Back to skill

Security audit

Book Deep Reader

Security checks for vulnerabilities and agentic risk

Overview

This skill is a book-research note generator that uses web sources and writes a markdown notes file, with only minor usability concerns about default language and filename handling.

Before installing, expect the agent to search the web for book information and create a markdown notes file in your workspace. If you need English-only output or a specific filename/location, state that up front and ask the agent to avoid overwriting existing files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template hardcodes the generated note title in Chinese ("《书名》深度读书笔记"), and the rest of the scaffold is entirely written as Chinese section headings and prompts. This imposes a specific language/locale on outputs without indicating that the user can choose another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to save a markdown file into the workspace but does not tell the user beforehand that a file will be created or whether an existing file with the same name may be overwritten. This can cause unintended modification of user files or confusion about where outputs are stored, especially in shared or automation-heavy workspaces.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill hardcodes output filename conventions based on language without asking the user to choose the filename or storage convention. While not severe, this can lead to unexpected file creation, naming conflicts, or difficulty integrating with user workflows that require specific naming or destination rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This reference uses bilingual section content and search instructions such as Chinese query phrases alongside English ones, which imposes a language/locale assumption on users. Under the policy, forcing a specific language without opt-in can be a natural-language policy issue when no justification or user choice is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.