Back to skill

Security audit

话袋笔记 Skill

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Huadai notes integration, but it needs Review because its helper scripts can execute unintended local code and can send the API key to an overridden endpoint.

Review before installing. Use only with a Huadai API key you are comfortable exposing to this skill, do not set HUADAI_BASE_URL to any non-Huadai host, and avoid passing arbitrary or externally supplied note IDs until upload.sh and update.sh are patched to serialize unique_id safely and validate the API host.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/upload.sh:49
Finding

Arbitrary Python Code Execution Through Unsafe unique_id Interpolation

Content
View full analysis
1 else "", "create_time": '"$CREATE_TIME"', "status": 1, "is_collect": 0, "is_todo": 0 ``` `scripts/update.sh:51-58`: ```bash import json, sys print(json.dumps({ "unique_id": "'"$UNIQUE_ID"'", "type": 1, "content": sys.argv[1] if len(sys.argv) > 1 else "", "status": 1, "is_collect": 0, "is_todo": 0 })) ``` ### Technical Analysis Both scripts insert the shell variable `UNIQUE_ID` directly into the source code supplied to `python3 -c`. Although the intended result is a Python string literal, no escaping or serialization is applied before the value becomes executable Python source. An attacker-controlled identifier containing quotes and Python expressions can terminate or alter the intended string expression. For example, an identifier shaped like the following can cause an operating-system command to execute while the dictionary is evaluated: ```text " + str(__import__("os").system("id")) + " ``` This is distinct from ordinary shell argument injection: the shell passes the value into the generated Python program, and the Python interpreter subsequently treats parts of the value as source code. The update workflow is particularly exposed because `unique_id` may originate from a user instruction or an API search result. The upload script also permits the caller to supply an optional `unique_id`. ### Attack Path 1. An attacker supplies a malicious `unique_id`, either directly in a user request or indirectly through untrusted data that the Agent treats as a note identifier. 2. The Agent invokes one of the affected comman ...[truncated 1259 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/search.sh:14
Finding

API Credential Disclosure Through Unrestricted Base URL Override

Content
View full analysis
&1) ``` `scripts/upload.sh`: ```bash BASE_URL="${HUADAI_BASE_URL:-https://openapi.ihuadai.cn/open/api/v1}" API_KEY="${HUADAI_API_KEY:-}" ``` ```bash RESP=$(curl -sS -w '\n%{http_code}' \ -X POST "$BASE_URL/block/upload-block" \ -H "Authorization: $API_KEY" \ -H "Content-Type: application/json" \ ``` `scripts/update.sh`: ```bash BASE_URL="${HUADAI_BASE_URL:-https://openapi.ihuadai.cn/open/api/v1}" API_KEY="${HUADAI_API_KEY:-}" ``` ```bash RESP=$(curl -sS -w '\n%{http_code}' \ -X POST "$BASE_URL/block/update-block" \ -H "Authorization: $API_KEY" \ -H "Content-Type: application/json" \ ``` ### Technical Analysis The scripts permit `HUADAI_BASE_URL` to replace the documented Huadai API URL without validating the URL scheme, hostname, port, or path. The scripts then send `HUADAI_API_KEY` to the selected endpoint in the `Authorization` header. This conflicts with the restriction in `SKILL.md` that declares `https://openapi.ihuadai.cn/open/api/v1` as the only permitted base URL. An attacker who can influence the Skill process environment can point the scripts to a server under their control and receive the API key. HTTPS alone does not prevent this issue. An attacker-controlled domain can use a valid TLS certificate, causing `curl` to establish a correctly validated encrypted connection to t ...[truncated 1317 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个覆盖新建、更新、搜索、查看、收藏和配置话袋笔记的综合 Skill,但提供的代码片段只执行“新建/上传笔记”这一项功能。它没有展示任何用于搜索、读取详情、更新已有笔记、收藏笔记或执行授权配置的代码路径。虽然代码使用话袋 OpenAPI 且与“保存到笔记”场景一致,但其实际能力范围明显窄于声明,因此描述不能准确代表该代码块的实际行为,属于描述与行为不匹配。

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

如果 ClawHub 不可用,也可以直接从 GitHub 安装:

text
请安装话袋笔记 Skill,地址:https://raw.githubusercontent.com/monkeyDB/hd-notes-skills/main/SKILL.md

手动安装

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly instructs the agent to run shell scripts from the scripts/ directory, but the manifest declares no tool scope or allowed-tools restrictions. This creates an execution-capability mismatch where an agent may invoke shell unexpectedly, increasing the attack surface for command execution and reducing policy enforcement around what tools the skill may use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Broad natural-language triggers such as '保存', '搜一下', and '找找笔记' can cause the skill to activate during ordinary conversation without clear user intent to access personal notes. In a notes skill tied to authenticated APIs, unintended invocation can expose private search results or create/update notes based on ambiguous utterances.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The routing table uses very broad trigger families like '新建/上传/保存/写入到笔记' and '搜/找/检索', which may overmatch general requests and route them into authenticated note operations. Because the skill handles personal note search and write flows, overbroad activation increases the risk of unauthorized or accidental data access and unintended state changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest contains user-facing natural-language metadata in a single language, which can amount to a language/locale policy violation when no opt-in or alternative language is provided. The file does not indicate that the skill is region-specific or that Chinese-only behavior is intentional and justified.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 79)May include surrounding context.

Authorization: <HUADAI_API_KEY>

text

curl 示例:

```bash
curl -sS "https://openapi.ihuadai.cn/open/api/v1/block/b_1730000000_a1b2c3d4" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script presents all user-facing guidance exclusively in Chinese, including setup instructions and status messages. Under the policy, forcing a specific language without user opt-in or a clearly documented justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's comments, usage text, and runtime messages are written entirely in Chinese, which imposes a specific language on users. The file does not offer an opt-in language choice or state that the skill is intentionally restricted to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's usage instructions and warnings are entirely written in Chinese, and the runtime output later in the script is also Chinese-only. This creates a natural-language locale policy issue because the skill forces a specific language without any opt-in or indication that it is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

The script transmits user-provided note content and an API key to an external service via curl, which is a real data-exfiltration boundary even if it is the skill's intended function. In the context of a note-taking skill this is expected behavior, but it is still security-relevant because sensitive user content may be sent off-host and the destination can be changed through the HUADAI_BASE_URL environment variable.

Content

Scanner excerpt · scripts/update.sh (reported line 13)May include surrounding context.

sh
#   - content 应为更新后的完整内容,非增量追加
#
# 依赖:
#   - curl
#   - 环境变量 HUADAI_API_KEY
# ============================================================
set -euo pipefail

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

All success and failure messages emitted by the script are fixed Chinese strings. Per the policy, forcing a specific language in natural-language output without offering a choice or clearly justified locale restriction is a reportable issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends arbitrary user-provided note content to a remote third-party API, but it does not provide any explicit user-facing warning or consent prompt at the point of transmission. In a note-taking skill, users may include sensitive personal, business, or credential-like data, so silent transmission increases the risk of unintended data disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script performs external network transmission of user note content and an API credential to a remote service via curl. In the context of a personal note skill, this behavior is expected, but it remains security-relevant because it can expose sensitive content to a third-party service and any compromise or misconfiguration of the endpoint would affect confidentiality.

Content

Scanner excerpt · scripts/upload.sh (reported line 43)May include surrounding context.

sh
"

# --- 调用 API ---
RESP=$(curl -sS -w '\n%{http_code}' \
  -X POST "$BASE_URL/block/upload-block" \
  -H "Authorization: $API_KEY" \
  -H "Content-Type: application/json" \

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill name and description are written only in Chinese, which can amount to a language/locale constraint in user-facing metadata. The manifest does not indicate that the skill is region-specific or provide any user opt-in or alternative language, so this appears to conflict with the language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language strings in comments, errors, and status messages are consistently Chinese-only, which effectively forces a specific language for operation and troubleshooting. Under the policy, this is a language-choice constraint unless the skill offers user selection or clearly documents a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.