Back to skill

Security audit

AI Book Recommendation Engine(AI 书籍推荐引擎)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed book-recommendation helper that searches public book sites and runs a small local scoring script, with no evidence of hidden, destructive, or persistent behavior.

Install only if you are comfortable with your book topics and candidate titles being searched on third-party services. The skill is strongly Chinese/Douban-oriented and includes a local Python scoring utility, but the inspected utility is narrow and deterministic.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented search strategy hard-codes Chinese queries such as "经典书籍推荐" and "必读书单", and the example output is also presented in Chinese fields/content. This indicates a locale/language preference is imposed by default rather than offered as a user-selectable option, which is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The input examples, output schema values, search templates, and required warning/error text are predominantly fixed in Chinese, indicating a Chinese locale requirement. The file does not offer users a language/locale choice or explain that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill explicitly directs the agent to invoke a local script (scripts/score_books.py) and pass collected data through stdin, expanding the behavior from web-based recommendation into local code execution. Even if the script is intended to be deterministic, introducing executable local components increases attack surface because the script may be modified, unsafe, or process untrusted input in unexpected ways.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language comments and later user-visible error strings in Chinese, while the rest of the file is in English. Under the policy, forcing a specific language without opt-in is a locale/language policy violation unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The exception messages returned to users are only in Chinese, with no mechanism for language selection or indication that the skill is region-specific. This is a direct natural-language policy issue because it constrains the user experience to one language by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs sending user-supplied topics and candidate book queries to external search engines and sites such as Douban and Goodreads without disclosing that this data leaves the local environment. This creates a privacy and transparency issue, especially if topics reveal sensitive interests, internal research areas, or user behavior patterns.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.