Back to skill

Security audit

书到技能 · 把技术书/PDF 蒸馏成 AI 技能

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent document-to-skill purpose, but it should be reviewed because untrusted PDF content can be transformed into persistent agent instructions without clear safeguards.

Install only if you are prepared to review generated skills before importing them. Use trusted or authorized PDFs, treat extracted sections as untrusted source text, inspect the generated SKILL.md and references for hidden instructions, and install Python dependencies in an isolated environment with pinned versions where possible.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:45
Finding

Indirect Prompt Injection Through Untrusted PDF Content

Content
View full analysis
Remediation
View remediation
... ``` 3. Separate data extraction from instruction generation. Generate a neutral serialized representation of document text and require the agent to process it under a fixed trusted prompt. 4. Add a validation stage before packaging: - Flag phrases that attempt to override prior instructions. - Flag tool invocation requests, credential requests, external URLs, encoded payloads, and commands unrelated to the source methodology. - Require human approval for generated executable scripts or operational instructions. 5. Ensure generated Skills cannot automatically inherit scripts or commands from source material. Any executable artifact should require explicit user approval and independent code review. 6. Run the distillation agent with least privilege: disable unnecessary network, shell, credential, and filesystem tools while processing untrusted documents. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a higher-level 'knowledge skillization' capability: converting books/PDFs/specs/manuals into usable AI skills that internalize methodologies for decision-making. The supplied code does not perform that transformation. It is explicitly labeled 'Stage 1' and only extracts and segments PDF text into sections, plus TOC/metadata scaffolding for later distillation. That is related support functionality, but the primary behavior of this chunk is document parsing, not skill creation. There is no evidence of rule extraction, template generation, mental-model distillation, or packaging into an AI skill. Therefore the description overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes transforming source materials such as books and PDFs into reusable AI skills/knowledge packs, explicitly contrasting this with RAG-style retrieval. The supplied code does not perform ingestion, parsing, summarization, rule extraction, skill packaging, or any conversion workflow. Instead, it indexes Markdown files under a references folder by simple term counts and returns top matching snippets for a query, which is a retrieval/search utility. That is a materially different primary purpose from the declared skill behavior, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- `SKILL.md` `description` must list concrete triggers ("when implementing X from <book>…").

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
- `SKILL.md` `description` must list concrete triggers ("when implementing X from <book>…").

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- `SKILL.md` `description` must list concrete triggers ("when implementing X from <book>…").

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The primary descriptive content and usage guidance are written in Chinese, and the file does not offer an explicit language choice or state that the skill is intentionally limited to Chinese-speaking users. This can violate language/locale policy expectations when users are not given opt-in or alternatives.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description contains broad trigger phrases such as '把这本书变成 skill' and '把 PDF 转成技能' that can match many ordinary user requests, causing the skill to activate outside a clearly bounded context. Over-broad activation increases the chance of unintended file-processing workflows, accidental ingestion of sensitive local documents, or the model applying this skill when a simpler/safe response was intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction tells the user to import via the Skills UI using the Chinese label "上传技能" and does not offer an alternative language or note that this applies only to a Chinese-localized interface. That can violate language/locale policy guidance when no user opt-in or locale justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.