Back to skill

Security audit

knowledge-workflow

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-language knowledge-workflow helper that reads notes from a configured local knowledge base and writes generated markdown outputs locally, with no evidence of hidden execution, exfiltration, or persistence beyond its stated file outputs.

Install only if you are comfortable with a Chinese-language, currently partial workflow that reads markdown notes from your configured knowledge-base directory and saves derived markdown files there. Configure base_path narrowly, review outputs before sharing them, and do not expect full Feishu/WeChat/URL collection or real LLM synthesis from the included artifacts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill claims a much broader workflow and external-source support than the code actually provides, while the implementation apparently only handles local Markdown and template-like generation. This mismatch is dangerous because users may trust the skill with sensitive knowledge-management tasks under false assumptions about functionality, provenance handling, and AI processing, which can lead to misuse, silent data loss, or insecure operational decisions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documentation declares no tool scope or permissions, yet the implementation reportedly reads and writes local files. This creates an authorization/transparency gap: users and hosting platforms cannot accurately assess what the skill can access, increasing the risk of unintended file access or overwrite if the skill is invoked in a broader environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's natural-language instructions, docstrings, and generated content templates are written entirely in Chinese, which strongly implies the skill will operate and produce output only in that language. There is no indication that users can choose another language or opt in to this locale constraint.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring says each evolve type has '真实的 AI 生成逻辑(基于 LLM prompt)'. In implementation, all _generate_* helpers simply return canned placeholder phrases like '...是...' and there is no model invocation, API client, or external generation path anywhere in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The code recursively searches the entire configured base path for a matching note ID and reads the first matching markdown file, with no visible user-facing notice or scope minimization. In this skill context, that broad local-file access can expose sensitive note content unexpectedly and makes the function more dangerous because knowledge bases commonly contain private personal or business material.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest promises a '完整的知识管理工作流' with 5 germination types as meaningful outputs. In this file, the generated markdown is largely scaffolding populated by generic placeholder fragments, so the actual behavior is closer to document templating than producing the claimed high-value evolved content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function persists generated content to disk automatically under the configured knowledge base path without any explicit confirmation, dry-run mode, or disclosure in this code path. In a knowledge-workflow skill that processes potentially sensitive notes, silent writes can create unintended local data retention, duplicate sensitive content, and privacy/compliance issues if users did not expect derived artifacts to be stored.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The comments assert '这些方法在实际使用时会调用 LLM API 生成内容', which implies real generated outputs. However, every helper below returns deterministic formatted strings with no API integration, so the comments overstate the implemented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description is presented entirely in Chinese, with no indication that users can choose another language or that the skill is intentionally limited to a Chinese-speaking locale. Under the policy rule for language or locale constraints, this can be treated as an implicit language restriction without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.