Back to skill

Security audit

Pyzotero

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Zotero management tool, but it needs review because its documentation encourages risky API-key storage, unpinned package installation, and force-delete commands.

Review before installing. Prefer local Zotero mode when possible, avoid sudo pip, use pipx or a virtual environment with a pinned pyzotero version if you can, and do not store or print ZOTERO_API_KEY in shell startup files. If using online mode, create a least-privilege Zotero key, keep it out of logs and screenshots, and be careful with collection delete or write commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:15
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15-25, SKILL.md:40, INSTALL.md:87, INSTALL.md:101, INSTALL.md:106
Vulnerability Type: Unpinned dependency and unsafe privileged installation guidance
Risk Level: Medium

Vulnerable Code

yaml
{
  "id": "pipx_lib",
  "kind": "pipx",
  "package": "pyzotero",
  "label": "Install pyzotero library (pipx - recommended)",
  "platforms": ["linux-debian", "linux-ubuntu", "linux-arch", "linux-fedora", "linux-rhel"],
},
{
  "id": "pip_lib",
  "kind": "pip",
  "package": "pyzotero",
  "label": "Install pyzotero library (pip)",
},
bash
pipx install pyzotero
bash
sudo pip install pyzotero
bash
pip install --user pyzotero

Technical Analysis

The installation configuration and documentation resolve the latest available pyzotero release without specifying an exact version, package hash, lock file, or other integrity constraint. Consequently, the dependency installed at a later date may differ from the version reviewed with this Skill.

The documented sudo pip install pyzotero alternative is particularly unsafe because package installation may execute package-controlled build or installation code with root privileges. Although no malicious dependency is currently demonstrated in the audited project, the installation process lacks controls that would limit exposure to a compromised or unexpectedly modified upstream release.

Attack Path

  1. An attacker compromises the upstream package, maintainer account, distribution infrastructure, or a future dependency release.
  2. A user follows the Skill documentation and runs pipx install pyzotero, pip install --user pyzotero, or sudo pip install pyzotero.
  3. The package manager resolves the attacker-controlled release because no reviewed version or hash is pinned.
  4. Malicious package installation or import-time code executes.
  5. With user-level ...[truncated 543 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin pyzotero to a reviewed, exact version in the Skill metadata and all installation examples.
  • Use a requirements or lock file containing cryptographic hashes, such as installation with --require-hashes.
  • Document the expected official package index and package provenance.
  • Remove the sudo pip install pyzotero recommendation.
  • Prefer a dedicated virtual environment or an isolated, version-pinned pipx installation.
  • Establish an update process in which dependency upgrades are reviewed and tested before changing the pinned version.

T09 · Insecure Skill Coding Practices

Warning
Location
INSTALL.md:263
Finding

Plaintext Persistence and Disclosure of the Zotero API Key

Content
View full analysis

Vulnerability Details

File Location: INSTALL.md:263-265, INSTALL.md:343-347, SKILL.md:280-283
Vulnerability Type: Insecure secret storage and diagnostic disclosure
Risk Level: Medium

Vulnerable Code

bash
echo 'export ZOTERO_LOCAL="false"' >> ~/.bashrc
echo 'export ZOTERO_USER_ID="your_user_id"' >> ~/.bashrc
echo 'export ZOTERO_API_KEY="your_api_key"' >> ~/.bashrc
source ~/.bashrc
bash
echo $ZOTERO_LOCAL
echo $ZOTERO_USER_ID
echo $ZOTERO_API_KEY

Technical Analysis

The installation guide recommends permanently storing the Zotero API key as plaintext in a shell startup file. It also recommends printing the complete secret during troubleshooting.

Shell profiles can be read by processes running as the same user and may be copied into backups, diagnostic archives, development environments, or support bundles. A globally exported key is inherited by child processes, increasing the number of processes that can access it. Printing the complete key may expose it through terminal recording, copied troubleshooting output, continuous-integration logs, remote-session capture, or shoulder surfing.

The main script itself reads the key from ZOTERO_API_KEY and sends it to the declared official Zotero API endpoint; no intentional exfiltration was identified. The weakness is the documented storage and diagnostic handling of that credential.

Attack Path

  1. A user follows the documentation and writes a valid Zotero API key into ~/.bashrc.
  2. The user sources the profile, causing the key to be inherited by subsequently launched processes.
  3. A malicious or compromised same-user process reads the profile or inherited environment, or an unauthorized party obtains a backup or support archive containing the profile.
  4. Alternatively, the user follows the troubleshooting instructions and prints the key into a recorded terminal or shared log.
  5. The attacker submits the recovered ke ...[truncated 591 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not recommend storing API keys directly in ~/.bashrc, ~/.zshrc, or other general-purpose startup files.
  • Use an operating-system secret manager, OpenClaw-supported secret facility, or a dedicated credential file readable only by the owning user.
  • If a credential file is necessary, require restrictive permissions such as mode 0600 and exclude it from source control and backups where appropriate.
  • Inject the key only into the process that requires it instead of globally exporting it to every child process.
  • Remove echo $ZOTERO_API_KEY from troubleshooting instructions.
  • Provide a redacted diagnostic command that reveals only whether the variable is set or displays a small non-sensitive suffix.
  • Recommend creating a least-privilege Zotero key and granting write or file permissions only when the required operation needs them.
  • Document immediate key revocation and rotation procedures for suspected disclosure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (29)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · INSTALL.md (reported line 112)May include surrounding context.

tall pyzotero

text

**3. 验证安装**
```bash
python3 -c "from pyzotero import zotero; print('pyzotero 已安装')"

方法二:pip (通用)

系统级安装 (需要 sudo)

bash
sudo pip install pyzotero

用户级安装 (推荐)

bash
pip install --user pyzotero
export PATH="$HOME/.local/bin:$PATH"

将 PATH 导出添加到 ~/.bashrc 或 ~/.zshrc:

bash
echo 'export PATH="$HOME/.local/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

方法三:虚拟环境

适合开发或测试:

bash
# 创建虚拟环境
python3 -m venv venv
source venv/bin/activate

# 安装 pyzotero
pip install pyzotero

# 验证
python3 -c "from pyzotero import zotero; print('OK')"

平台特定说明

Debian 11+ / Ubuntu 23.04+ (PEP 668 系统)

这些系统实施了 PEP 668,禁止使用系统 pip 安装包。

推荐方案:

bash
pipx install pyzotero

备选方案:

bash
pip install --user pyzotero
export PATH="$HOME/.local

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Even though the command is scoped to a specific directory, documenting 'rm -rf /root/.openclaw/workspace/skills/pyzotero-cli' without warning is dangerous because it is recursive, forceful, and targets a root-owned absolute path. In agent/skill environments, users may run commands as privileged users or adapt the path incorrectly, leading to unintended deletion of neighboring data.

Content

Scanner excerpt · INSTALL.md (reported line 391)May include surrounding context.

删除技能 (可选)

bash
rm -rf /root/.openclaw/workspace/skills/pyzotero-cli

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Even though the command is scoped to a specific directory, documenting 'rm -rf /root/.openclaw/workspace/skills/pyzotero-cli' without warning is dangerous because it is recursive, forceful, and targets a root-owned absolute path. In agent/skill environments, users may run commands as privileged users or adapt the path incorrectly, leading to unintended deletion of neighboring data.

Content

Scanner excerpt · INSTALL.md (reported line 391)May include surrounding context.

删除技能 (可选)

bash
rm -rf /root/.openclaw/workspace/skills/pyzotero-cli

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The changelog instructs users to set ZOTERO_USER_ID and ZOTERO_API_KEY for online API access but provides no warning that queries and library metadata may be transmitted to Zotero's web service or that API keys must be protected. In a developer-facing skill, this omission can lead users to expose credentials in shell history, shared dotfiles, logs, or screenshots, and to use remote mode without understanding the privacy implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation forces a specific language/locale for all usage examples and instructions, with no indication that Chinese is optional or that the skill is intentionally region-specific. Under the stated policy, this is a natural-language locale constraint without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The examples instruct users to export ZOTERO_API_KEY and related account identifiers directly in the shell, but do not warn that these are secrets or advise safer handling. In practice, this can lead to accidental disclosure through shell history, screenshots, shared terminals, copied scripts, or checked-in dotfiles, exposing access to a user's Zotero Web API account.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 62)May include surrounding context.

Debian/Ubuntu:

bash
sudo apt update
sudo apt install pipx -y
pipx ensurepath

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 63)May include surrounding context.

Debian/Ubuntu:

bash
sudo apt update
sudo apt install pipx -y
pipx ensurepath

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 69)May include surrounding context.

Debian/Ubuntu:

bash
sudo apt update
sudo apt install pipx -y
pipx ensurepath

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 75)May include surrounding context.

Debian/Ubuntu:

bash
sudo apt update
sudo apt install pipx -y
pipx ensurepath

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · INSTALL.md (reported line 167)May include surrounding context.

Debian/Ubuntu:

bash
sudo apt update
sudo apt install pipx -y
pipx ensurepath

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

The guide explicitly recommends 'sudo pip install pyzotero' as a generic installation option. Running pip as root bypasses distro package controls, can overwrite system Python packages, and executes package installation logic with full privileges, increasing the blast radius of supply-chain compromise or packaging mistakes.

Content

Scanner excerpt · INSTALL.md (reported line 101)May include surrounding context.

系统级安装 (需要 sudo)

bash
sudo pip install pyzotero

用户级安装 (推荐)

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The online-mode instructions have users create a private API key and then proceed toward persistent environment-variable setup, encouraging long-lived credentials for routine use. In a CLI skill context, that raises exposure risk because the token grants library access and may be left resident across sessions, shells, and support workflows.

Content

Scanner excerpt · INSTALL.md (reported line 244)May include surrounding context.

md
1. **获取 API 密钥:**
   - 访问 https://www.zotero.org/settings/keys
   - 点击 "Create new private key"
   - 授予读取权限 (Read access to library and files)
   - 复制密钥

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide tells users to persist a private Zotero API key in ~/.bashrc, which leaves a long-lived secret in plaintext in a common shell startup file. That increases the chance of accidental disclosure through backups, dotfile sync, screen sharing, shell-history-adjacent troubleshooting, or local compromise, especially on shared/admin-managed systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The uninstall section includes a recursive force-delete command against an absolute path with no warning, verification step, or safer alternative. Destructive commands in installation docs are risky because users may copy-paste them blindly, and path mistakes or environment differences can cause unintended data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The online mode example omits any privacy or network-transmission warning, even though searches and library operations may send user queries, metadata, and account-linked activity to Zotero's Web API. Users may assume behavior is equivalent to local mode and inadvertently disclose sensitive research topics or library information over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The online mode example omits any privacy or network-transmission warning, even though searches and library operations may send user queries, metadata, and account-linked activity to Zotero's Web API. Users may assume behavior is equivalent to local mode and inadvertently disclose sensitive research topics or library information over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The quickstart instructs users to place a long-lived Zotero API key directly into shell environment variables without any warning about credential exposure. Secrets exported in a shell can leak through shell history, process inspection, logs, screenshots, shared terminals, or persistence in startup files, which is especially relevant because the document later suggests adding common commands to shell rc files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions and user-facing documentation are presented in Chinese throughout the file, with no indication that users may choose another language. Per the policy, forcing a specific language without opt-in is a language/locale policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents use of ZOTERO_USER_ID and ZOTERO_API_KEY for remote access, and later suggests printing them with echo for troubleshooting. The skill description lacks any warning that these values are sensitive credentials and should be protected from shell history, shared terminals, logs, or screenshots.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises commands that use environment variables, local files, network access, and shell execution, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates an authorization and transparency gap: an agent or reviewer cannot tell from the manifest what capabilities the skill expects, increasing the risk of unintended execution with broader privileges than necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s instructional content and examples are presented in Chinese throughout, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. This can violate language/locale policy when a specific language is effectively forced without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings exclusively in Chinese in the module docstring and later user-facing prints, which effectively enforces a specific language for users. The policy allows locale constraints only when users are given a choice or when the constraint is explicitly justified, neither of which is present here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/examples.py (reported line 24)May include surrounding context.

python
def run_command(args):
    """运行 pyzotero.py 命令"""
    cmd = ['python3', SCRIPT_PATH] + args
    result = subprocess.run(cmd, capture_output=True, text=True)
    return result.stdout, result.stderr, result.returncode

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Natural-language policy violations apply to all file types, including code comments, docstrings, and help text. This file presents its primary instructions, usage, and messages only in Chinese, with no opt-in or alternative locale, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.destructive_delete_command

Documentation contains a destructive delete command without an explicit confirmation gate.

Warn
Code
suspicious.destructive_delete_command
Location
INSTALL.md:391