Back to skill

Security audit

Hyperthink

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed deep-research automation tool, but it uses long-running scheduled jobs, external API calls, generated local scripts, and optional outbound notifications with limited user control after the first approval.

Install only if you are comfortable with an unattended, multi-hour research pipeline that sends prompts and generated content to Anthropic, writes persistent files under /data/hyperthink and batch-jobs, may create cron jobs, and may notify external webhook or Telegram destinations. Use non-sensitive topics unless you add privacy controls, pin dependencies, review the generated helper scripts, and require explicit approval before enabling cron or network notifications.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/md2docx-spec.md:20
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/md2docx-spec.md:20-23; also referenced in SKILL.md:45-49 and SKILL.md:681-688
Vulnerability Type: Uncontrolled third-party dependency installation
Risk Level: Medium

Vulnerable Code

markdown
## Environment Requirements

- Python 3.8+
- `python-docx` library — install with: `pip install python-docx`
- No other third-party packages

The main Skill instructions similarly direct users to run:

markdown
3. Install python-docx: `pip install python-docx`

Technical Analysis

The installation command does not constrain python-docx to a reviewed version and does not verify a package hash. Consequently, the effective dependency can change after the Skill has been audited.

Package installation may execute package build or installation logic with the privileges of the user running pip. If a future package release, package-index account, distribution artifact, or dependency in the resolved dependency graph is compromised, following these instructions could execute unreviewed code locally. Even without a compromise, uncontrolled version drift can introduce incompatible or newly vulnerable code and make the pipeline non-reproducible.

This is a supply-chain weakness rather than evidence that the current python-docx package is malicious.

Attack Path

  1. An attacker compromises a future python-docx release, its package-index account, a resolved transitive dependency, or the package distribution path.
  2. A user follows the Skill’s first-time setup instructions.
  3. pip install python-docx resolves the current uncontrolled release rather than a previously reviewed artifact.
  4. Malicious package installation or import-time code executes in the user’s environment.
  5. That code operates with the filesystem, network, environment-variable, and process privileges available to the installing or pipeline user.

Impact Assessment

...[truncated 608 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin python-docx to a specific, reviewed version.

  2. Maintain a locked requirements file with hashes, such as a hash-validated requirements.txt.

  3. Install with hash enforcement:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  4. Record the trusted package index explicitly and avoid untrusted extra indexes.

  5. Install the dependency inside a dedicated virtual environment rather than globally.

  6. Run installation and document conversion as an unprivileged account with access only to the required input and output directories.

  7. Periodically review dependency advisories and update the pin only after testing and artifact verification.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/batch-worker-spec.md:222
Finding

Unrestricted Optional Webhook Egress Can Disclose Research and Filesystem Metadata

Content
View full analysis

Vulnerability Details

File Location: scripts/batch-worker-spec.md:222-238; configuration declared in SKILL.md:25-27 and SKILL.md:55-59
Vulnerability Type: Insufficiently constrained outbound notification handling
Risk Level: Low

Vulnerable Code

markdown
## Notification

How to notify the user when a job completes is intentionally left to the implementer.
Options ranked by simplicity:

1. **Print to stdout** — always do this regardless of other methods
2. **Write to a delivery queue** — if your platform has one (e.g. OpenClaw writes a JSON file to a watched directory)
3. **Send an HTTP request** — POST to a webhook URL from `NOTIFY_WEBHOOK_URL` env var
4. **Send a Telegram message** — if `TELEGRAM_BOT_TOKEN` and `TELEGRAM_CHAT_ID` env vars are set
5. **Write to a log file** — `NOTIFY_LOG_FILE` env var

Implement at least option 1. Add others based on your environment.

Notification message should include:
- Job description
- Number of succeeded / errored requests
- Path to results file

Technical Analysis

The specification permits a future implementation to send notifications to any URL supplied through NOTIFY_WEBHOOK_URL. It does not require:

  • HTTPS;
  • an approved-host allowlist;
  • validation against loopback, private, link-local, or cloud metadata destinations;
  • redirect restrictions;
  • per-run user approval;
  • redaction of sensitive job descriptions;
  • omission of local filesystem paths.

The required notification content can reveal a research topic through the job description and disclose local storage structure through the results path. Because stdout notification is already mandatory and sufficient for baseline operation, arbitrary network notification is optional rather than necessary for the core research pipeline.

The environment-controlled destination makes this behavior disclosed rather than covert. Nevertheless, inherited, mistaken, or attacker-con ...[truncated 1563 chars]

Remediation
View remediation

Remediation Suggestions

  1. Keep network notifications disabled by default and require explicit configuration or per-run consent.
  2. Treat stdout or a local delivery queue as the default least-privilege notification mechanism.
  3. Require HTTPS and reject plaintext HTTP URLs.
  4. Validate destinations against an explicit hostname allowlist where feasible.
  5. Resolve and reject loopback, private, link-local, multicast, and cloud metadata addresses.
  6. Disable redirects or revalidate every redirect target before following it.
  7. Send a minimal notification identifier instead of the full job description.
  8. Do not transmit absolute result paths; use a generic message such as “results are available.”
  9. Apply strict connection and response-size timeouts.
  10. Ensure logs redact webhook credentials, Telegram tokens, API keys, and sensitive URL query parameters.
  11. Document precisely which fields leave the host and obtain user approval before enabling remote delivery.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · scripts/batch-worker-spec.md (reported line 113)May include surrounding context.

md
"id": "another-request",
      "model": "claude-haiku-4-5",
      "max_tokens": 1000,
      "system": "Override system prompt for this request only",
      "messages": [
        {"role": "user", "content": "Different prompt"}
      ]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends large volumes of user-provided research content to Anthropic batch APIs and optionally to Telegram or arbitrary webhook endpoints, but the description does not provide an explicit privacy or data-handling warning. This is dangerous because users may provide confidential business, legal, financial, or product information during the interrogate flow without realizing it will be transmitted to third parties and stored in persistent local output directories.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

After a single scope confirmation, the skill runs for 8–18 hours with no further checkpoints while making external API calls, writing persistent files, scheduling pollers, and delivering outputs through notification channels. That autonomy is risky because there is no opportunity to stop unexpected cost escalation, data leakage, or unintended downstream actions once the unattended pipeline begins.

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
2. Create output directories (see above)
3. Run **interrogate flow** — ask 4–10 questions in batches of 2 to narrow scope
4. Confirm scope summary — wait for explicit "yes"
5. From here: **fully hands-off** — no more checkpoints, no approvals needed

---

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs execution of local Python scripts and shell-style commands such as batch submission and document conversion, expanding the agent from analysis into code execution on the host. This is dangerous because the scripts are not intrinsic trusted platform tools: the skill even tells the AI to implement them first, creating a path for unsafe code generation, arbitrary file access, network calls, and command execution under broad filesystem permissions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill directs the agent to create, update, and remove cron jobs that persist beyond the initiating interaction, giving it host-scheduling capability rather than just performing research. In context, this is risky because the pipeline is explicitly unattended and self-propagating across stages, so a malformed or repurposed poller could repeatedly execute actions, consume resources, or continue operating after user intent has changed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/batch-worker-spec.md (reported line 130)May include surrounding context.

Submit a batch:

text
POST https://api.anthropic.com/v1/messages/batches
Headers:
  x-api-key: <ANTHROPIC_API_KEY>
  anthropic-version: 2023-06-01

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/batch-worker-spec.md (reported line 157)May include surrounding context.

Submit a batch:

text
POST https://api.anthropic.com/v1/messages/batches
Headers:
  x-api-key: <ANTHROPIC_API_KEY>
  anthropic-version: 2023-06-01

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/batch-worker-spec.md (reported line 167)May include surrounding context.

Submit a batch:

text
POST https://api.anthropic.com/v1/messages/batches
Headers:
  x-api-key: <ANTHROPIC_API_KEY>
  anthropic-version: 2023-06-01

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The spec expands a batch worker from core API submission/polling into optional outbound notification channels including generic webhooks and Telegram. That creates additional exfiltration paths for job metadata and result locations, and if implemented without strict allowlisting and secret handling, it can leak sensitive research topics or results to third parties.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.