Back to skill

Security audit

Daily Learning

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent daily-learning workflow, but it can persist private context and publish learning output to a shared wiki without clear approval boundaries.

Install only if you want a Chinese-first recurring learning workflow that may write local learning files and submit notes to a configured shared wiki. Restrict who can edit LEARNING-REQUESTS.md, review and redact notes before wiki ingestion, and avoid granting broad conversation or workspace access unless that context use is intentional.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:61
Finding

Untrusted External Learning Requests Can Override the Agent's Intended Plan

Content
View full analysis
/learning/LEARNING-REQUESTS.md` if it exists. This file records learning requests from users, partners, or other agents. Priority rules: - Urgent requests override the original learning plan and must be studied immediately. - Near-term requests are inserted every three days. - Continue the original plan only when there are no external requests. Accept external request injection: users, partners, and other agents may add learning requests to LEARNING-REQUESTS.md, and urgent requests take priority over the original plan. ``` ### Technical Analysis The Skill treats entries in `LEARNING-REQUESTS.md` as trusted instructions rather than untrusted data. In particular, content classified as urgent is allowed to override the existing learning plan immediately. No authentication, provenance verification, authorization check, content validation, or user-confirmation boundary is defined for requests written by other agents. Consequently, any process or agent with write access to the file can influence the scheduled agent's goals. This is an instruction-hijacking weakness because attacker-controlled persistent file content can alter the agent's intended workflow when the Skill is loaded and executed. ### Attack Path 1. An attacker-controlled process or compromised agent obtains write access to `/learning/LEARNING-REQUESTS.md`. 2. It inserts a malicious request under the urgent section. 3. The scheduled daily-learning workflow reads the request file. 4. The Skill prioritizes the injected request over the original learning plan. 5. The agent performs attacker-selected research or other actions associated with the injected topic. 6. The res ...[truncated 556 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:136
Finding

Daily Plan Expansion Requires Overly Broad Access to User Context

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verify-daily-learning.sh:13
Finding

Unvalidated Verification Arguments Allow Regex, Glob, and Path Manipulation

Content
View full analysis
}" AGENT_ID="${2:?Missing agent-id}" WORKSPACE="${3:?Missing workspace path}" WIKI_INBOX="${4:?Missing wiki-inbox-path}" ``` ```bash PATTERN="${DATE}_*_${AGENT_ID}.md" MATCHES=$(find "$WIKI_INBOX" -name "$PATTERN" -type f 2>/dev/null || true) ``` ```bash if grep -q "${DATE}" "$LEARNING_MD" 2>/dev/null; then ``` The date is also inserted into a filesystem path: ```bash NOTE_FILE="${WORKSPACE}/learning/notes/${DATE}.md" ``` ### Technical Analysis The script accepts `DATE` and `AGENT_ID` without validating their expected formats. `DATE` is passed to `grep` as a basic regular expression rather than a fixed string. Regular-expression metacharacters can therefore make unrelated progress records match. Both `DATE` and `AGENT_ID` are interpolated into the pattern supplied to `find -name`. Glob metacharacters in either argument can broaden the match to unrelated wiki files. The date is also used in the note path. Because path separators and traversal components are not rejected, a crafted value could cause the script to inspect a different Markdown file relative to the notes directory. Arguments are quoted, so the displayed code does not provide direct shell command injection. The weakness instead permits manipulation of the script's integrity checks. ### Attack Path 1. An attacker or untrusted caller invokes the verification script with a crafted date or agent identifier. 2. The supplied date contains regular-expression syntax that matches unrelated text in `LEARNING.md`. 3. The date or agent identifier contains glob metacharacters that match a wiki file produced for another date or agent. 4. Alternatively, the date cont ...[truncated 792 chars]
Remediation
View remediation
&2 exit 2 fi ``` 2. Validate the agent identifier against a strict allowlist: ```bash if [[ ! "$AGENT_ID" =~ ^[A-Za-z0-9][A-Za-z0-9_-]*$ ]]; then echo "Invalid agent identifier" >&2 exit 2 fi ``` 3. Use fixed-string matching for the progress check: ```bash if grep -Fq -- "$DATE" "$LEARNING_MD"; then ``` 4. Explicitly reject slashes, traversal components, newlines, glob characters, and control characters in all identifier-like arguments. 5. Canonicalize `WORKSPACE` and `WIKI_INBOX`, then verify that resolved paths remain within approved base directories. 6. Prefer exact filename construction or structured metadata parsing rather than wildcard-based discovery. 7. Verify that matched wiki files contain the expected `submitted` date and `contributor` metadata instead of relying only on filenames. 8. Add regression tests using values such as regex metacharacters, glob characters, traversal sequences, whitespace, and multiline input. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script hard-fails when wiki inbox output is missing, even though the skill metadata says shared knowledge base ingest is optional. In an agent setting, this can coerce unintended writing into a shared repository, causing unnecessary disclosure of locally produced notes or internal context to a broader audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

From the description onward, the skill normalizes writing notes to the local workspace and optionally ingesting them into a shared knowledge base, but it does not disclose modification or dissemination risks. In practice, this can cause agents to persist or share sensitive, inaccurate, or user-specific material without an explicit warning or confirmation step.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly tells the agent to read AGENTS.md and recent conversations to infer future learning topics, which expands scope from a standardized learning workflow into opportunistic inspection of broader user context. This creates unnecessary access to potentially sensitive information and turns transient context into persistent planning data without explicit minimization or consent boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to read AGENTS.md and recent conversations to determine user needs, but it does not warn that these sources may contain private or sensitive information. Because the resulting topics are then added to learning plans, the skill encourages silent reuse of contextual data beyond the immediate interaction.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This section defines a plain-language workflow for mining user conversations and AGENTS.md, inferring needs, and writing those inferences into a persistent learning plan. That is a genuine data-use and retention path: user-provided context is transformed into durable artifacts, which raises privacy and purpose-limitation concerns if done without explicit authorization.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill includes a 'code analysis' mode using read + exec even though the skill is framed as a learning and note-ingestion workflow. This broadens capability into command execution, increasing the chance that unsafe repositories, scripts, or shell commands are run under the cover of a benign learning task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template headings and content scaffold in this section are written in Chinese, which effectively directs users to produce the learning document in a specific language. Under the stated policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction '必须按四层结构组织内容' and the required section labels and prompts are all in Chinese, which imposes a specific language/locale on submissions. No opt-in, alternative language path, or region-specific justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire template and instructions are written as mandatory Chinese-language content, including fixed headings and wording such as '没有就写"暂无"'. There is no indication that the user may choose another language, nor any documented reason that this skill must be Chinese-only, which creates a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script’s natural-language interface is predominantly Chinese in comments, usage text, and runtime messages, which imposes a specific language/locale on users. The policy allows locale constraints only when users are given a choice or the constraint is clearly documented and justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a standardized workflow of studying a topic, writing notes locally, and optionally ingesting them to a shared knowledge base. This script goes further by evaluating note content quality using heuristic checks for evidence, examples, and boundary conditions, which is a semantic expansion beyond verifying completion of the stated workflow outputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.