for every encrypted file.
  • Store the salt, KDF algorithm, version, and cost parameters in authenticated metadata.
  • Prefer Argon2id with calibrated memory, iteration, and parallelism costs appropriate to supported systems.
  • Preserve backward compatibility only through an explicit legacy-decryption path, and re-encrypt legacy files after successful decryption.
  • Encourage generated high-entropy passphrases rather than relying only on composition rules.

T09 · Insecure Skill Coding Practices

Error
Location
knowledge_lock.py:405
Finding

Default Plaintext Backup Defeats the File-Encryption Confidentiality Boundary

Content
View full analysis

Vulnerability Details

File Location: knowledge_lock.py:405-440
Vulnerability Type: Plaintext sensitive-data retention
Risk Level: High

Vulnerable Code

python
def backup_file(filepath: str) -> str:
    """Create a timestamped backup file."""
    timestamp = datetime.now().strftime("%Y%m%d_%H%M%S")
    base, ext = os.path.splitext(filepath)
    backup_path = f"{base}.backup_{timestamp}{ext}"
    shutil.copy2(filepath, backup_path)
    return backup_path


def lock_file(filepath: str, password: str, preview_ratio: float = 0.3,
              do_backup: bool = True, enable_recovery: bool = False):
    ...
    if do_backup:
        backup_path = backup_file(filepath)
        print(f"Backup created: {backup_path}")

Technical Analysis

File locking creates a complete plaintext copy by default before writing the encrypted output. The backup is stored beside the source using a predictable timestamped filename.

An attacker with access to the directory does not need to attack the encryption algorithm or discover the password. The attacker can read the backup directly. The original source file is also not removed by the locking routine, further requiring users to manage plaintext retention manually.

Attack Path

  1. A user runs the lock command with default options.
  2. The program copies the complete source document to a timestamped plaintext backup.
  3. The encrypted .locked file is created, but the backup remains readable.
  4. An attacker, synchronization service, archive process, or other local account obtains the backup.
  5. The protected content is read without the encryption password.

Impact Assessment

The complete source document can be disclosed to any principal that can read the output directory, including local users, cloud synchronization software, backup agents, or recipients of an accidentally packaged directory. The issue bypasses the intended encryption bou ...[truncated 68 chars]

Remediation
View remediation

Remediation Suggestions

  • Disable plaintext backup creation by default.
  • Require explicit, informed confirmation before creating any plaintext backup.
  • Store necessary backups in a separately encrypted location with restrictive permissions.
  • Clearly report that the original source and any backup remain unencrypted.
  • Offer an explicit post-encryption cleanup operation only after the encrypted output has been written and successfully verified.
  • Avoid claiming secure deletion guarantees on copy-on-write filesystems, SSDs, or managed storage.
  • Add tests ensuring default encryption workflows do not create additional plaintext copies.

T09 · Insecure Skill Coding Practices

Error
Location
mailbox_tool.py:224
Finding

Arbitrary Email Attachments Are Treated as Verified Payment Evidence

Content
View full analysis

Vulnerability Details

File Location: mailbox_tool.py:224-260
Vulnerability Type: Missing payment authorization and business-logic validation
Risk Level: High

Vulnerable Code

python
att_name, att_data = find_attachment(msg)
body_text = extract_email_body(msg)

referrer_email = ref_eng.parse_referral_from_text(subject + " " + body_text)

...

if att_name:
    print(f"   Payment evidence detected; beginning automatic delivery...")
    ok = deliver_capsule(config, sender_email, sender_name)
    if ok:
        order["status"] = "delivered"
        delivered += 1

        if referrer_email:
            comm = ref_eng.record_commission(
                order_id, sender_email, 99, referrer_email
            )
    else:
        order["status"] = "failed"

Technical Analysis

The application equates the presence of any email attachment with proof of payment. It retrieves the attachment name and bytes but never validates the attachment contents, transaction identifier, payment amount, payer, recipient, timestamp, or payment-provider signature.

An attacker can therefore attach an empty file, unrelated image, or fabricated screenshot and trigger automatic fulfillment. If referral information is accepted from the email text, the same request may also create a fraudulent commission record.

The shipped artifact references an absent tools.referral_engine extension. The vulnerable path becomes operational when that documented extension is installed; its absence does not make attachment presence a valid authorization control.

Attack Path

  1. The attacker sends an unread email to the monitored mailbox.
  2. The email contains any attachment, such as an empty text file or unrelated image.
  3. The attacker optionally places a referral identifier in the subject or body.
  4. The mailbox watcher finds the unread message and observes that an attachment exists.
  5. The script classifies t ...[truncated 604 chars]
Remediation
View remediation

Remediation Suggestions

  • Never authorize fulfillment based on attachment presence or screenshot analysis alone.
  • Integrate a payment-provider webhook with verified digital signatures.
  • Retrieve the transaction from the payment provider and verify its status, currency, amount, merchant account, payer, and unique order identifier.
  • Enforce transaction uniqueness to prevent replay and duplicate fulfillment.
  • Bind each payment to a server-generated pending order and expected recipient.
  • Require manual review where cryptographically verifiable payment confirmation is unavailable.
  • Validate and constrain referral identifiers independently of email-controlled text.
  • Maintain an immutable audit log of verification results and fulfillment decisions.

T09 · Insecure Skill Coding Practices

Warning
Location
voice_clone.py:151
Finding

Complete Document Contents Are Sent to an External Cloud TTS Service Without Explicit Consent

Content
View full analysis

Vulnerability Details

File Location: voice_clone.py:151-173
Vulnerability Type: Undisclosed third-party transmission of user content
Risk Level: Medium

Vulnerable Code

python
async def speak(self, text, output_path=None):
    if not output_path:
        output_path = "voice_output.mp3"

    text = self._preprocess_text(text)

    communicate = edge_tts.Communicate(
        text=text,
        voice=self.voice,
        rate=self.rate,
        pitch=self.pitch,
    )
    await communicate.save(output_path)
    return output_path

async def speak_file(self, file_path, output_path=None):
    path = Path(file_path)
    text = path.read_text(encoding="utf-8", errors="ignore")
    if not output_path:
        output_path = path.stem + ".mp3"
    return await self.speak(text, output_path)

Technical Analysis

The file-narration function reads the entire selected document and passes its plaintext to edge_tts.Communicate. Edge TTS relies on an external Microsoft speech service, so generation requires transmitting the supplied text outside the local environment.

The user-facing documentation emphasizes that the function is free and requires no API key, but it does not provide a clear per-operation warning that document contents are sent to a third party. There is no explicit consent prompt, local-only mode, redaction step, or sensitive-data detection.

This network activity is necessary for the selected cloud TTS implementation, but it exceeds local file-processing privileges and should be disclosed before sensitive notes are transmitted.

Attack Path

  1. A user selects a private note or confidential document for narration.
  2. speak_file reads the entire file into memory.
  3. The complete processed text is passed to the Edge TTS client.
  4. The client transmits the text to the external speech service.
  5. The service returns generated audio, which is saved locally.

...[truncated 331 chars]

Remediation
View remediation

Remediation Suggestions

  • Display a clear warning that the selected text will be sent to Microsoft or the applicable external TTS provider.
  • Require explicit user confirmation before each file transmission, or provide a persistent opt-in setting.
  • Document the destination service, transmitted fields, retention considerations, and relevant privacy policy.
  • Add an offline TTS backend and make it available for sensitive content.
  • Provide optional redaction for credentials, email addresses, identifiers, and other sensitive patterns.
  • Apply content-size limits and show a preview of the material that will be transmitted.
  • Do not describe the function in a way that could reasonably imply fully local processing.

T09 · Insecure Skill Coding Practices

Error
Location
create_package.py:5
Finding

Recursive Package Creation Can Include Credentials and Private User Files

Content
View full analysis

Vulnerability Details

File Location: create_package.py:5-48
Vulnerability Type: Sensitive-file inclusion through unsafe packaging defaults
Risk Level: High

Vulnerable Code

python
EXCLUDE_DIRS = {
    "__pycache__", ".vscode", ".git", "tools", "genesis_engine",
    "knowledge_library", "ephemeral_shares", "data", "temp"
}
EXCLUDE_FILES = {
    "Zero-One-Two-Three-SkillHub.zip",
    "package_for_skillhub.ps1",
    "create_package.py",
    "test_sample.md",
    "test_sample.md.locked",
    "unlock_output.txt",
    "lock_test_output.txt",
    "mailbox_output.txt",
    "connector_output.txt",
    "output_test.txt",
}
EXCLUDE_EXTS = {".pyc", ".whl", ".html", ".bat", ".locked", ".backup"}

...

with zipfile.ZipFile(zip_filename, "w", zipfile.ZIP_DEFLATED) as zipf:
    for file_path in root.rglob("*"):
        if file_path.is_dir():
            continue
        rel = str(file_path)
        if not should_include(rel, str(root)):
            continue
        zipf.write(rel, rel)

Technical Analysis

The packaging script recursively archives the current working directory and excludes only a limited blacklist. It does not exclude common sensitive files such as .env, mailbox_config.json, credential JSON files, private keys, token files, or arbitrary personal notes.

Because the inclusion policy is blacklist-based, any unrecognized filename or extension is automatically packaged. Running the script from a directory containing configuration files or user knowledge can therefore silently place sensitive data into the distributable ZIP archive.

The repository .gitignore also does not provide relevant exclusions for these artifacts, increasing the likelihood that sensitive runtime files remain inside the project tree.

Attack Path

  1. A user stores mailbox configuration, tokens, private notes, or key material under the current working directory.
  2. The sensit ...[truncated 634 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the blacklist with an explicit allowlist of files required in the published package.
  • Anchor packaging to the script's verified project directory rather than the caller's current working directory.
  • Reject .env, credential and mailbox configuration files, private-key formats, token caches, user notes, generated reports, and unknown files.
  • Run an automated secret scanner before archive creation.
  • Print the complete archive manifest and require confirmation before finalizing the package.
  • Add appropriate runtime-secret patterns to .gitignore.
  • Add tests that create representative secret files and verify that none are included.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (48)

Known Vulnerable Dependency: langchain-core==0.3.0 — 14 advisory(ies): CVE-2026-26013 (LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_to); CVE-2024-10940 (langchain-core allows unauthorized users to read arbitrary files from the host f); CVE-2025-65106 (LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templa) +11 more

Critical
Category
Supply Chain
Confidence
100% confidence
Finding

langchain-core==0.3.0 is reported with numerous high-severity and critical issues, including arbitrary file read, SSRF, and template injection classes of bugs. In the context of an agent skill, this is especially dangerous because LLM-agent frameworks often process untrusted prompts, remote content, and tool inputs, making exploitation paths substantially more realistic than in a passive library.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that a configuration success report will be automatically emailed, but it does not present a prominent privacy warning or clear consent boundary for that transmission. Automatic outbound messaging tied to setup can leak personal details, environment information, or usage context to an external recipient without informed approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The mailbox workflow instructs continuous inbox monitoring, attachment parsing, and automatic knowledge processing without an explicit high-visibility warning about the privacy and security implications. This creates a standing intake channel for sensitive documents and expands attack surface through email content and attachments.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
**执行**:调用 `knowledge_lock.py` 进行 AES-256 加密,生成 `.locked` 文件。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 507)May include surrounding context.

md
**执行**:调用 `knowledge_lock.py` 进行 AES-256 加密,生成 `.locked` 文件。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 269)May include surrounding context.

md
**风格克隆 (`style_clone.py`)**:20+ 维语言指纹分析

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 550)May include surrounding context.

md
**风格克隆 (`style_clone.py`)**:20+ 维语言指纹分析

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 516)May include surrounding context.

md
### 5. 邮箱工具 (`mailbox_tool.py`)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

unlock_file() derives the output path by stripping '.locked' and writes the decrypted plaintext directly there without checking whether that path already exists. This can silently overwrite an existing file, causing data loss and potentially replacing trusted local content with attacker-supplied decrypted content if a user is tricked into unlocking an untrusted '.locked' file.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script is designed to automatically monitor inbound email, parse message content and attachments, and send outbound delivery/report emails without any interactive confirmation or meaningful privacy notice. Because email contents and attachments may contain sensitive personal or financial data, unattended processing and transmission materially increases privacy and misuse risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script can send an automatically generated report to an external author-controlled email address containing mailbox account details, operating environment, and business metrics. In a mailbox-processing skill, silent transmission of operational data to a third party is a clear data exfiltration risk, especially because the destination defaults to an externally controlled address via configuration/environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The report includes mailbox/account identifiers and order/revenue summaries, then sends them to an external author email without strong upfront warning or narrowly justified purpose. This creates a direct confidentiality risk because business and account data leave the user's environment through normal SMTP functionality.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: cryptography==41.0.0 — 16 advisory(ies): CVE-2023-50782 (Python Cryptography package vulnerable to Bleichenbacher timing oracle attack); GHSA-537c-gmf6-5ccf (Vulnerable OpenSSL included in cryptography wheels); CVE-2024-26130 (cryptography NULL pointer dereference with pkcs12.serialize_key_and_certificates) +13 more

High
Category
Supply Chain
Confidence
99% confidence
Finding

cryptography==41.0.0 is affected by multiple serious advisories, including issues involving timing side channels, vulnerable bundled OpenSSL components, and denial-of-service conditions. Because this library underpins certificate validation, encryption, signing, and secret handling, keeping a known-vulnerable version materially weakens the security of any feature that relies on cryptographic trust or key material.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: langchain-community==0.3.0 — 2 advisory(ies): CVE-2025-6984 (Langchain Community Vulnerable to XML External Entity (XXE) Attacks); CVE-2025-6984 (Langchain Community Vulnerable to XML External Entity (XXE) Attacks)

High
Category
Supply Chain
Confidence
97% confidence
Finding

langchain-community==0.3.0 is flagged for XXE vulnerabilities, which can allow attackers to read local files, trigger server-side requests, or cause parser-based denial of service when XML is processed unsafely. This is more concerning in an agent ecosystem because community integrations often ingest heterogeneous external data sources, increasing the chance that attacker-controlled XML reaches a vulnerable parser path.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: langchain-text-splitters==0.3.0 — 4 advisory(ies): CVE-2026-41481 (LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redire); CVE-2025-6985 (LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due ); CVE-2025-6985 (LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due ) +1 more

High
Category
Supply Chain
Confidence
99% confidence
Finding

langchain-text-splitters==0.3.0 is associated with SSRF and XXE-related advisories, including risky URL-based text extraction behavior. In a skill that may retrieve, split, and embed remote or user-supplied documents, those weaknesses can enable internal network probing, unintended outbound requests, or local data exposure through malicious document sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes voice cloning and style cloning as core features but provides no warning about consent, impersonation, biometric privacy, or legal/ethical misuse. In a skill centered on creating digital personas and distributing content, omission of these safeguards increases the likelihood that users deploy the capability for unauthorized impersonation or privacy-invasive use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README gives a direct example for creating self-destructing shares of confidential files without warning that recipients may still copy, screenshot, or redistribute content and that access settings may be irreversible or misconfigured. Because the feature is presented as suitable for secret material, users may develop a false sense of security and expose sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to place email and Notion credentials in environment variables but does not warn that these are sensitive secrets that must be protected from shell history exposure, screenshots, shared profiles, or accidental logging. Since the platform includes mailbox automation and content distribution, compromise of these credentials could enable account takeover, unauthorized sending, and data exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes style and voice cloning capabilities without any explicit consent, identity, or anti-impersonation safeguards. In a skill centered on cloning a person's writing style and voice, omission of misuse warnings normalizes capabilities that can enable deception, impersonation, privacy abuse, and social-engineering attacks.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Automatic email-based collection and reporting creates a natural-language exfiltration path because user setup context and generated feedback are transmitted over email. Even if intended as a convenience feature, it can disclose sensitive metadata or user content to external addresses, especially if configuration is misunderstood or prefilled.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase for deep reading is broad and conversational, making accidental activation plausible during normal chat. In a skill that can read files, connect knowledge sources, or kick off downstream workflows, ambiguous triggers increase the chance of unintended data processing.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The mailbox workflow monitors incoming mail, parses attachments, and uses the content to drive downstream processing, which is a direct data leakage and prompt-injection pathway. Email is an untrusted input channel, so automatic ingestion of documents and instructions can expose sensitive materials and trigger unsafe actions if not tightly constrained.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation claims the skill 'does not do crawling' while elsewhere describing network-connected integrations, model downloads, email workflows, and external platform connectors. This inconsistency can mislead users about the skill's actual network behavior and trust boundaries, increasing the risk of unreviewed outbound connections and data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstring and runtime messages are presented exclusively in Chinese, which imposes a specific language on users without any opt-in or documented regional constraint. The policy explicitly calls out forced language or locale as a natural-language policy violation unless the skill offers a choice or clearly justifies the restriction.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
ephemeral_share.py:87