Back to skill

Security audit

腾讯乐享知识库-私有化版本

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for a private Lexiang knowledge-base integration, but it deserves Review because it can modify enterprise content and transmit local files with weak upload-destination controls.

Install only if you trust the Lexiang MCP endpoint and understand that the token may allow the agent to read and modify private enterprise knowledge-base content. Before uploads or folder sync, verify the exact local paths, avoid folders containing secrets or regulated data, and confirm the destination host for any presigned upload URL. Prefer least-privilege tokens, test in a non-production space first, and use pinned/local dependency environments for the helper scripts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload-files.py:119
Finding

Unvalidated Upload Destination Can Cause Local File Disclosure

Content
View full analysis
This step is not an MCP call. An HTTP PUT request must be executed with curl. curl -X PUT \ -H "Content-Type: " \ --data-binary "@" \ "" ``` `scripts/upload-files.py:119-149`: ```python async def upload_file_async(self, upload_url: str, file_path: str, mime_type: str) -> bool: """Asynchronously upload a file to a presigned URL.""" if not HAS_AIOHTTP: loop = asyncio.get_event_loop() return await loop.run_in_executor( None, self.upload_file_sync, upload_url, file_path, mime_type ) loop = asyncio.get_event_loop() data = await loop.run_in_executor(None, Path(file_path).read_bytes) async with aiohttp.ClientSession() as session: headers = {'Content-Type': mime_type} async with session.put(upload_url, data=data, headers=headers) as response: return response.status in (200, 201) def upload_file_sync(self, upload_url: str, file_path: str, mime_type: str) -> bool: """Synchronously upload a file to a presigned URL.""" with open(file_path, 'rb') as f: data = f.read() headers = {'Content-Type': mime_type} response = requests.put(upload_url, data=data, headers=headers) return response.status_code in (200, 201) ``` The tests also construct sessions with unrestricted plaintext HTTP destinations, demonstrating that host and transport restrictions are not part of the expected behavior: ```python def make_session( name: str = "test.md", upload_url: str = "http://example.com/upload" ) -> Uplo ...[truncated 2984 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/README.md:6
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (52)

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · README.md (reported line 20)May include surrounding context.

text

登录后即可获取:
- **MCP Endpoint**:填入 mcp.json 的 `url` 字段
- **LEXIANG_TOKEN**:访问令牌(格式 `lxmcp_xxx`)

填入 `mcp.json`:

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Claiming a 'full-featured' knowledge-base skill while implementing only a narrower upload/test workflow is materially misleading and can cause improper invocation, overbroad trust, or inappropriate permission grants. In security terms, misrepresentation of capabilities undermines reviewability and can conceal risky behavior or unsupported operations from both users and policy controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Claiming a 'full-featured' knowledge-base skill while implementing only a narrower upload/test workflow is materially misleading and can cause improper invocation, overbroad trust, or inappropriate permission grants. In security terms, misrepresentation of capabilities undermines reviewability and can conceal risky behavior or unsupported operations from both users and policy controls.

Content

No source excerpt is available for this finding.

MCP Config Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The skill explicitly instructs access to MCP configuration and retrieval/use of the MCP endpoint and bearer token for insertion into mcp.json. Accessing and handling MCP config and secrets is highly sensitive because it enables the agent workflow to read, modify, or operationalize stored credentials that grant access to a private enterprise knowledge base.

Content

Scanner excerpt · references/setup.md (reported line 24)May include surrounding context.

md
> 例如:用户的乐享地址是 `https://lexiang.mycompany.com`,则配置页为 `https://lexiang.mycompany.com/ai/claw`

登录后,用户可在页面上看到:
- **MCP Endpoint**:MCP 服务地址(用于 mcp.json 的 `url` 字段)
- **LEXIANG_TOKEN**:访问令牌(格式 `lxmcp_xxx`)

### Step 2: 确定 mcp.json 路径

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Deriving the private deployment domain from the current mcp.json url requires inspecting local MCP configuration, which is sensitive metadata. Even if the purpose is benign, reading config to extract internal hostnames can disclose enterprise infrastructure details and normalize agent access to credential-bearing configuration files.

Content

Scanner excerpt · references/setup.md (reported line 114)May include surrounding context.

{乐享私有化域名}/ai/claw

text

> `{乐享私有化域名}` 从当前 mcp.json 的 `url` 字段中提取主机部分。

---

MCP Config Access

High
Category
Agent Snooping
Confidence
93% confidence
Finding

This duplicate finding points to the same behavior: silent reconnection and confirmation of mcp.json correctness using stored configuration. The risk is not malicious intent but unsafe handling expectations around config files that may contain tokens and internal service details.

Content

Scanner excerpt · references/setup.md (reported line 122)May include surrounding context.

md
1. **先自动重连一次**:使用 mcp.json 中已有的配置静默重连
2. **重连成功**:继续执行未完成的任务
3. **重连失败**:引导用户确认 mcp.json 配置是否正确,或重新访问 `/ai/claw` 页面检查 token 状态

---

MCP Config Access

High
Category
Agent Snooping
Confidence
93% confidence
Finding

This duplicate finding points to the same behavior: silent reconnection and confirmation of mcp.json correctness using stored configuration. The risk is not malicious intent but unsafe handling expectations around config files that may contain tokens and internal service details.

Content

Scanner excerpt · references/setup.md (reported line 122)May include surrounding context.

md
1. **先自动重连一次**:使用 mcp.json 中已有的配置静默重连
2. **重连成功**:继续执行未完成的任务
3. **重连失败**:引导用户确认 mcp.json 配置是否正确,或重新访问 `/ai/claw` 页面检查 token 状态

---

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · references/setup.md (reported line 130)May include surrounding context.

md
| 问题 | 解决方案 |
|------|---------|
| 连接无响应 | 确认 mcp.json 中 `url` 填写的是 MCP Endpoint(非乐享访问域名) |
| 401 未授权 | token 过期,参见上方「Token 已过期」处理步骤 |
| 参数报错 | 执行 `get_tool_schema(tool_name="xxx")` 获取最新参数定义 |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises powerful data-changing capabilities including document creation, block editing, file upload, and external import, but does not clearly warn users that these actions can alter or expose enterprise knowledge-base data. In a private deployment context, lack of explicit risk disclosure makes accidental destructive or privacy-impacting use more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The routing table uses broad trigger phrases such as common search/read requests, which can cause the skill to activate in situations where the user did not intend to operate on the private knowledge base. Because this skill supports read, write, edit, and file operations against enterprise data, accidental invocation increases the chance of unintended data access or modification.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares broad operational behavior around MCP, file, network, and shell-like capabilities but provides no explicit tool scoping or allowed-tools restrictions. In an agent environment, missing scope boundaries increases the chance the skill can invoke higher-risk capabilities than intended, especially when combined with broad triggers and write-oriented workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Overly broad trigger phrases like generic mentions of 'knowledge base' or related terms can cause unintended invocation in unrelated contexts. When a skill can write, search, or interact with external systems, accidental activation may leak context, perform unauthorized actions, or steer the agent away from safer/default handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Ambiguous invocation guidance that activates on broad mentions without exclusion rules increases the attack surface for prompt-trigger abuse and accidental routing. In this skill, that risk is amplified because the instructions cover sensitive operations like writing, editing, file handling, and credential-dependent KB access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly describes a delete_text operation that can irreversibly remove content from an existing knowledge-base document, but it does not warn about data loss, confirmation requirements, or recovery limitations. In a skill whose purpose is to search, write, and edit private knowledge-base content, omission of safeguards increases the chance that an agent or user will perform destructive edits unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document exposes destructive deletion capabilities (block_delete_block_children and block_delete_block) but does not explicitly warn that these operations can permanently remove content and descendants. In an agent skill, omission of a strong confirmation/data-loss warning increases the chance that an LLM or user workflow invokes deletion without understanding scope or irreversibility, especially because one operation deletes the target block together with all descendants.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all headings, instructions, examples, and FAQ content exclusively in Chinese, with no indication that the user can opt into another language. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The file mandates an external HTTP PUT using curl to send file contents to an upload_url, which is a direct external data transmission path. Because this step is outside MCP, it may bypass centralized permission checks, logging, and safety controls, increasing the risk of unreviewed transfer of sensitive data if the skill is invoked on unintended local files or maliciously influenced destinations.

Content

Scanner excerpt · references/files.md (reported line 65)May include surrounding context.

}

text

### Step 2: HTTP PUT 上传文件内容(curl 命令,非 MCP)

> ⚠️ **这一步不是 MCP 调用,必须用 curl 命令执行 HTTP PUT 请求。**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs the agent/user to upload arbitrary local file contents via a raw curl PUT to a pre-signed URL, but it provides no privacy warning, confirmation gate, or restriction on what local paths may be transmitted. In an agent context, this can normalize exfiltration of sensitive local files outside the MCP trust boundary, especially because the transfer occurs via non-MCP HTTP and may bypass expected auditing controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs users to synchronize a local folder to a remote knowledge base but does not clearly warn that local files, metadata, and directory structure will be transmitted off the machine. In a knowledge-base integration skill, this omission is more dangerous because users may run it against project docs or mixed-content folders containing proprietary or sensitive material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented HTTP PUT step sends file contents to a pre-signed URL over the network, but the text does not warn users that this transfers raw file data to remote storage. In this skill context, that omission can lead to accidental disclosure because users may assume the MCP call is only metadata registration rather than full content upload.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document title and core instructions are entirely in Chinese, including the routing guidance for how the AI should use the reference index. This imposes a specific language/locale on users or downstream agents without indicating any opt-in, alternative language support, or region-specific justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/markdown-import.md (reported line 40)May include surrounding context.

Step 2: HTTP PUT 上传

bash
curl -X PUT -H "Content-Type: text/markdown" \
  --data-binary @document.md \
  "$upload_url"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly describes converting Markdown into Block structures and writing them into documents, but it provides no warning, confirmation step, or usage guidance about modifying persistent document data. In an agent setting, this increases the risk of unintended or over-broad writes, especially if user-supplied Markdown or the wrong entry_id is passed through automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all user-facing instructional content are written exclusively in Chinese, which indicates a fixed language expectation. There is no note that the skill supports multiple languages, follows the user's language preference, or is limited to a justified Chinese-only context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger condition "MCP 连接失败或返回 401 错误时" is broad and does not clearly limit when this specific setup skill should activate versus other troubleshooting or authentication skills. Without narrower scope or exclusion conditions, ordinary runtime failures could unintentionally invoke the setup flow.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/test_upload_files.py:28