Back to skill

Security audit

Getnote 1.5.7

Security checks for vulnerabilities and agentic risk

Overview

This note-taking skill is mostly coherent, but it handles private notes and long-lived credentials with several under-scoped safeguards that users should review before installing.

Install only if you are comfortable granting this skill access to your private Get笔记 notes. Configure GETNOTE_OWNER_ID before using it in shared or group chats, avoid using the helper scripts with sensitive local paths, treat OAuth output as secret, and prefer ClawHub installation over the README's raw GitHub curl method.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:43
Finding

Private note operations rely on optional sender authorization

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/oauth_poll.py:97
Finding

OAuth API key is exposed through process standard output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/upload_image.py:53
Finding

Image uploader can transmit arbitrary local files to an unvalidated server-provided host

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
README.md:111
Finding

Manual installation retrieves mutable Skill instructions without integrity verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README presents all user prompts, examples, and operational instructions exclusively in Chinese, with no indication that language choice is optional. This can amount to a language-policy violation if the skill expects or defaults to a specific language without offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 109)May include surrounding context.

方式三:手动安装

bash
mkdir -p ~/.openclaw/workspace/skills/getnote
cd ~/.openclaw/workspace/skills/getnote
curl -sL https://raw.githubusercontent.com/iswalle/getnote-openclaw/main/SKILL.md -o SKILL.md
curl -sL https://raw.githubusercontent.com/iswalle/getnote-openclaw/main/package.json -o package.json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises very broad natural-language triggers such as generic save/search/manage-note phrasing, which can cause the agent to invoke the skill on ambiguous user messages without clear intent confirmation. For a note-taking integration that can store private content and retrieve personal notes, overbroad activation increases the chance of unintended data disclosure or unintended writes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares network, environment-variable, and shell-like capabilities but does not constrain them with an explicit tool/permission allowlist. In an agent setting, missing scope boundaries can let the skill invoke more powerful primitives than users would reasonably expect, increasing the blast radius for prompt injection, data exfiltration, or unintended side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases for invoking the skill are overly broad, including common conversational words like '保存' or '收藏'. In an agent environment, this can cause accidental invocation on unrelated user messages, leading to unintended network calls, storage of private content, or note operations the user did not mean to perform.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file states that the agent should verify sender_id against GETNOTE_OWNER_ID before operating on private notes, but this protection is only documented and not enforced in executable logic here. If the runtime does not independently implement that check, another user in a shared context could trigger read/write operations against the owner's private notes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The natural-language router uses single characters and very common verbs such as '记', '存', '搜', and '看看' as dispatch triggers without robust boundaries. This makes false positives likely and increases the chance of unauthorized or privacy-impacting actions being taken from ordinary conversation, especially in multi-turn or shared-chat contexts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The package description includes very broad natural-language trigger phrases such as '说「记一下」就能存,说「搜一下」就能找', which can overlap with ordinary user conversation and cause unintended invocation. In a note-taking skill, accidental activation is risky because it may capture, store, or search private user content without sufficiently explicit intent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-details.md (reported line 222)May include surrounding context.

bash
# 1. 获取上传凭证
curl 'https://openapi.biji.com/open/api/v1/resource/image/upload_token?mime_type=jpg&count=1' \
  -H 'X-Client-ID: {client_id}' \
  -H 'Authorization: {api_key}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation includes a delete-note operation but does not require any explicit user-facing confirmation or warning before performing a destructive action. In an agent context, this increases the chance that ambiguous user input, prompt injection, or UI misunderstanding could cause unintended note deletion, even if the API only moves items to trash.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to automatically initiate OAuth Device Flow before every API call whenever $GETNOTE_API_KEY is absent, even if the user did not explicitly request account linking. That creates an overly broad auth trigger that can surprise users, condition them to approve authorization prompts in unrelated contexts, and potentially cause unintended account connection or consent fatigue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, and there is no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. The policy requires flagging forced language or locale behavior when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger examples for global search are broad conversational phrases like “搜一下” and “找找我哪些笔记提到了 XX”, which can overlap with ordinary user requests that do not clearly intend to query a personal note store. In a note-management skill, this can cause unintended retrieval of private notebook content and unnecessary data exposure if the agent invokes the search API without explicit user confirmation or namespace grounding.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, usage instructions, and runtime messages are entirely in Chinese, which imposes a specific language on all users. Under the policy, locale or language restrictions should either provide user opt-in/choice or be clearly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This Python code reads a user-supplied local image file and transmits both the file contents and API credentials to remote endpoints. Although the script prints progress messages, it does not clearly warn the user that local data will be uploaded to an external service, which is the kind of disclosure SQP-2 expects for network transmission of user data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/upload_image.py (reported line 177)May include surrounding context.

python
print(f"访问 URL: {image_url}")
        print()
        print("💡 创建图片笔记:")
        print(f'   curl -X POST "https://openapi.biji.com/open/api/v1/resource/note/save?task_id=..."')
        print(f'     -H "Authorization: $GETNOTE_API_KEY"')
        print(f'     -H "Content-Type: application/json"')
        print(f'     -d \'{{"type":"img_text","image_urls":["{image_url}"]}}\'')

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

文件中的触发短语、指令示例和固定回复语均以中文为唯一语言呈现,例如“不匹配时回复‘抱歉,笔记是私密的,我无法操作’”。这会形成默认语言约束,但文档未说明可根据用户语言偏好切换,也未提供显式语言选择。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes the skill as saving, searching, and managing personal notes and knowledge bases, but the documented command set also includes deleting notes, blogger subscriptions, live subscriptions, and credential configuration flows. These are broader operational capabilities than the short manifest description suggests, even though they appear intentionally supported by the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file title and all surrounding instructional text are presented in Chinese, which effectively forces a specific language for users consuming this skill documentation. Under the policy, language constraints should either provide user choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes an operation to remove notes from a knowledge base, but the section provides no user-facing warning about the action affecting stored organization of user data or whether the removal is reversible. Under the markdown-specific warning rule, destructive or data-affecting behavior should be disclosed clearly in the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

整个技能说明与示例对话均固定为中文表达,未说明是否支持按用户偏好切换语言或 locale。按规则,若技能在自然语言层面强制单一语言且无用户选择机制,可能构成语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The knowledge-base search guidance says it applies when the user says “在我的 XX 知识库搜一下 XX”, but it does not define how confidently the agent must map a natural-language name to a specific topic_id or what to do when multiple matches exist. This ambiguity can lead to searching the wrong knowledge base, causing minor privacy leakage across a user’s own collections or returning misleading results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file documents POST actions that add and delete note tags, which are user-data modifications. While the file explains request/response details and notes that system tags cannot be deleted, it does not explicitly warn users that invoking these operations will change note metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script's docstrings, help text, and console messages are presented in Chinese, which imposes a specific language on users without any choice or documented locale constraint. Under SQP-3, forcing a language/locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.