Back to skill

Security audit

对话读书助理

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local reading-notes skill, but it needs review because its scripts can read or write outside the intended notes folder and can create unsafe HTML exports.

Review before installing. Use it only in a constrained workspace, avoid custom output paths, do not import untrusted note files, and do not open exported HTML from untrusted content until HTML escaping and path confinement are fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/import_notes.py:258
Finding

Path Traversal Allows Reads and Writes Outside the Notes Directory

Content
View full analysis
Remediation
View remediation
Path: root = root.resolve() candidate = (root / filename).resolve() if not candidate.is_relative_to(root): raise ValueError("Path escapes the permitted directory") return candidate ``` 3. Apply confinement independently to: - Source book files. - Imported book files. - Export destinations. - User-configurable base directories. 4. Do not accept arbitrary export destinations by default. Restrict outputs to a dedicated export directory unless the user explicitly authorizes a destination after displaying its resolved path. 5. Use `mkdir(parents=True, exist_ok=True)` only after confirming that the resolved directory is permitted. 6. Use atomic writes: - Create a temporary file inside the destination directory. - Flush and synchronize it. - Replace the destination atomically. 7. Add tests covering traversal payloads, absolute paths, symbolic links, Windows drive paths, and mixed path separators. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/export_notes.py:126
Finding

Stored HTML Injection in Exported Reading Notes

Content
View full analysis
{book_info.get("title", "Reading Notes")}') html_lines.append(f'

{book_info.get("title", "Unknown Book")}

') html_lines.append('
') if book_info.get("author"): html_lines.append(f' Author: {book_info["author"]} | ') if book_info.get("tags"): html_lines.append(f' Tags: {", ".join(book_info["tags"])} | ') html_lines.append(f' Excerpt count: {len(excerpts)}') html_lines.append('
') html_lines.append('

Table of Contents

') html_lines.append('
    ') for chapter in chapters.keys(): html_lines.append( f'
  • {chapter}
  • ' ) html_lines.append('
') for chapter, chapter_excerpts in chapters.items(): html_lines.append( f'

{chapter}

' ) for i, excerpt in enumerate(chapter_excerpts, 1): html_lines.append('
') html_lines.append(f'

Excerpt {i}

') html_lines.append( f'
{excerpt.get("content", "")}
' ) if excerpt.get("tags"): html_lines.append('
') for tag in excerpt["tags"]: html_lines.append(f' {tag}') html_lines.append('
') if include_analysis and excerpt.get("deep_meaning"): html_lines.append('
') html_lines.append(' Deeper meaning:') html_lines.append(f'

{excerpt["deep_meaning"]}

') html_lines.append(' ...[truncated 2442 chars]
Remediation
View remediation
``` 5. Do not permit scripts, frames, forms, external stylesheets, or remote media in exported content unless there is a documented and securely implemented requirement. 6. Add regression tests using payloads in every rendered field, including: - Element-closing payloads. - Quoted attribute payloads. - Event-handler attributes. - Script and iframe elements. - Entity-encoded payloads. 7. Ensure any future PDF renderer is configured to prohibit network access and local-file inclusion when processing generated HTML. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/import_notes.py:34
Finding

Unbounded Import and Export Processing Enables Resource Exhaustion

Content
View full analysis
{excerpt.get('content', '')}") md_lines.append("") if excerpt.get("tags"): md_lines.append(f"**Tags**: {', '.join(excerpt['tags'])}") md_lines.append("") if include_analysis and excerpt.get("deep_meaning"): md_lines.append("**Dee ...[truncated 2290 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/export-templates.md:156
Finding

Documentation Recommends Installing an Unpinned PDF Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个功能较完整的读书辅助/笔记管理工具,但提供的代码片段只负责识别文本中的章节信息,属于较窄的解析子功能。它没有实现笔记记录、搜索、导出、统计、标签管理等核心声明能力,也没有体现“读书”开头记录摘录或“读完了”结束阅读等触发逻辑。虽然章节识别可能是读书工具的辅助组件,但就该代码块本身而言,其主要用途与声明的主要用途存在明显偏差,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

代码片段的核心功能非常明确:它是一个本地笔记导出脚本,而不是完整的“新一代读书辅助工具”。虽然声明中提到“导出阅读记录”,这与代码部分吻合,但声明还包含多项主要能力(标签管理、全文搜索、批量导入导出、阅读统计、摘录记录、结束阅读触发)在该代码中均未体现。按照评估标准,这属于声明的主要用途与实际行为存在显著差异。代码也未表现出额外的敏感或越权行为;问题主要是声明范围远大于实际实现。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

代码的实际核心功能是“批量导入笔记”,尤其是从微信读书和 Kindle 导出文件中解析摘录并保存到本地 JSON 文件。这与声明中的“批量导入”部分一致,但声明将技能描述为更完整的读书辅助工具,包含搜索、导出、统计、标签管理以及结束阅读等能力,而这些在当前代码片段中都没有体现。未发现明显越权或恶意行为;问题主要是声明范围明显大于实际实现,且若按整体描述理解,会对用户造成功能预期偏差,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

代码的实际功能明显比声明窄,核心上只是“搜索笔记”的单一脚本。它会读取本地 JSON 笔记文件并按关键词、标签、章节等条件筛选结果,这与声明中的“搜索笔记内容”部分一致;但声明强调的主要能力还包括智能标签管理、批量导入导出、阅读统计、记录摘录以及结束阅读,这些在提供的代码中均不存在。因此描述未准确代表该代码块的实际行为,属于能力范围上的明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该代码块的实际职责是“阅读统计脚本”,与声明中的“支持多种读书辅助能力”的广泛功能不一致。它不会记录摘录、不会结束阅读、不会搜索笔记内容,也没有批量导入导出能力。虽然声明中包含“阅读统计”,这一点与代码相符,但代码仅覆盖声明功能中的一个子集,且缺少多个核心已声明能力,因此描述不能准确代表该代码块的实际行为。未发现额外越权或隐蔽行为,主要问题是声明明显过宽。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill directs the agent to read and write files under ./reading-notes/, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates a least-privilege failure: if the runtime grants broader filesystem access than intended, the skill may operate with more authority than users or reviewers expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The search trigger phrases like generic '搜索XXX' are broad enough to overlap with ordinary conversation, which can cause unintended skill activation. In a file-accessing skill, accidental activation can expose note contents or cause the agent to search through user data when the user did not intend to invoke this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The export trigger is ambiguous and may match generic requests to export unrelated content. Because export writes files and may include sensitive notes, unintended activation could lead to accidental data disclosure, creation of files in unexpected contexts, or exporting more content than the user meant.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Very generic view-notes triggers like '查看笔记' or '显示笔记' can activate in ordinary dialogue and cause unintended disclosure of stored reading notes. Since the skill manages potentially private excerpts and annotations, loose activation increases the chance of revealing sensitive user data in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file is written entirely in Chinese and presents the chapter-recognition rules as the default behavior, while also prioritizing Chinese chapter formats over other formats. Under the policy, forcing a specific language or locale without user choice or explicit justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该 markdown 文件的标题和正文均以中文固定表述数据结构定义,未见任何允许用户选择语言或说明该技能仅面向中文用户/中文场景的声明。根据规则,强制特定语言而无用户 opt-in 可能构成语言/locale 政策违反。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level docstring says the script supports exporting to Markdown, HTML, and PDF, and the export_notes docstring lists 'pdf' as a format. In practice, the PDF branch explicitly comments that PDF is not actually generated yet and writes HTML instead, which is a direct contradiction between documentation and behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description explicitly says it supports batch import/export and this file's module docstring also claims support for Markdown, HTML, and PDF export. However, when 'pdf' is requested, the implementation only generates HTML and changes the output path from .pdf to .html, so the advertised PDF capability is not implemented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The function writes user-controlled content to a caller-supplied output path without path validation or restriction to a safe export directory. In an agent skill that handles user requests and exports notes, this can enable arbitrary file overwrite in locations accessible to the running process, potentially clobbering application files or exposing sensitive note content to unintended destinations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template hard-codes lang="zh-CN", which enforces a specific language/locale in generated output. There is no indication in the file that users can opt into another locale or that the constraint is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is written entirely in Chinese and presents the skill behavior and examples only in Chinese, including the conversational example. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language or locale choice is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains natural-language strings and docstrings exclusively in Chinese, including the module description and later CLI usage/error text. Under the policy, forcing a specific language without offering user choice or documenting a justified locale restriction is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML output always sets the document language to Simplified Chinese via lang="zh-CN". This is a natural-language/locale constraint embedded in the generated output, and the file does not provide a user option or justification for forcing that locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains natural-language strings that define how users interact with the tool, and they are exclusively in Chinese. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicit and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring and command-line help text are written entirely in Chinese, which can force a specific language experience on users. Under the policy, language constraints should either offer a choice or be clearly documented as justified for a specific locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Multiple user-visible strings, including error messages and argparse help text, are only in Chinese. This creates a fixed locale behavior without presenting an alternative language or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file contains user-facing natural-language text entirely in Chinese, including the module docstring and command-line help strings. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.