T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:38- Finding
Overly Broad Node.js and npm Command Execution Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent multi-platform publishing hub, but it requests overly broad command authority and stores long-lived publishing/profile data with unclear opt-in and retention controls.
Install only if you are comfortable giving this skill a shared YouMind API key, letting it coordinate posts or drafts across connected publishing accounts, and keeping author-profile and learning-history files in ~/.youmind/. Review or narrow the node/npm tool permissions before use, prefer draft mode, and confirm what historical articles or engagement data may be analyzed.
SKILL.md:38Overly Broad Node.js and npm Command Execution Permissions
references/profile-learning.md:42Profiling and Persistent Behavioral Logging Without an Explicit Collection Opt-In
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Content Brief Format
The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.
## Brief Structure
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Hashnode
- **Skill:** `youmind-hashnode-article`
- **API:** GraphQL — `https://gql.hashnode.com`
- **Auth:** Personal Access Token (Bearer header)
- **Rate Limit:** ~30 requests/minute
- **Audience:** Developer bloggers, tech writers, coding enthusiasts
- **Content format:** Markdown
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
## Hashnode
- **Skill:** `youmind-hashnode-article`
- **API:** GraphQL — `https://gql.hashnode.com`
- **Auth:** Personal Access Token (Bearer header)
- **Rate Limit:** ~30 requests/minute
- **Audience:** Developer bloggers, tech writers, coding enthusiasts
- **Content format:** Markdown
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
## Privacy
- `author-profile.yaml` and `learning-log.yaml` are local files, not uploaded
- Edit diffs are analyzed locally by the dispatch skill's agent, not sent to any service
- YouMind KB analysis uses the user's own API key to access their own content
- Engagement data, if fetched, comes from the user's connected platform accounts
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
1. `~/.youmind/config/<skill>.yaml`
2. `~/.youmind/config.yaml`
This is now a hard requirement. Article skills do **not** read repo-local `config.yaml` files or `~/.youmind-skill/credentials.yaml` anymore.
## Canonical Files
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
1. `~/.youmind/config/<skill>.yaml`
2. `~/.youmind/config.yaml`
This is now a hard requirement. Article skills do **not** read repo-local `config.yaml` files or `~/.youmind-skill/credentials.yaml` anymore.
## Canonical Files
The README materially understates the skill's capabilities by calling it 'pure orchestration, no publishing logic' while elsewhere claiming research, writing, adaptation, publication, and archiving behavior. This kind of scope mismatch is dangerous because users and downstream policy systems may grant the skill more trust or permissions than intended, enabling unintended external actions and data flows.
The trigger phrase 'Publish everywhere' is very broad for a skill that can cause multi-platform external posting. Broad activation language raises the risk of accidental invocation from natural conversation, leading to unintended content distribution across multiple connected accounts.
The setup text explains centralized credential storage and server-side proxying but does not clearly warn users that their content and account-linked publishing actions will be transmitted to external services. For a dispatch/publishing skill, missing disclosure can lead to uninformed consent and unexpected data sharing or posting under user accounts.
The README instructs users to place a reusable API key in a persistent local config file. Persistent bearer tokens increase the blast radius of local compromise, accidental file disclosure, backups, or overbroad file permissions, especially because the key appears to unlock multiple connected publishing services through a single proxy account.
### Step 1: Get YouMind API Key
1. Open [YouMind API Keys](https://youmind.com/settings/api-keys?utm_source=youmind-article-dispatch)
2. Create a key → copy the `sk-ym-xxxx` value
3. Put the key in `~/.youmind/config.yaml` once for all article skills
### Step 2: Connect Platforms in YouMind
Copying shared configuration into ~/.youmind/config.yaml reinforces long-term local credential persistence. In the context of a multi-platform dispatch hub, compromise of this one file could enable broad misuse of linked services via the YouMind API.
cd youmind-article-dispatch
mkdir -p ~/.youmind/config
cp shared/config.example.yaml ~/.youmind/config.yaml
The README introduces web search and article archiving functions that are not reflected in the orchestration-only description. Hidden or undeclared data ingestion and exfiltration paths increase the risk of unauthorized transmission of user content and make it harder for reviewers to assess what the skill can do.
The README states that the dispatch skill publishes directly and determines publishing order, contradicting the claim that it has no publishing logic. This discrepancy can mislead users and security controls about whether the skill is capable of performing account-linked external actions, increasing the chance of unintended posting.
The manifest says this skill is only an orchestration layer for multi-platform dispatch, but the README describes broader behavior including topic selection, writing, internet research, knowledge-base mining, and automatic article archiving. Those capabilities go beyond simple dispatch/orchestration and materially expand what the skill is presented as doing.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
cd youmind-article-dispatch
mkdir -p ~/.youmind/config
cp shared/config.example.yaml ~/.youmind/config.yaml
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
cd youmind-article-dispatch
mkdir -p ~/.youmind/config
cp shared/config.example.yaml ~/.youmind/config.yaml
The documentation characterizes Dispatch as merely a '分发中枢' that does not itself need platform credentials, yet elsewhere presents it as carrying out full automation steps such as topic research, writing, adaptation, and publishing drafts. This is an intent-level contradiction within the documentation about whether the skill is just an orchestrator or a broader content-production agent.
Detected: suspicious.exposed_secret_literal