Back to skill

Security audit

Ebook Maker

Security checks for vulnerabilities and agentic risk

Overview

This ebook-generation skill is mostly purpose-aligned, but it includes unsafe credential checks, unsandboxed browser PDF generation, and automatic local saving of user/request details that warrant review before installation.

Review before installing. Use it only for non-sensitive ebook projects unless you change the workflow to avoid printing API keys, remove --no-sandbox, pin dependencies in an isolated environment, and require explicit approval before saving reports or sending prompts to external image services.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
illustration.md:55
Finding

API Credentials Exposed Through Shell Output and Process Arguments

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi ``` 2. Apply the same presence-only check to `GEMINI_API_KEY`. 3. Avoid placing secrets in URLs or command-line arguments. Prefer an SDK or an authentication header where the provider supports it. 4. Disable shell tracing before handling credentials and redact authorization headers and sensitive query parameters from logs. 5. Run API clients in an environment where unrelated users and processes cannot inspect process metadata. 6. Rotate any keys that may already have appeared in tool transcripts or logs. 7. Use narrowly scoped credentials with spending limits, quotas, expiration, and provider-side monitoring. ]]>

T08 · Insecure Dependencies

Warning
Location
illustration.md:77
Finding

Unpinned Runtime Installation of Third-Party Packages

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:196
Finding

Headless Chrome PDF Generation Disables the Browser Sandbox

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
| `SKILL.md`(本文件) | 主流程、阶段定义、调研策略、交付规范 | 改流程逻辑时 |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to activate on common requests like '写本电子书' or '做个 PDF 手册' without strong scoping. Overbroad activation increases the chance the skill runs in contexts where the user did not intend file generation, research collection, or other downstream actions defined by the workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs automatic saving of research files into the user's Downloads directory without prior notice or opt-in. This creates privacy and clutter risks, and may persist sensitive research topics or user project details on disk contrary to user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file says '本文件只定义流程' and presents itself as a workflow document for ebook generation, but it also instructs execution of a headless Chrome command with '--no-sandbox' to generate PDFs. Because no manifest is available and this file is positioned as process documentation rather than an execution spec, embedding direct OS-level command execution is an additional capability not clearly justified by the stated scope of this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill automatically creates and saves a detailed work report containing user request details, source URLs, workflow notes, and output metadata without a privacy warning. This can retain sensitive prompts, research topics, branding details, or other user-supplied information in a persistent local file.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The work report template explicitly requires preserving the user's original request and inferred parameters, which may include personal, proprietary, or sensitive information. Persisting that text in a local markdown report increases the risk of inadvertent disclosure through shared devices, backups, or later file sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document instructs the agent to send prompts to a third-party image generation API using an environment-stored credential, but it provides no warning that book content, prompts, or derived user data will leave the local environment. This creates a real privacy and governance risk because sensitive manuscript content could be transmitted externally without explicit user consent or data-classification checks.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This section explicitly directs use of an external HTTP endpoint for image generation, meaning user-supplied or book-derived content will be transmitted outside the local trust boundary. In the context of an ebook-generation skill, that is a meaningful data exposure risk if the source material contains confidential, regulated, or unpublished information.

Content

Scanner excerpt · illustration.md (reported line 49)May include surrounding context.

选项 B:SeedDream API(火山引擎方舟)

text
工具:HTTP API(curl 或 Python SDK)
模型:seedream-5-0-260128(最新)/ doubao-seedream-4-5-251128(稳定)
端点:https://ark.cn-beijing.volces.com/api/v3/images/generations
认证:ARK_API_KEY 环境变量

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Gemini section describes transmitting prompt content to Google's API and writing returned image data to a local file path, but it does not warn about third-party data transfer or filesystem side effects. This is dangerous because users may unknowingly expose proprietary text to an external service and the skill may create local artifacts in predictable locations without prior approval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is written as a universal layout specification, but it hard-codes Chinese-language typography choices such as Noto Sans SC and Noto Serif SC and presents them as the default standard without any user opt-in or scope limitation. That can violate language/locale policy because it implicitly forces a specific locale rather than offering a choice or documenting that the skill is only for Chinese-language ebooks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Automatically opening a local PDF via the OS expands the skill from content generation into system-affecting behavior without explicit user consent at execution time. While low impact, it can surprise users, trigger associated handlers, or expose file contents on screen in shared environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Opening the generated PDF automatically is a system-affecting action that occurs without warning or opt-in. Even if the file is benign, automatic launching can be unexpected and may reveal content or alter the user's environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This file presents all operational instructions in Chinese only, which can constitute a language/locale policy issue when no user opt-in or documented locale limitation is provided. The policy allows locale constraints only when they are explicitly offered as a choice or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.