Back to skill

Security audit

Literature Manager

Security checks for vulnerabilities and agentic risk

Overview

This literature-management skill is mostly coherent, but it includes a Sci-Hub paywall-bypass path and helper scripts with unsafe file, network, and runtime-package behavior that merit review before installation.

Install only if you are comfortable reviewing and controlling each download. Avoid using the Sci-Hub path, run the scripts in a restricted working directory without sensitive files or credentials, do not pass untrusted filenames or reference-directory paths, and pin or preinstall conversion dependencies before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit.sh:75
Finding

Python Code Injection Through an Attacker-Controlled Audit Directory Path

Content
View full analysis
/dev/null; then PAPER_COUNT=$(python3 -c "import json; d=json.load(open('$INDEX')); print(len(d.get('papers', d if isinstance(d, list) else [])))") echo "index.json entries: $PAPER_COUNT" MISSING=$(python3 -c " import json, os d = json.load(open('$INDEX')) papers = d.get('papers', d if isinstance(d, list) else []) for p in papers: for key in ['pdf_path', 'markdown_path']: path = p.get(key, '') full = os.path.join('$REFDIR', path) if path and not os.path.exists(full): print(f'Missing: {path}') " 2>/dev/null) DUPES=$(python3 -c " import json d = json.load(open('$INDEX')) papers = d.get('papers', d if isinstance(d, list) else []) ids = [p.get('id','') for p in papers] seen = set() for i in ids: if i in seen: print(f'Duplicate ID: {i}') seen.add(i) " 2>/dev/null) ``` ### Technical Analysis The script embeds the values of `INDEX` and `REFDIR` directly into Python source passed to `python3 -c`. Shell double quoting does not make these values safe inside the resulting Python program. If an audited directory name contains a single quote followed by valid Python syntax, the value can terminate the Python string literal and introduce additional statements. The injected Python executes with the same operating-system identity and permissions as the audit process. The issue affects multiple Python invocations. Escaping only one invocation would therefore be insufficient. ### Attack Path 1. An attacker creates or supplies a references directory whose path contains a crafted Python payload. 2. The attac ...[truncated 904 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/download.sh:9
Finding

Arbitrary File Overwrite or Deletion Through Filename Path Traversal

Content
View full analysis
/dev/null if file -b "$OUTPATH" | grep -q "PDF"; then echo "✅ Downloaded from $label: $OUTPATH" return 0 fi rm -f "$OUTPATH" return 1 } ``` ### Technical Analysis The optional `FILENAME` argument is concatenated directly with `OUTDIR`. The script does not reject absolute paths, path separators, or `..` components, and it does not verify that the resolved destination remains inside the requested output directory. Consequently, a value such as `../../target` causes `curl` to write outside `OUTDIR`. If the downloaded response is recognized as a PDF, the external target is overwritten and retained. If validation fails, `rm -f "$OUTPATH"` deletes the selected external file. Writing directly to the destination also means an existing file is modified before content validation succeeds. ### Attack Path 1. The attacker chooses a file writable by the user or Agent running the script. 2. The attacker supplies a traversal filename such as `../../project/configuration`. 3. To overwrite the target, the attacker supplies a URL returning content that `file` recognizes as PDF. 4. Alternatively, to delete the target, the attacker supplies a non-PDF response. 5. `curl -o "$OUTPATH"` writes to the traversed path. 6. For a non-PDF response, the subsequent `rm -f "$OUTPATH"` removes that path. ### Impact Assessment An ...[truncated 401 chars]
Remediation
View remediation
&2 exit 1 ;; esac ``` A safer download flow is: ```bash OUTDIR_REAL=$(realpath -m "$OUTDIR") mkdir -p "$OUTDIR_REAL" TMPFILE=$(mktemp --tmpdir="$OUTDIR_REAL" '.download.XXXXXX') trap 'rm -f "$TMPFILE"' EXIT curl --fail --silent --show-error --location \ --max-time 30 --connect-timeout 10 \ -H "User-Agent: $UA" \ -o "$TMPFILE" "$url" if file -b "$TMPFILE" | grep -q "PDF"; then mv -- "$TMPFILE" "$OUTDIR_REAL/$FILENAME" trap - EXIT else echo "Downloaded content is not a PDF" >&2 exit 1 fi ``` Also define an explicit overwrite policy, such as refusing to replace an existing destination unless the caller provides a dedicated option. ]]>

other

Warning
Location
scripts/download.sh:16
Finding

Unrestricted User-Supplied URL Fetching Enables SSRF-Style Requests

Content
View full analysis
/dev/null if file -b "$OUTPATH" | grep -q "PDF"; then echo "✅ Downloaded from $label: $OUTPATH" return 0 fi rm -f "$OUTPATH" return 1 } # Strategy 1: Direct URL if provided if [[ -n "$URL" ]]; then try_download "$URL" "direct URL" && exit 0 fi ``` ### Technical Analysis Every input not recognized as a DOI is treated as a direct URL and passed to `curl`. The script does not restrict URL schemes or hosts, does not reject embedded credentials, and does not block loopback, private, link-local, or cloud metadata addresses. The `-L` option follows redirects without validating each redirect destination. Thus, even a URL with an initially acceptable hostname could redirect to an internal endpoint. Depending on the protocols supported by the installed curl build, non-HTTP schemes may also be reachable. ### Attack Path 1. An attacker provides a URL targeting an internal service, localhost endpoint, link-local metadata service, or attacker-controlled redirector. 2. The downloader invokes `curl` from the Agent’s network context. 3. If a redirector is used, `curl -L` follows the redirect to the otherwise restricted destination. 4. The internal service receives a GET request carrying the configured browser-like user agent. 5. If the response resembles a PDF, its content is retained in the selected output path; otherwise, the request still occurs before validation fails. ### Impact Assessment ...[truncated 537 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/convert.sh:31
Finding

Unpinned Package Resolution and Execution Through uvx

Content
View full analysis
/dev/null; then uvx markitdown[pdf] "$INPUT" > "$OUTPUT" 2>/dev/null if [[ -s "$OUTPUT" ]]; then echo "✅ Converted with markitdown[pdf]: $OUTPUT ($(wc -c < "$OUTPUT") bytes)" exit 0 fi fi ``` The corresponding dependency documentation states: ```markdown - `uvx markitdown[pdf]` (optional) — fallback PDF→MD converter ``` ### Technical Analysis The fallback invokes `uvx` with an unversioned package specification. `uvx` may resolve, download, install, and execute package code from a third-party package registry at runtime. Because neither the package version nor dependency integrity hashes are pinned, the effective executable code can change after the Skill has been reviewed. A compromised package release, transitive dependency, package registry, or future malicious version could therefore execute under the Agent’s identity. The fallback is reached when `pdftotext` is unavailable or fails to produce a non-empty output file. ### Attack Path 1. `pdftotext` is absent, fails, or produces an empty output. 2. The system has `uvx` installed. 3. The script executes `uvx markitdown[pdf]`. 4. `uvx` resolves the current package and dependency versions from its configured source or cache. 5. Any compromised code in the resolved dependency chain executes with the privileges of the conversion process. ### Impact Assessment A malicious dependency can execute arbitrary code with all permissions available to the user or Agent running the converter. This may expose local documents, modify project data, invoke network connections, or execute additional programs. ...[truncated 216 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes downloading papers from Sci-Hub and only includes a legal note, not a hard requirement for explicit user warning and consent before such action. In practice this means an agent could proceed directly to a copyright-bypassing source, creating serious policy, legal, and trust risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs using Sci-Hub to bypass publisher access controls and obtain paywalled papers. That introduces legal/compliance risk and normalizes unauthorized acquisition behavior that is outside legitimate literature-management needs, making the skill materially more dangerous in context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill invokes shell commands and external scripts but does not declare any tool scope or allowed-tools boundaries. That makes the skill harder to sandbox and review, and increases the chance an agent will execute commands beyond the minimum needed for literature management.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description is broad enough to match common research-assistance requests, which can cause the skill to be invoked in situations where its shell and download behavior is unnecessary or risky. Overbroad triggering increases the chance of accidental execution of network access and file-processing steps on behalf of unsuspecting users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
79% confidence
Finding

Referencing uvx markitdown[pdf] without a pinned version creates a supply-chain risk because future or compromised releases could change behavior or introduce malicious code. Since the skill encourages executing the package for document conversion, an unreviewed update could run in the user's environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
79% confidence
Finding

The skill recommends executing uvx markitdown[pdf] without pinning a specific version, exposing users to supply-chain and reproducibility risks. In a workflow that processes untrusted academic files, pulling the latest package at runtime expands the attack surface unnecessarily.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
79% confidence
Finding

The command example uses uvx markitdown[pdf] without version pinning, which allows whatever version is current at execution time to run. That can introduce malicious or breaking changes into an otherwise routine conversion workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
79% confidence
Finding

This occurrence is in a commented warning example showing an incorrect command, so it is less directly actionable than the other references. However, it still normalizes an unpinned package reference and should be cleaned up for consistency and to avoid copy-paste risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
79% confidence
Finding

The recommendation to prefer uvx markitdown[pdf] is not tied to a reviewed version, so users may execute an untrusted latest release. This is a classic dependency drift and supply-chain issue made more significant by direct execution of the tool.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/audit.sh (reported line 18)May include surrounding context.

sh
echo ""

# 0. Check dependencies
for cmd in pdftotext python3 curl file; do
  if ! command -v "$cmd" &>/dev/null; then
    echo "❌ Missing dependency: $cmd"
    ERRORS=$((ERRORS + 1))

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The script executes uvx markitdown[pdf] "$INPUT" without pinning an exact version, which can fetch and run whatever version is current at execution time. That creates a supply-chain risk: a compromised, malicious, or simply breaking upstream release could execute attacker-controlled code in the user's environment when converting PDFs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script queries multiple third-party services using a user-supplied DOI or URL, which leaks the user's research targets and access intent to external parties without explicit disclosure or consent. Because this is a literature-management tool, such transmission is functionally related, but the broad fallback behavior increases privacy and compliance risk, especially when reaching services like arXiv lookups, EuropePMC, and Sci-Hub.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script explicitly falls back to Sci-Hub, a piracy-oriented third-party service, to obtain papers when other sources fail. In a literature-management skill, this creates legal/compliance risk and sends user-requested DOIs to an untrusted external service that may expose users to policy violations, deceptive content, or unsafe downloads.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.