Back to skill

Security audit

article-organizer-builder

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed builder for creating an Obsidian article-organizer skill, with local file movement risks that are described and bounded rather than hidden.

Before installing, be aware that using this builder will create a persistent local skill and that the generated organizer may move processed source articles and attachment folders into an archive or recycle location. Review the generated paths and cleanup behavior before running the generated skill on important notes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
3. **生成目标 skill**:在 `~/.workbuddy/skills/<用户主题相关的名字>/` 下按规范 8 步生成完整目录:`SKILL.md` + `scripts/scan.py` + `scripts/cleanup.py` + `references/classification.md`。规范中

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description advertises 'cleanup source files' behavior but does not clearly warn about the data-impact risks or require explicit approval for destructive or quasi-destructive actions. Even though the note mentions 'archive not delete' for generated scripts, the skill's own high-level description still normalizes source-file cleanup without defining safeguards, which can lead to accidental data loss or unexpected file state changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly states it will generate and write a new skill under ~/.workbuddy/skills/, but it does not require explicit user confirmation immediately before performing that filesystem modification. Because this is a meta-skill that creates executable automation artifacts, silent or implicit writes could surprise the user, create persistence, or install unsafe logic into the user's environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill goal states that after archiving, the source files will be cleaned up automatically, which affects user data and file location. Although later sections describe safety constraints like archiving or recycle-bin use, the description does not clearly warn the user up front that successful execution will move their original files and attachments out of the source directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction "用中文写一份流程说明" forces a specific language for generated skill documentation. There is no indication that the user may opt into another language or that the skill is region-specific enough to justify a mandatory Chinese-only policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.