Back to skill

Security audit

Cnki

Security checks for vulnerabilities and agentic risk

Overview

The CNKI skill appears purpose-aligned, but it should be reviewed because it uses a logged-in browser, user-supplied URLs, downloads, and Zotero/file export without tight scoping.

Install only if you are comfortable using a dedicated Chrome profile for CNKI, manually confirming downloads and Zotero exports, and limiting supplied URLs to official CNKI pages. Avoid using a browser profile that contains unrelated logged-in accounts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:47
Finding

Unrestricted User-Supplied URL Navigation in an Authenticated Browser Session

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:47-57, SKILL.md:82, SKILL.md:98-100, and SKILL.md:144-146
Vulnerability Type: Unvalidated URL navigation
Risk Level: Medium

Vulnerable Snippets

SKILL.md:47-57:

text
detail [URL]
detail https://kns.cnki.net/kcms2/article/abstract?xxx

download pdf [URL]
download caj [URL]

SKILL.md:82 and SKILL.md:98-100 instruct the browser workflow to navigate to a supplied paper URL before checking authentication state or CAPTCHA conditions.

SKILL.md:144-146 requires Chrome with browser automation and recommends retaining the authenticated session.

Technical Analysis

The skill accepts arbitrary URLs for its detail, download, and export workflows but does not define any URL validation or destination restrictions. The CNKI URL shown in the examples is illustrative and does not enforce a security boundary.

A secure implementation should parse the supplied URL and enforce an explicit allowlist of required official CNKI hosts. It should also restrict the scheme to HTTPS, reject embedded credentials and unexpected ports, and verify redirect destinations. Without these controls, schemes such as file:, data:, or javascript:, unrelated HTTPS domains, and redirects to attacker-controlled hosts are not explicitly prohibited.

The exposure is amplified by the recommendation to keep Chrome logged in. Browser same-origin controls ordinarily prevent an unrelated website from directly reading CNKI cookies, but they do not prevent the browser automation agent from processing hostile page content, initiating unintended downloads, encountering phishing content, or being influenced by instructions rendered on an attacker-controlled page.

Attack Path

  1. An attacker or untrusted input source supplies a detail, download, or export command containing a URL outside the legitimate CNKI domain.
  2. The skill follows its documented workflow and ...[truncated 1177 chars]
Remediation
View remediation

Remediation Suggestions

  1. Parse every supplied URL with a standards-compliant URL parser before browser navigation.
  2. Permit only the https: scheme. Explicitly reject http:, file:, data:, javascript:, and all other schemes.
  3. Define a minimal hostname allowlist containing only the official CNKI hosts required by each operation, such as kns.cnki.net.
  4. Compare normalized hostnames exactly. Do not use substring checks that would accept domains such as kns.cnki.net.attacker.example.
  5. Reject URLs containing embedded usernames or passwords, unexpected ports, malformed hostnames, or ambiguous encoded characters.
  6. Validate the final destination after every redirect and terminate navigation if any redirect leaves the allowlist.
  7. Require explicit user confirmation before initiating a file download or navigating outside the expected page flow.
  8. Use a dedicated browser profile containing no unrelated authenticated sessions or sensitive browsing state.
  9. Treat all page content as untrusted data and prohibit webpage text from changing tool permissions, security rules, or the task objective.
  10. Add automated tests covering malicious domains, subdomain confusion, encoded hostnames, unsupported schemes, embedded credentials, and cross-domain redirects.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

A bash capability is context-inappropriate for a CNKI portal skill because it gives the workflow access to execute local shell operations unrelated to browsing or metadata retrieval. In an agent setting, this kind of capability expansion is dangerous because seemingly harmless export flows can become vectors for command execution, file modification, or data exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The usage examples explicitly show downloading papers and exporting citations to tools like Zotero, which can affect local data and external applications. In this markdown file, those behaviors are presented as normal commands without any warning about file creation, overwrite risk, destination handling, or data transfer implications.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

Lines L132-L150 present the unified entry logic as if it already exists in a single-file architecture. However, L224-L225 and L263 state that the complete implementation and testing are still future work, so the documentation overstates the current code reality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The batch workflow states that exported data is pushed to Zotero via bash without any privacy, consent, or system-impact warning. Because this involves transfer of citation data to another application and shell-mediated local actions, the lack of disclosure and confirmation increases the risk of unintended data propagation and unsafe automation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The report explicitly documents using a shell command (bash) to push exported data into Zotero, which exceeds the narrowly described CNKI portal operations of search, detail lookup, download, and export. Expanding a content-retrieval skill to invoke shell-level actions increases the attack surface and can enable unintended local system side effects if the exported content or arguments are not tightly controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill integration plan, including command guidance and user-facing examples, is presented only in Chinese with no indication that other languages are supported or that users may opt into a preferred locale. This can violate language/locale policy when a skill implicitly forces a specific language without user choice or justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes the skill as a unified entry for CNKI search, download, export, and detail lookup. This plan documents additional capabilities such as journal search/TOC, batch download, citation analysis, cross-database search, scholar homepage queries, and institutional knowledge base access, which go beyond the stated description rather than merely implementing it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill metadata and usage guidance are entirely presented in Chinese, and the command hint examples assume Chinese-language interaction without any opt-in or alternative locale. Under the stated policy, enforcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file states that export ris [URL] will save an RIS file, which affects user data on the local system. While download/export behavior is central to the skill, the description does not explicitly warn where the file will be written or that a local file will be created, so users may not realize a filesystem write occurs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.