Back to skill

Security audit

youmind-article-dispatch

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent multi-platform publishing hub, but it requests overly broad command authority and stores long-lived publishing/profile data with unclear opt-in and retention controls.

Install only if you are comfortable giving this skill a shared YouMind API key, letting it coordinate posts or drafts across connected publishing accounts, and keeping author-profile and learning-history files in ~/.youmind/. Review or narrow the node/npm tool permissions before use, prefer draft mode, and confirm what historical articles or engagement data may be analyzed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:38
Finding

Overly Broad Node.js and npm Command Execution Permissions

Content
View full analysis
Remediation
View remediation

other

Warning
Location
references/profile-learning.md:42
Finding

Profiling and Persistent Behavioral Logging Without an Explicit Collection Opt-In

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (55)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · author-profile.example.yaml (reported line 8)May include surrounding context.

yaml
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/author-profile-spec.md (reported line 13)May include surrounding context.

md
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/author-profile-spec.md (reported line 21)May include surrounding context.

md
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/content-adaptation-matrix.md (reported line 3)May include surrounding context.

md
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/content-adaptation-matrix.md (reported line 100)May include surrounding context.

md
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/content-adaptation-matrix.md (reported line 117)May include surrounding context.

md
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/content-adaptation-matrix.md (reported line 200)May include surrounding context.

md
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/content-brief-format.md (reported line 3)May include surrounding context.

md
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/dispatch-protocol.md (reported line 5)May include surrounding context.

md
# Content Brief Format

The content brief is the standardized data structure passed from the dispatch skill to each platform sub-skill. It ensures consistent context while allowing each platform to independently adapt content.

## Brief Structure

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/platform-registry.md (reported line 23)May include surrounding context.

md
## Hashnode
- **Skill:** `youmind-hashnode-article`
- **API:** GraphQL — `https://gql.hashnode.com`
- **Auth:** Personal Access Token (Bearer header)
- **Rate Limit:** ~30 requests/minute
- **Audience:** Developer bloggers, tech writers, coding enthusiasts
- **Content format:** Markdown

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/platform-registry.md (reported line 157)May include surrounding context.

md
## Hashnode
- **Skill:** `youmind-hashnode-article`
- **API:** GraphQL — `https://gql.hashnode.com`
- **Auth:** Personal Access Token (Bearer header)
- **Rate Limit:** ~30 requests/minute
- **Audience:** Developer bloggers, tech writers, coding enthusiasts
- **Content format:** Markdown

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/profile-learning.md (reported line 224)May include surrounding context.

md
## Privacy

- `author-profile.yaml` and `learning-log.yaml` are local files, not uploaded
- Edit diffs are analyzed locally by the dispatch skill's agent, not sent to any service
- YouMind KB analysis uses the user's own API key to access their own content
- Engagement data, if fetched, comes from the user's connected platform accounts

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · shared/YOUMIND_HOME.md (reported line 34)May include surrounding context.

md
1. `~/.youmind/config/<skill>.yaml`
2. `~/.youmind/config.yaml`

This is now a hard requirement. Article skills do **not** read repo-local `config.yaml` files or `~/.youmind-skill/credentials.yaml` anymore.

## Canonical Files

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · shared/YOUMIND_HOME.md (reported line 46)May include surrounding context.

md
1. `~/.youmind/config/<skill>.yaml`
2. `~/.youmind/config.yaml`

This is now a hard requirement. Article skills do **not** read repo-local `config.yaml` files or `~/.youmind-skill/credentials.yaml` anymore.

## Canonical Files

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README materially understates the skill's capabilities by calling it 'pure orchestration, no publishing logic' while elsewhere claiming research, writing, adaptation, publication, and archiving behavior. This kind of scope mismatch is dangerous because users and downstream policy systems may grant the skill more trust or permissions than intended, enabling unintended external actions and data flows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrase 'Publish everywhere' is very broad for a skill that can cause multi-platform external posting. Broad activation language raises the risk of accidental invocation from natural conversation, leading to unintended content distribution across multiple connected accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The setup text explains centralized credential storage and server-side proxying but does not clearly warn users that their content and account-linked publishing actions will be transmitted to external services. For a dispatch/publishing skill, missing disclosure can lead to uninformed consent and unexpected data sharing or posting under user accounts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The README instructs users to place a reusable API key in a persistent local config file. Persistent bearer tokens increase the blast radius of local compromise, accidental file disclosure, backups, or overbroad file permissions, especially because the key appears to unlock multiple connected publishing services through a single proxy account.

Content

Scanner excerpt · README.md (reported line 24)May include surrounding context.

md
### Step 1: Get YouMind API Key

1. Open [YouMind API Keys](https://youmind.com/settings/api-keys?utm_source=youmind-article-dispatch)
2. Create a key → copy the `sk-ym-xxxx` value
3. Put the key in `~/.youmind/config.yaml` once for all article skills

### Step 2: Connect Platforms in YouMind

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

Copying shared configuration into ~/.youmind/config.yaml reinforces long-term local credential persistence. In the context of a multi-platform dispatch hub, compromise of this one file could enable broad misuse of linked services via the YouMind API.

Content

Scanner excerpt · README.md (reported line 54)May include surrounding context.

bash
cd youmind-article-dispatch
mkdir -p ~/.youmind/config
cp shared/config.example.yaml ~/.youmind/config.yaml

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README introduces web search and article archiving functions that are not reflected in the orchestration-only description. Hidden or undeclared data ingestion and exfiltration paths increase the risk of unauthorized transmission of user content and make it harder for reviewers to assess what the skill can do.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README states that the dispatch skill publishes directly and determines publishing order, contradicting the claim that it has no publishing logic. This discrepancy can mislead users and security controls about whether the skill is capable of performing account-linked external actions, increasing the chance of unintended posting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says this skill is only an orchestration layer for multi-platform dispatch, but the README describes broader behavior including topic selection, writing, internet research, knowledge-base mining, and automatic article archiving. Those capabilities go beyond simple dispatch/orchestration and materially expand what the skill is presented as doing.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README_CN.md (reported line 55)May include surrounding context.

bash
cd youmind-article-dispatch
mkdir -p ~/.youmind/config
cp shared/config.example.yaml ~/.youmind/config.yaml

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README_CN.md (reported line 55)May include surrounding context.

bash
cd youmind-article-dispatch
mkdir -p ~/.youmind/config
cp shared/config.example.yaml ~/.youmind/config.yaml

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The documentation characterizes Dispatch as merely a '分发中枢' that does not itself need platform credentials, yet elsewhere presents it as carrying out full automation steps such as topic research, writing, adaptation, and publishing drafts. This is an intent-level contradiction within the documentation about whether the skill is just an orchestrator or a broader content-production agent.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
shared/config.example.yaml:2