Back to skill

Security audit

Context Manager

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it needs review because it stores sensitive personal context locally and has file-path handling that can write outside intended folders.

Review before installing. Use it only with a dedicated local context directory, avoid importing secrets or third-party private chats/documents without permission, and do not run tagging or bundled knowledge-workflow helpers on untrusted IDs or indexes until path validation and privacy/retention controls are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
modules/tagger.py:104
Finding

Path Traversal in Context Tagging Enables Unauthorized JSON Modification

Content
View full analysis
`. Exploitation requires the selected source to exist and contain valid JSON. The method then adds `tags` and `keywords` fields and writes the resulting document to the traversal-selected destination. ### Attack Path 1. The attacker identifies a readable JSON file and a writable destination accessible to the process. 2. The attacker constructs a `context_id` containing sufficient `../` components to escape the configured knowledge-base directories. 3. The attacker invokes the CLI `tag` command or calls `MeaningTagger.tag()` directly. 4. `_update_context()` resolves the source p ...[truncated 994 chars]
Remediation
View remediation
Path: parent = parent.resolve() candidate = (parent / filename).resolve() if not candidate.is_relative_to(parent): raise ValueError("Path escapes the permitted directory") return candidate ``` 3. Reject absolute paths, path separators, `.` and `..` components, null bytes, and unexpected extensions. 4. Generate context identifiers internally rather than accepting arbitrary identifiers where possible. 5. Account for symlink escapes by validating canonical resolved paths immediately before access. 6. Avoid creating arbitrary parent directories from user-derived paths. 7. Add tests covering absolute paths, nested traversal, mixed separators, encoded traversal, and symlink-based escapes. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
subfunctions/store.py:53
Finding

Caller-Controlled Note ID Enables Arbitrary Markdown File Write

Content
View full analysis
Dict[str, Any]: """ Execute storage operation. Args: note_id: Note ID content: Tagged note content tags: Tag information Returns: Storage result """ # Determine storage path from theme tag theme = tags["themes"][0] if tags["themes"] else "Other" folder = self._theme_to_folder(theme) storage_path = self.base_path / folder storage_path.mkdir(parents=True, exist_ok=True) # Extract title title = self._extract_title(content) # Move note into the corresponding folder note_path = storage_path / f"{note_id}.md" note_path.write_text(content) ``` ### Technical Analysis `StoreFunction.execute()` accepts `note_id` from its caller and directly embeds it into a filesystem path. No allowlist, normalization, or containment check is performed before `write_text()` creates or overwrites the target file. A note ID containing traversal components can cause the resolved path to leave `storage_path`. Because the method writes caller-controlled `content`, this is an arbitrary-content write primitive for files whose final name ends in `.md`. The theme-to-folder mapping limits the initial storage directory but does not mitigate traversal inside `note_id`. ### Attack Path 1. The attacker obtains access to a workflow or integration that calls `StoreFunction.execute()`. 2. The attacker supplies a `note_id` containing `../` path components. 3. The attacker places the desired file contents in the `content` parameter. 4. The path expression resolves outside the intended theme folder and potentially outside the knowledge base. 5. `write_text()` creates or overwrites the selected `.md` file. 6. The escaped path is subsequently stor ...[truncated 823 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
subfunctions/wiki_lint.py:246
Finding

Poisoned Knowledge-Base Index Enables Arbitrary Existing-File Modification

Content
View full analysis
💡 提示:此笔记暂无连接,建议添加相关笔记链接。\n" note_path.write_text(content) ``` ### Technical Analysis `WikiLint` loads note metadata from the local `_index.json` file and treats each stored `path` as trusted. `_fix_orphan_note()` creates a `Path` directly from that value and modifies the referenced file without checking whether it is located beneath `kb_path`. The value may be absolute or relative to the process working directory. A tampered, imported, or otherwise poisoned index can consequently reference any readable and writable text file available to the process. `run_lint()` enables automatic repair by default through `auto_fix=True`. An unsafe index can therefore trigger mutation without a separate per-file confirmation. The method appends Markdown text and rewrites the entire target file. ### Attack Path 1. The attacker modifies, replaces, or supplies a knowledge-base `_index.json`. 2. The attacker inserts a note entry whose `path` points to a target file outside the knowledge base. 3. The entry is structured as an orphan note so that lint classifies it as automatically repairable. 4. The user or an automated workflow invokes `run_lint()` without disabling its default auto-fix behavior. 5. `_fix_orphan_note()` reads the external ta ...[truncated 894 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (101)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a personal context/thought-tree assistant, but its description also instructs collection of content from private sources like WeChat, Feishu, web pages, and manual notes, and implies unified import into a local context store. When a skill understates that it ingests and writes potentially sensitive personal data, users may invoke it without understanding the privacy and persistence implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill is presented as a personal context/thought-tree assistant, but its description also instructs collection of content from private sources like WeChat, Feishu, web pages, and manual notes, and implies unified import into a local context store. When a skill understates that it ingests and writes potentially sensitive personal data, users may invoke it without understanding the privacy and persistence implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill is presented as a personal context/thought-tree assistant, but its description also instructs collection of content from private sources like WeChat, Feishu, web pages, and manual notes, and implies unified import into a local context store. When a skill understates that it ingests and writes potentially sensitive personal data, users may invoke it without understanding the privacy and persistence implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a personal context/thought-tree assistant, but its description also instructs collection of content from private sources like WeChat, Feishu, web pages, and manual notes, and implies unified import into a local context store. When a skill understates that it ingests and writes potentially sensitive personal data, users may invoke it without understanding the privacy and persistence implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill is presented as a personal context/thought-tree assistant, but its description also instructs collection of content from private sources like WeChat, Feishu, web pages, and manual notes, and implies unified import into a local context store. When a skill understates that it ingests and writes potentially sensitive personal data, users may invoke it without understanding the privacy and persistence implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a personal context/thought-tree assistant, but its description also instructs collection of content from private sources like WeChat, Feishu, web pages, and manual notes, and implies unified import into a local context store. When a skill understates that it ingests and writes potentially sensitive personal data, users may invoke it without understanding the privacy and persistence implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages collection from highly sensitive sources such as chat logs, Feishu documents, personal cognition logs, and web articles, but provides no prominent warning about privacy, consent, retention, or downstream exposure. In the context of a personal-memory and decision-background tool, that omission is especially dangerous because users may paste intimate, regulated, or third-party data into a system without understanding the sensitivity or handling boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This path stores raw 'inner cognition' content together with derived emotion analysis and tags to disk, creating a highly sensitive local record of the user's thoughts and inferred mental state. Because the skill is explicitly designed to manage personal context and 'inner cognition,' the collected data is unusually intimate, making undisclosed persistence especially dangerous from a privacy and profiling perspective.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · subfunctions/rule_miner.py (reported line 133)May include surrounding context.

python
self._save_observations()
        
        return rule
    
    def _generate_title(self, category: str) -> str:
        """生成规则标题"""

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · subfunctions/rule_miner.py (reported line 213)May include surrounding context.

python
if lesson:
                    rule = self._create_rule(observations[0]["category"], observations, lesson)
                    rules.append(rule)
        return rules
    
    def get_active_rules(self) -> List[dict]:
        """获取活跃规则"""

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file documents and validates a broad knowledge-workflow pipeline that collects external content, stores files locally, evolves content, and generates article outputs, while the manifest presents the skill as personal context management. This capability mismatch is dangerous because reviewers and users may grant the skill access or trust under a narrower description, while the actual behavior expands data ingestion, transformation, and publication scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes and operationalizes a different skill ('knowledge-workflow') than the declared skill metadata ('context-manager'). This scope mismatch can mislead users and orchestrators about what the skill actually does, causing unexpected collection, transformation, storage, and publication of user data beyond the declared personal-context-management purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README encourages processing Feishu documents, meeting notes, URLs, and exported reading content, and also describes storage, but provides no warning that these inputs may contain sensitive personal, corporate, or confidential information. This omission is dangerous because users may submit protected data without understanding retention, destination, or sharing implications, especially given the documented store/evolve/output pipeline.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The documented auto_execute=True enables an end-to-end pipeline to run without explicit confirmation between collect, tag, store, evolve, and output steps. In a context-management skill handling potentially sensitive documents, this increases the chance of unreviewed persistence, transformation, and generation of derived artifacts from user data.

Content

Scanner excerpt · README.md (reported line 86)May include surrounding context.

md
result = kw.run(
    source_type="feishu",
    content="PFAvdKEILouK29xCgNuc5b1bnnK",
    auto_execute=True
)

# 分步调用

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documented scenarios expand from personal context management into team knowledge-base ingestion and publishable content generation, which materially increases data handling and exfiltration risk. In this skill context, capabilities that transform private notes or meeting records into shared artifacts are more dangerous because users may invoke a seemingly personal tool without realizing it can create externally consumable outputs.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger language is broad, using many generic concepts such as 'manage my context,' 'organize important information,' 'decision background,' and 'memory external brain.' Overbroad activation can cause the skill to engage on unrelated conversations and solicit or process sensitive personal information when the user did not intend to invoke a high-sensitivity context collection workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The review feature explicitly recommends deleting redundant content quarterly, yet the description does not warn about permanence, backup, or recovery options. In a personal-context system that may store valuable memories, decisions, and cognition logs, silent destructive operations can lead to irreversible loss of important or sensitive records.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger guidance lacks explicit constraints, disambiguation rules, and non-trigger examples, so activation boundaries are unclear. Because this skill manages personal context and references integrations like WeChat/Feishu APIs, accidental invocation could expose or process sensitive memory, decision history, or cognitive-map data beyond the user's intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger guidance lacks explicit constraints, disambiguation rules, and non-trigger examples, so activation boundaries are unclear. Because this skill manages personal context and references integrations like WeChat/Feishu APIs, accidental invocation could expose or process sensitive memory, decision history, or cognitive-map data beyond the user's intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description includes many broad trigger phrases and generic keyword-based activation cues such as '管理我的上下文', '整理重要信息', and '决策背景', which can match normal conversation outside the user's intent to invoke this skill. In a context-management skill, accidental activation is more dangerous because users may disclose sensitive personal reflections, memories, or decision context to the wrong capability without explicit consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file-level description and all user-facing CLI messages are written only in Chinese, which imposes a specific language on users without any opt-in or alternative locale handling. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames this skill as a personal context manager and thought-tree builder. In code, the review API explicitly supports operations such as delete_redundant, which indicates deletion of stored material rather than merely managing or recording context, expanding behavior into destructive content pruning not clearly stated in the manifest description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains module and class descriptions entirely in Chinese, and the skill logic is built around Chinese-language keywords and outputs. Because the file provides no indication that Chinese is optional or that the skill is intentionally region-specific, it appears to impose a specific language/locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file's natural-language descriptions and generated labels/reasons are written exclusively in Chinese, including user-visible values like bridge types and reasons. This creates a locale/language constraint without any indication of user choice or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.