Back to skill

Security audit

knowledge-base-manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent knowledge-base tool, but it sends private document searches and uploads to a hard-coded external HTTP service and includes destructive delete operations without clear consent or safety guidance.

Review this skill carefully before installing. Only use it with non-sensitive documents unless you control and trust the remote service, and avoid automatic searches or uploads until the endpoint uses HTTPS, the destination is configurable, and delete operations require explicit confirmation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
search.py:12
Finding

Plaintext HTTP exposes knowledge-base queries and allows search-result tampering

Content
View full analysis

Vulnerability Details

File Location: search.py:12-22, search_kb.py:9-21, and SKILL.md:54-58,82-86,103-106
Vulnerability Type: Cleartext transmission of potentially sensitive knowledge-base data
Risk Level: Medium

Technical Analysis

Both search scripts hardcode a remote knowledge-base service using plaintext HTTP. Requests containing the user's query are sent without TLS, and returned document excerpts are accepted without transport-level server authentication or integrity protection.

Relevant code from search.py:

python
# Configuration
KB_SERVICE_URL = "http://crawdxiaowu.com:3000"

def search_knowledge_base(query: str, kb_id: str = "default", top_k: int = 5) -> dict:
    """Search the knowledge base."""
    url = f"{KB_SERVICE_URL}/api/knowledge-bases/{kb_id}/search"
    
    data = {
        "query": query,
        "top_k": top_k
    }
    
    try:
        resp = requests.post(url, data=data, timeout=30)

Relevant code from search_kb.py:

python
KB_SERVICE_URL = "http://crawdxiaowu.com:3000"

def main():
    query = sys.argv[1] if len(sys.argv) > 1 else ""
    kb_id = sys.argv[2] if len(sys.argv) > 2 else "test-kb"
    
    if not query:
        print("Usage: python3 search_kb.py 'search content' [knowledge base ID]")
        sys.exit(1)
    
    url = f"{KB_SERVICE_URL}/api/knowledge-bases/{kb_id}/search"
    
    try:
        resp = requests.post(url, data={"query": query, "top_k": 3}, timeout=30)

The Skill documentation also directs the Agent to use the same plaintext production service for listing, uploading, searching, and deleting knowledge-base content. For example:

bash
curl -X POST http://crawdxiaowu.com:3000/api/knowledge-bases/{kb_id}/files \
  -F "file=@/path/to/document.pdf" \
  -F "chunk_size=500" \
  -F "chunk_overlap=50"
bash
curl -X POST http://crawdxiaowu.com:3000/api/knowledge-bases/{kb_id}/
...[truncated 1762 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the hardcoded HTTP endpoint with an HTTPS endpoint protected by a valid certificate.
  • Retain certificate verification in requests; do not set verify=False or implement an automatic plaintext fallback.
  • Reject non-HTTPS production service URLs during configuration validation.
  • Update every curl example in SKILL.md to use HTTPS.
  • Configure the service to redirect or, preferably, refuse plaintext HTTP requests.
  • Consider authenticating requests and responses at the application layer where appropriate, while recognizing that authentication does not replace TLS.
  • Avoid logging full private queries, document contents, or retrieved excerpts during migration and diagnostics.
  • After deploying HTTPS, test search, upload, deletion, and listing operations to ensure no operation silently returns to the plaintext endpoint.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个较完整的知识库管理与检索能力集合,包括管理、上传、向量存储及供Agent自动检索使用;而实际代码只是一段独立的搜索客户端,通过HTTP POST调用远程知识库搜索接口并格式化输出结果。虽然“语义检索/搜索知识库”这一部分与声明部分一致,但声明的主要能力范围明显大于实际实现,属于描述与行为不一致。未发现额外的高风险未声明能力,但实际功能显著少于声明内容。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较完整的知识库管理与检索能力集合,包括管理知识库、上传文件、向量存储,以及供Agent自动检索参考来源。但实际代码片段只包含搜索功能,而且是通过命令行参数手动调用远程HTTP接口完成的简单检索客户端。代码没有展示任何知识库管理、文件上传、索引构建或向量存储逻辑,也没有体现Agent自动集成触发机制。因此,实际行为只覆盖声明中的一小部分,且主功能范围明显更窄,属于描述与代码行为不一致。

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
83% confidence
Finding

This duplicate finding is still valid because the skill promotes direct command construction for network requests from user-controlled search content. Even if the immediate example is simple, agentized execution with broad Bash(curl:*) access increases the chance of misuse, exfiltration, or malformed requests when prompts are attacker influenced.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

bash
# 基本搜索
curl -X POST http://crawdxiaowu.com:3000/api/knowledge-bases/{kb_id}/search \
  -d "query=搜索关键词&top_k=5"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
83% confidence
Finding

This duplicate finding is still valid because the skill promotes direct command construction for network requests from user-controlled search content. Even if the immediate example is simple, agentized execution with broad Bash(curl:*) access increases the chance of misuse, exfiltration, or malformed requests when prompts are attacker influenced.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

bash
# 基本搜索
curl -X POST http://crawdxiaowu.com:3000/api/knowledge-bases/{kb_id}/search \
  -d "query=搜索关键词&top_k=5"

Lp1

High
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The script performs outbound network access via requests.post(), but this capability is not declared by the finding context and is aimed at a remote host outside the apparent local workbench boundary. In an agent skill that may process user prompts and internal knowledge-base identifiers, undeclared network egress is dangerous because it can silently exfiltrate sensitive queries or metadata to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly encourages uploading private documents and querying them through an external HTTP endpoint, but provides no meaningful warning about confidentiality, third-party processing, or plaintext transmission risks. In this context, users may expose resumes or other sensitive files to a remote service without informed consent, making the data-exposure risk materially higher.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill directs agents to send requests to a remote domain over plain HTTP rather than HTTPS. That exposes knowledge-base identifiers, metadata, queries, and potentially sensitive document-related traffic to interception or tampering by any network adversary on the path.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

列出所有知识库

bash
curl http://crawdxiaowu.com:3000/api/knowledge-bases

创建知识库

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents knowledge-base deletion operations without any warning, confirmation step, or scope validation guidance. An agent following these instructions could irreversibly remove user data due to misunderstanding, prompt injection, or incorrect kb_id selection.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This search example sends user queries and retrieved-knowledge context to an external server over plain HTTP. Because the skill is specifically meant for private documents and semantic retrieval, leaking search terms can reveal highly sensitive personal or proprietary information, and the responses can also be modified in transit.

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

bash
# 基本搜索
curl -X POST http://crawdxiaowu.com:3000/api/knowledge-bases/{kb_id}/search \
  -d "query=搜索关键词&top_k=5"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented file deletion endpoint allows irreversible removal of uploaded content, yet the skill gives no caution or confirmation workflow. In an agent setting, undocumented destructive behavior increases the chance of accidental or manipulated data loss.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes knowledge-base management for an AI Agent workbench, but the code hard-codes requests to http://crawdxiaowu.com:3000, which creates a trust-boundary mismatch. This is risky because users may reasonably expect local or platform-managed KB operations, while their searches and identifiers are actually sent to an external server they may not control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script transmits the user's search query and the knowledge-base identifier to a remote service without clear disclosure at runtime, and it does so over plain HTTP. In a knowledge-base context, queries can contain sensitive business data, secrets, or personal information, so silent transmission materially increases privacy and data-leak risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends the user's raw search query to an external service over plain HTTP, which exposes potentially sensitive user input to interception in transit and to a third-party endpoint without any explicit warning or consent. In a knowledge-base search skill, queries may contain internal business data, credentials, case details, or other confidential text, so silent transmission increases privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill instructions and examples are effectively Chinese-only, which can impose a language constraint on users or operators without any stated opt-in or justification. Under the policy, forcing a specific language without user choice can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language strings throughout the script, including usage text, argument help, and output messages, are fixed in Chinese. This can violate language or locale policy when no user opt-in or documented region-specific justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The docstring and CLI usage/output strings are fixed in Chinese, which imposes a specific language on users without offering a locale choice. This is a natural-language policy concern because the skill does not provide any mechanism for user language preference or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.