Back to skill

Security audit

个人文献知识库,自带全球文献检索(支持向量搜索+传统分词搜索)

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with an academic knowledge-base purpose, but it ships a plaintext gateway secret and gives users misleading privacy and account-handling expectations.

Review before installing. Do not use this package with confidential or unpublished research unless external SmartLib matching and embeddings are disabled or clearly confirmed. The publisher should remove and rotate the bundled gateway secret, correct the privacy disclosure, avoid URL query-string email transmission, and require explicit consent before registration, persistence, or cross-skill config changes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
config.json:3
Finding

Production Gateway Secret Embedded in Distributed Configuration

Content
View full analysis

Vulnerability Details

File Location: config.json:3
Vulnerability Type: Hard-coded production credential
Risk Level: High

Vulnerable Code

json
{
  "SMARTLIB_GATEWAY_URL": "https://1318491188-jvmi3wist0.ap-shanghai.tencentscf.com",
  "SMARTLIB_GATEWAY_SECRET": "[REDACTED EXPOSED sk- PREFIX SECRET]",
  "SMARTLIB_EMAIL": null,
  "SMARTLIB_APPID": null,
  "SMARTLIB_APPSECRET": null
}

The credential value is redacted in this report to avoid further disclosure. The audited file contains the complete plaintext secret.

Technical Analysis

The active configuration contains a plaintext, secret-like production gateway credential. This is not a sample value: config.example.json:3 uses the placeholder <your-gateway-secret>, demonstrating that the value in config.json is inconsistent with the intended configuration pattern.

Any party able to download the Skill package or read its source can recover the credential without authentication. If the gateway accepts this value for authentication or authorization, it can be replayed outside the Skill. Storing the secret in JSON also exposes it to source-control history, package archives, backups, diagnostic collection, and other users with access to the installation.

Attack Path

  1. An attacker downloads or otherwise obtains the distributed Skill package.
  2. The attacker opens config.json and extracts SMARTLIB_GATEWAY_SECRET.
  3. The attacker identifies the associated endpoint from SMARTLIB_GATEWAY_URL.
  4. The attacker reproduces the gateway request format used by the related SmartLib integration.
  5. If the gateway accepts the exposed secret, the attacker submits authenticated requests independently of the Skill.
  6. The credential remains reusable until it is revoked or rotated.

Impact Assessment

Potential impact depends on the gateway permissions assigned to the secret. If valid, exposure may permit unauthorized gatewa ...[truncated 474 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed gateway secret immediately.
  2. Remove config.json containing production values from the distributed package and source-control history.
  3. Ship only config.example.json with placeholders.
  4. Load secrets from environment variables, an operating-system credential store, or the platform's managed secret facility.
  5. Apply strict filesystem permissions to any locally generated configuration containing credentials.
  6. Configure narrowly scoped, per-installation credentials rather than a shared production secret.
  7. Add automated secret scanning to pre-commit and release pipelines.
  8. Review gateway logs for suspicious use of the exposed credential and invalidate related sessions or tokens where necessary.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:134
Finding

User Email Address Transmitted in a URL Query String

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:134-140
Vulnerability Type: Personal information exposed through URL parameters
Risk Level: Medium

Vulnerable Code

text
SMARTLIB_EMAIL configured → reuse credentials and perform quota check

Quota check:
GET {GATEWAY_URL}/quota?email={SMARTLIB_EMAIL}

If the response is 404 "not_registered":
  call gateway /register using the same email
  write the result to config.json

Technical Analysis

The Skill instructs the Agent to place the user's email address directly in the query string of a GET request. Although HTTPS protects the request in transit from passive network observers, URLs are routinely captured by application access logs, reverse proxies, API gateways, monitoring systems, tracing platforms, and debugging tools.

An email address is personally identifiable information. Sending it in a URL therefore expands its exposure and retention beyond what is necessary for a quota lookup. The email is relevant to the declared registration and quota functionality, so the network call itself is not inherently unauthorized; the insecure element is the transport location and associated logging risk.

The instructions also persist registration information to configuration. Without documented retention, access controls, and redaction, this can create additional local and remote copies of the identifier.

Attack Path

  1. The user supplies an email address for SmartLib registration or quota management.
  2. The Agent interpolates that value into /quota?email={SMARTLIB_EMAIL}.
  3. The request passes through the configured cloud gateway and any associated proxy or monitoring infrastructure.
  4. One or more systems record the complete request URL.
  5. An operator, compromised logging account, log-export recipient, or other party with log access retrieves the user's email from the recorded URL.
  6. The disclosed address may then be correlated with acade ...[truncated 583 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the GET request with an authenticated POST request and place the email in the request body.
  2. Use an opaque account identifier for recurring quota checks after registration instead of repeatedly transmitting the email.
  3. Configure gateway, proxy, tracing, and application logs to redact personal identifiers.
  4. Define and disclose retention periods for registration and quota records.
  5. Encrypt locally persisted account configuration and restrict its filesystem permissions.
  6. Obtain explicit user consent before registration and clearly identify the recipient service and purpose.
  7. Avoid including email addresses in errors, telemetry, diagnostic bundles, or user-visible debug output.

other

Warning
Location
README.md:106
Finding

Local-Only Privacy Claim Contradicts External Transmission of User Data

Content
View full analysis

Vulnerability Details

File Location: README.md:106-108; related behavior in SKILL.md:117-146, SKILL.md:300-304, and SKILL.md:335-340
Vulnerability Type: Misleading privacy disclosure
Risk Level: Medium

Conflicting Documentation and Behavior

The README privacy answer at README.md:106-108 states, in English translation:

text
Q: Is my data secure?
A: Everything is stored locally under ~/.workbuddy/academic-kb/;
   nothing is uploaded to any server.

However, the Skill defines external document matching:

text
Step 1: Parse the document.
Step 2: Match against SmartLib using the title and author through the search API.
Step 3: Store the document and completed metadata locally.

It also defines external embedding requests:

http
POST {base_url}/embeddings
Authorization: Bearer {api_key}
Body: {"model": "{model_name}", "input": ["text 1", "text 2"]}

In addition, SKILL.md:117-146 requires collecting and transmitting the user's email to the SmartLib gateway for registration and quota operations.

Technical Analysis

The Skill's declared features legitimately require some network access, including SmartLib literature search, document metadata matching, quota management, and optional vectorization. The privacy statement is nevertheless materially inaccurate because it claims that no information is uploaded to any server.

Depending on the operation, the external data can include:

  • The user's email address.
  • Literature search queries.
  • Titles and author names extracted from uploaded documents.
  • Abstracts or other text selected for vectorization.
  • Potentially sensitive research topics, unpublished titles, or document-derived content.

The embedding request's input field is not bounded to a clearly disclosed minimum set of fields. Users may therefore believe an imported document remains entirely local while portions of it are sent to a third-part ...[truncated 1488 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the local-only claim with an accurate, prominent data-flow disclosure.
  2. Identify each external recipient, the fields transmitted, the purpose, and whether the feature is optional.
  3. Require explicit opt-in before enabling SmartLib matching or third-party vectorization for user-uploaded documents.
  4. Show a confirmation containing the destination and data categories before the first transmission.
  5. Default confidential uploads to local-only parsing and lexical search.
  6. Send only the minimum text required for each operation; do not transmit full text when title-only or abstract-only processing is sufficient.
  7. Allow users to disable external matching independently from external search.
  8. Support a local embedding provider as the privacy-preserving default.
  9. Document provider retention, deletion, and training-use policies.
  10. Add controls allowing users to inspect and delete locally stored credentials and externally registered account information.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill contains contradictory credential-handling rules: it says the agent must ask the user for an email first, but also instructs reuse of a preconfigured email from another skill's config and even writing back to that config. This creates a privacy and authorization risk because the agent may act on behalf of a prior user or silently bind/query an account without fresh user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README describes ingestion of uploaded papers, news, and personal academic data but does not clearly warn that these inputs are parsed and written into a persistent local knowledge base. For research materials, personal notes, and experimental data, silent persistence can expose sensitive unpublished work, regulated data, or confidential documents to unintended retention and later retrieval.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The monetization section instructs users to reply with the Chinese phrase '充值' to obtain a payment code, which imposes a language-specific interaction requirement. The README is bilingual overall, but this command is presented without an English alternative or explicit language choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough that ordinary literature- or note-related requests could unintentionally invoke this skill and cause persistence actions or external searches. In a skill that can create local storage, parse files, and consume shared quota, accidental activation creates real privacy, cost, and data-retention risk even without explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example phrases around first-use actions are ambiguous and do not clearly distinguish between temporary assistance and persistent knowledge-base operations. Because the skill auto-creates directories and may trigger external retrieval on casual prompts, a user may unknowingly start local retention and quota consumption.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad, natural phrases that can appear in ordinary conversation, increasing the chance the skill activates unexpectedly. Because the skill can write files, store data, and make external requests, accidental invocation can lead to unintended persistence or network activity without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The quick-trigger table gives ambiguous examples without guardrails or confirmation requirements, which can cause the agent to interpret casual language as operational commands. In this skill's context, that may initiate storage, tagging, exporting, or other actions affecting the user's local knowledge base.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs automatic persistence of user-provided materials, notes, and derived summaries into multiple files such as raw content, databases, wiki pages, session notes, analysis, and logs. This creates a data retention risk because sensitive or unpublished research content may be copied into more locations than the user expects, increasing exposure and making deletion harder.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs automatic extraction of email addresses from user messages and their reuse for registration and quota operations. Even if convenient, this can process personally identifiable information without clear confirmation and may cause external account actions to occur based on incidental text rather than explicit consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document promises file access is limited to ~/.workbuddy/academic-kb/, yet operational steps require reading and writing ~/.workbuddy/skills/global-biblio-base/config.json. That cross-skill access breaks the declared trust boundary and can expose or modify unrelated credentials and state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The security section at L550 says the skill uses only SmartLib API and vectorization API with no telemetry. But L177 explicitly documents '外文 OA PDF 探测' via an external free API, which is an additional network destination not covered by that claim. This creates a clear documentation-versus-behavior contradiction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill performs persistent local storage of user academic content, notes, metadata, and derived analysis, but the description does not present a clear upfront disclosure of that behavior. Users may share sensitive research materials believing the interaction is ephemeral when it is actually retained in a local knowledge store.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.