Back to skill

Security audit

石油工程油藏论文写作专家团

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed WorkBuddy expert-team installer for petroleum-reservoir paper writing, with sensitive research-data handling that fits its stated purpose but should be used carefully.

Before installing, understand that the script will persistently add this expert team to WorkBuddy and modify marketplace.json. When using it, only provide manuscripts, samples, notes, and links that you are comfortable sharing with the whole expert-team workflow, especially if the work is unpublished, confidential, or contains personal information.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs the agent/user to execute a local Python deployment script that reads environment variables, copies files into the user's WorkBuddy plugin directory, and modifies marketplace.json, but it does not declare any permissions for environment access or file read/write. This creates a trust and consent gap: the skill can cause local filesystem changes and use environment-derived paths without explicit permission metadata, increasing the risk of unauthorized or unexpected installation behavior if the bundled script or assets are modified or malicious.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The agent explicitly requires sending the complete polished manuscript and style notes via SendMessage, which can transmit unpublished research, proprietary data, or personally identifying author information beyond the immediate interaction boundary. In an academic-paper workflow, full-text exfiltration is especially sensitive because manuscripts may contain embargoed results, confidential collaborations, or submission-ready content with significant intellectual-property value.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly directs a team member to read and organize the user's local and cloud notes across multiple platforms, which can expose highly sensitive personal or research data without any explicit consent flow, scope limitation, or warning. In this context, the broad data-access instruction is riskier because it spans several personal knowledge repositories and could lead to over-collection beyond what is necessary for the paper-writing task.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The agent is instructed to send a compiled knowledge-base summary to a third party ('主理人') via SendMessage after processing user notes gathered from multiple platforms, but it does not require user consent, minimization, or any warning that potentially sensitive research notes may be forwarded. In this context, the data may include unpublished research ideas, proprietary notes, annotations, or personal information, so silent onward transmission creates a real confidentiality and privacy risk.

Static analysis

No suspicious patterns detected.