Back to skill

Security audit

地方文博文史研究 Local Wenbo Research

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese local-history research helper, but users should keep uncertainty labels visible and understand its limited network lookups.

Install only if you are comfortable with a Chinese-language research workflow that can fetch public texts from GitHub, optionally query Baidu Baike with book titles, and cache downloaded texts locally. For serious museum, archival, or scholarly use, keep confidence and pending-verification labels in the final report even though the skill text says to omit them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill advertises an authoritative local-history research framework grounded in curated 四库 and multi-source evidence, but the described implementation mainly performs retrieval and keyword extraction from limited open-source texts. This mismatch can mislead operators into overtrusting outputs as scholarly or policy-grade conclusions, especially because the skill presents itself as suitable for formal cultural-heritage research.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill invokes shell commands and network-backed data retrieval workflows but does not declare any explicit tool or permission scope. This creates an authorization gap where an agent may execute broader capabilities than users expect, increasing the risk of unintended file writes, command execution, or remote fetches under a benign research pretext.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill requires internal use of uncertainty, verification status, and confidence grading, but then instructs final reports to suppress terms like '待核' and '置信度'. In a research workflow, hiding unresolved verification status can cause speculative or weakly sourced claims to be presented as established fact, which is dangerous for cultural-heritage, archival, or institutional decision-making.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The final output policy explicitly suppresses uncertainty markers even when conclusions are internally graded as needing verification. This is a direct safety-quality failure because it converts tentative findings into apparently definitive statements, increasing the likelihood of misinformation and improper reliance by museums or local-history institutions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction says discussions '必须使用「当时」的地名、地貌、物产称谓' and '禁止古今混用', which imposes a mandatory terminology/locale policy in natural language. The file does not present this as an optional convention or offer user choice, so it constitutes a language/locale constraint without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title and opening statement are written as a universal requirement and say the specification 'must be followed' for all local historical-cultural research, but provide no user choice or justification for enforcing Chinese-language output. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest describes a research skill centered on using specific historical reference corpora to reconstruct local academic narratives, but it does not justify spawning external system binaries as part of that purpose. Network retrieval of open texts is understandable for this workflow, yet shelling out to curl adds an execution capability beyond what is semantically necessary for a literature-fetching helper.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_ancient.py (reported line 66)May include surrounding context.

python
url = RAW_BASE + urllib.parse.quote(rel)
    # 优先 curl(对慢速/不稳定连接更稳健),失败 fallback 到 urllib
    try:
        subprocess.run(
            ["curl", "-sL", "--max-time", "180", "--retry", "2",
             "-A", "Mozilla/5.0 wenbo-research", url, "-o", p],
            check=True, timeout=200)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill file is written in Chinese and does not provide any indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains user-facing natural-language instructions exclusively in Chinese, including the description and usage examples. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. The docstring and user-facing output are written in Chinese only, which effectively forces a specific language without indicating user opt-in or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

When the optional --web mode is used, the script transmits the user-supplied book title to Baidu over the network. This creates a real privacy/data-handling issue because potentially sensitive research queries are disclosed to a third party, and the script does not present a clear runtime warning or consent prompt beyond the flag itself. In this skill context, the queried titles are usually bibliographic terms rather than secrets, so the impact is limited but still real.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.