Back to skill

Security audit

Lovefromio Getnote

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent cloud note-taking skill, but it needs review because it can access private notes, save shared content externally, and store long-lived credentials with weak default scoping.

Install only if you are comfortable giving the skill access to your Get笔记 account and sending saved links, images, and note contents to that service. Configure GETNOTE_OWNER_ID before using it in any shared chat or workspace, avoid broad auto-save behavior for sensitive links or images, and treat OAuth/API key output as secret material that should not appear in chat logs or command transcripts.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:111
Finding

Caller identity verification is optional for private note operations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload_image.py:84
Finding

API-controlled image upload destination is used without validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/oauth_poll.py:61
Finding

OAuth API key is emitted through captured process output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/upload_image.py:23
Finding

Runtime dependency installation is unpinned and not integrity-verified

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (21)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest presents a normal note-management capability, but the document also directs the agent to obtain API credentials, poll for tokens, and write secrets into local configuration. That hidden operational behavior is materially different from the user-facing description, making consent and security review harder and increasing the risk of credential handling abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatic activation on any URL or image is risky because many conversations naturally contain links or images that the user did not intend to upload to a third-party notes service. In this skill's context, such activation can directly expose private content to an external API and create persistent records without clear consent.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are very broad, covering generic terms like '笔记', '保存', and '搜一下', which can cause the skill to activate during ordinary conversation. Because activation can lead to external data transmission or OAuth initiation, overly permissive triggering creates a real risk of unintended privacy-impacting actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The entire skill documentation and all example interactions are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. This can constitute a language/locale policy issue because the skill appears to assume one language by default without opt-in or justification.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 109)May include surrounding context.

方式三:手动安装

bash
mkdir -p ~/.openclaw/workspace/skills/getnote
cd ~/.openclaw/workspace/skills/getnote
curl -sL https://raw.githubusercontent.com/iswalle/getnote-openclaw/main/SKILL.md -o SKILL.md
curl -sL https://raw.githubusercontent.com/iswalle/getnote-openclaw/main/package.json -o package.json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises very broad trigger phrases such as general note/save/search language and even automatic activation on any URL or image. In a chat environment, this can cause unintended invocation on unrelated user content, leading to accidental capture, storage, or retrieval of sensitive data without clear user confirmation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares capabilities that require environment access, outbound network access, and shell/process execution, but it does not explicitly scope or constrain those tools. In practice this increases the blast radius of prompt-induced misuse, especially because the same document also instructs the agent to run local scripts and handle credentials/OAuth automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises saving links, images, audio, and text, but it does not prominently warn that this content will be sent to an external service for storage, OCR, transcription, summarization, and retrieval. For a personal notes tool handling potentially sensitive material, missing disclosure undermines informed consent and increases privacy risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to automatically initiate OAuth when credentials are absent and continue the user's original request after authorization. This can cause unexpected authentication flows and persistence of access without an adequately explicit consent checkpoint, which is risky for a privacy-sensitive notes service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to execute a local Python script and manage background polling sessions during OAuth. Introducing arbitrary local script execution for a note-taking integration is a dangerous expansion of privilege because it creates an execution path on the host that can be repurposed or abused beyond simple API access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly instructs writing obtained API credentials to ~/.openclaw/openclaw.json. Storing secrets via an agent-directed local file write is sensitive behavior that exceeds the visible note-management scope and can lead to credential exposure, persistence without oversight, or modification of unrelated local configuration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The package description contains broad, natural-language trigger phrases like ‘存一下’ and ‘记到笔记’, and the broader skill metadata also indicates automatic activation on arbitrary URLs, images, and common words such as ‘保存’ or ‘收藏’. This can cause unintended invocation during ordinary conversation, resulting in accidental capture, storage, or transmission of user content to the notes service without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language description is entirely in Chinese and presents the interaction examples only in Chinese, which can imply a fixed language expectation. There is no indication that the skill supports user language choice or that the Chinese-only behavior is a documented, justified regional constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-details.md (reported line 221)May include surrounding context.

bash
# 1. 获取上传凭证
curl 'https://openapi.biji.com/open/api/v1/resource/image/upload_token?mime_type=jpg&count=1' \
  -H 'X-Client-ID: {client_id}' \
  -H 'Authorization: {api_key}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language documentation entirely in Chinese, and later emits Chinese-only user-facing status and error messages. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and there is no indication here that the locale restriction is optional or justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script takes an arbitrary local image path and uploads the file contents to a remote service, but the interface and help text do not clearly warn the operator that local data will leave the machine and be stored/processed by third-party infrastructure. In a note-taking skill context, users may reasonably expect cloud sync, but local file upload still creates privacy and data handling risk if sensitive images are provided unintentionally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/upload_image.py (reported line 177)May include surrounding context.

python
print(f"访问 URL: {image_url}")
        print()
        print("💡 创建图片笔记:")
        print(f'   curl -X POST "https://openapi.biji.com/open/api/v1/resource/note/save?task_id=..."')
        print(f'     -H "Authorization: $GETNOTE_API_KEY"')
        print(f'     -H "Content-Type: application/json"')
        print(f'     -d \'{{"type":"img_text","image_urls":["{image_url}"]}}\'')

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file presents all headings, field descriptions, and usage guidance in Chinese, which effectively enforces a single language for readers. Under the stated policy, natural-language materials should not force a specific language unless the locale constraint is explicitly documented or the user is given a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file includes concrete curl examples that use Authorization: {api_key}, X-Client-ID, and OSS upload signing fields such as signature, policy, and OSSAccessKeyId. While the examples are legitimate API documentation, the description does not warn readers that these values are sensitive credentials/tokens that should not be exposed, logged, or shared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script's docstring, CLI descriptions, and runtime messages are presented only in Chinese, which imposes a language choice on users without opt-in. The file does not document that this skill is intentionally restricted to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.