Back to skill

Security audit

youmind-ghost-article

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for Ghost publishing, but it needs Review because it can change or delete Ghost posts and has code paths that can expose local files or API keys under unsafe inputs or configuration.

Review carefully before installing. Only use trusted Markdown and image inputs, keep youmind.base_url on the documented YouMind endpoint unless doing controlled local development, protect ~/.youmind/config.yaml with owner-only permissions, and require a human check before publishing, unpublishing, or deleting any Ghost content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
toolkit/src/content-adapter.ts:211
Finding

Arbitrary Local File Disclosure Through Feature Image Metadata

Content
View full analysis
{ const resolvedPath = resolve(filePath); if (!existsSync(resolvedPath)) { throw new Error(`Feature image file not found: ${resolvedPath}`); } const filename = basename(resolvedPath); const content = readFileSync(resolvedPath); const response = await postJson>( '/ghost/uploadImage', { filename, contentBase64: content.toString('base64'), contentType: detectMimeType(filename), }, ``` ### Technical Analysis A Markdown document can specify `featureImage`, `image`, or `ghost.featureImage` in YAML frontmatter. Non-HTTP values are treated as local file paths. The publishing pipeline resolves those paths relative to the Markdown file but does not ensure that the resulting path remain ...[truncated 1800 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
toolkit/src/config.ts:78
Finding

Shared API Key Can Be Sent to an Arbitrary Configured Host

Content
View full analysis
; } { const raw = loadLayeredConfig(); const youmind = isPlainObject(raw.youmind) ? raw.youmind : {}; const imageYouMind = getImageYouMindConfig(raw); const apiKey = (typeof youmind.api_key === 'string' && youmind.api_key) || (typeof imageYouMind.api_key === 'string' && imageYouMind.api_key) || ''; const configuredBaseUrl = typeof youmind.base_url === 'string' ? normalizeBaseUrl(youmind.base_url) : ''; return { raw, apiKey, baseUrl: configuredBaseUrl || DEFAULT_YOUMIND_OPENAPI_BASE_URL, }; } ``` ```ts // toolkit/src/youmind-api.ts:51-59 const resp = await fetch(`${cfg.baseUrl}${endpoint}`, { method: 'POST', headers: { 'Content-Type': 'application/json', 'x-api-key': cfg.apiKey, }, body: JSON.stringify(body), signal: AbortSignal.timeout(endpoint.includes('Chat') || endpoint.includes('Message') ? 120_000 : 15_000), }); ``` ```ts // toolkit/src/ghost-api.ts:107-116 const response = await fetch(`${cfg.baseUrl}${endpoint}`, { method: 'POST', headers: { 'Content-Type': 'application/json', 'x-api-key': cfg.apiKey, 'x-use-camel-case': 'true', }, body: JSON.stringify(body), signal: AbortSignal.timeout ...[truncated 2229 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
toolkit/package.json:19
Finding

Mandatory Installation Uses Unpinned Dependencies Without a Lockfile

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
toolkit/src/content-adapter.ts:36
Finding

Unsanitized Raw HTML Is Written to Local Previews and Forwarded for Publication

Content
View full analysis
${title} body { max-width: 740px; margin: 40px auto; padding: 0 20px; font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, "Noto Sans", Ubuntu, "Droid Sans", "Helvetica Neue", sans-serif; font-size: 1.8rem; line-height: 1.7; color: #15171a; background: #fff; } h1 { font-size: 3.2rem; line-height: 1.2; margin-bottom: 0.5em; } h2 { font-size: 2.4rem; margin-top: 1.5em; } h3 { font-size: 2rem; margin-top: 1.2em; } code { background: #f0f0f0; padding: 2px 6px; border-radius: 3px; font-size: 0.9em; } pre { background: #f0f0f0; padding: 20px; border-radius: 5px; overflow-x: auto; } pre code { background: none; padding: 0; } blockquote { border-left: 3px sol ...[truncated 2861 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:103
Finding

Shared Credential File Is Created Without Explicit Owner-Only Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (84)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill documentation exposes capabilities beyond the top-level description, including management actions on existing Ghost posts. Underspecified remote-content operations are security-relevant because users may invoke a writing tool without realizing it can alter publication state or potentially delete content, increasing the risk of unintended destructive actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill documentation exposes capabilities beyond the top-level description, including management actions on existing Ghost posts. Underspecified remote-content operations are security-relevant because users may invoke a writing tool without realizing it can alter publication state or potentially delete content, increasing the risk of unintended destructive actions.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · shared/YOUMIND_HOME.md (reported line 34)May include surrounding context.

md
1. `~/.youmind/config/<skill>.yaml`
2. `~/.youmind/config.yaml`

This is now a hard requirement. Article skills do **not** read repo-local `config.yaml` files or `~/.youmind-skill/credentials.yaml` anymore.

## Canonical Files

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · shared/YOUMIND_HOME.md (reported line 46)May include surrounding context.

md
1. `~/.youmind/config/<skill>.yaml`
2. `~/.youmind/config.yaml`

This is now a hard requirement. Article skills do **not** read repo-local `config.yaml` files or `~/.youmind-skill/credentials.yaml` anymore.

## Canonical Files

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The delete command permanently removes Ghost posts by ID, which is materially outside the stated article-writing/publishing workflow and grants destructive capability to the skill. The presence of a simple '--yes' flag is only a usability confirmation, not a security control, so an agent or attacker with access to the CLI can irreversibly destroy content.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
96% confidence
Finding

This module performs outbound network requests with fetch to a remote YouMind/Ghost API, but the finding indicates that capability is not declared in the skill's permissions. Undeclared network access is dangerous because it can bypass user/operator expectations and policy controls, especially in a publishing skill that transmits article content and metadata off-host.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
79% confidence
Finding

The README instructs users to store a long-lived YouMind API key in ~/.youmind/config.yaml, creating local session persistence in plaintext. If the workstation is compromised, misconfigured, shared, or backed up insecurely, the token could be recovered and used to access the user's YouMind-connected Ghost publishing capabilities and related API actions.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

1. Install dependencies

cd toolkit && npm install && npm run build && cd ..

2. Create shared config (recommended)

mkdir -p ~/.youmind/config cp shared/config.example.yaml ~/.youmind/config.yaml

text

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 44)May include surrounding context.

md
### Publishing prerequisite

Before publishing, connect your Ghost account inside YouMind. This skill no longer reads `ghost.site_url` or `ghost.admin_api_key` locally and should never ask the user to paste Ghost admin credentials into this repo.

### Get a YouMind API Key

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README_CN.md (reported line 27)May include surrounding context.

cd toolkit && npm install && npm run build && cd ..

2. 创建共享配置

mkdir -p ~/.youmind/config cp shared/config.example.yaml ~/.youmind/config.yaml

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README_CN.md (reported line 27)May include surrounding context.

cd toolkit && npm install && npm run build && cd ..

2. 创建共享配置

mkdir -p ~/.youmind/config cp shared/config.example.yaml ~/.youmind/config.yaml

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README documents direct publication of content and state-changing operations without an explicit warning that these commands can affect a live Ghost site. In an agent-skill context, this increases the chance of accidental public posting by users or automation, especially because the skill is designed for one-click publishing through a connected account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README exposes an unpublish operation for existing posts without a clear warning that it can remove live content from the public site. In a publishing skill with authenticated access to a connected Ghost account, this can lead to accidental service/content disruption and editorial impact if invoked by a user or agent without understanding the consequences.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Several triggers such as write ghost, ghost article, and ghost blog are broad enough to match ordinary conversational requests, which can cause accidental activation of a skill capable of publishing remote content. Because this skill can progress toward Ghost publication, overbroad dispatch increases the chance of unintended side effects.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
76% confidence
Finding

The trigger write ghost is close to a generic built-in write command and may shadow or intercept unrelated authoring requests. In a skill that can publish or modify remote posts, ambiguous dispatch can lead to unintended tool activation and downstream side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description prominently advertises one-click publishing and feature image upload without an equally prominent warning that these actions modify remote Ghost content. Users may perceive it as a local writing helper and not appreciate that invocation can lead to external publication actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
> **AI Ghost Article Writer installed!**
>
> Tell me your topic and I'll write and publish a Ghost article for you.
>
> **Try it now:** "Write a Ghost article about AI programming trends"
>

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

The setup verification command uses npx tsx without pinning an exact version. If tsx is not already installed locally, npx may fetch the latest package at execution time, creating a supply-chain risk and reducing reproducibility.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill instructs drafts to be stored under ~/.youmind/articles/ghost/, a shared home directory accessible to all YouMind skills. Cross-skill shared storage increases the chance that sensitive unpublished content, editorial plans, or proprietary material can be read, modified, or exfiltrated by another compromised or overly-permissive skill.

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
## Draft Location Rule

**Canonical:** write local article Markdown files to `~/.youmind/articles/ghost/<slug>.md`. This shared home directory is available to all YouMind skills — see [`shared/YOUMIND_HOME.md`](shared/YOUMIND_HOME.md).

**Legacy fallback** (if `~/.youmind/` is not writable): `skills/youmind-ghost-article/output/<slug>.md`.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
1. **Self-critique**: Pass all checklist items in the playbook's Step 6
2. **Conformance report**: Generate and present to user (Step 7/8)
3. **Newsletter readiness**: Custom excerpt + email-safe HTML + CTA verified
4. **User approval**: Do not auto-publish without confirmation

### Result Links Rule

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/api-reference.md:12

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
shared/config.example.yaml:2