Back to skill

Security audit

Arknights Guide

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its Arknights guide purpose, but its install instructions include mutable remote shell execution and its profile feature creates persistent local game-account data automatically.

Review the install path carefully. Prefer installing from a pinned release or reviewed package instead of running the documented curl-to-bash command from main. Also be aware that the skill keeps a local Doctor profile with game UID, level, server, roster, resources, goals, and preferences; use ARKNIGHTS_MEMORY_DIR deliberately and delete the profile manually if you no longer want it retained.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/quickstart.md:15
Finding

Unpinned Remote Installer Download and Execution

Content
View full analysis

Vulnerability Details

File Location: references/quickstart.md, lines 15-24
Vulnerability Type: Mutable remote code retrieval and shell execution
Risk Level: Critical

Vulnerable Code:

bash
```bash
bash -c "$(curl -fsSL https://raw.githubusercontent.com/morandot/arknights-skill/main/install.sh)"

This runs a script fetched from GitHub. To review it first:

bash
curl -fsSL -o /tmp/arknights-install.sh https://raw.githubusercontent.com/morandot/arknights-skill/main/install.sh
less /tmp/arknights-install.sh   # inspect the script
bash /tmp/arknights-install.sh   # run after review
text

### Technical Analysis

The documented installation procedure downloads a shell script from the mutable `main` branch of a personal GitHub repository and executes it with `bash`. The first installation command passes the response body directly to a shell without pinning an immutable commit, checking a cryptographic digest, or verifying a digital signature.

The downloaded `install.sh` file is not part of the audited artifact, so its effective behavior cannot be reviewed from this project. Its contents may change after the Skill has passed review. A repository compromise, maintainer account takeover, malicious upstream update, DNS or endpoint compromise, or unauthorized branch modification could therefore turn the installation command into an arbitrary code-execution channel.

The alternative download-and-review workflow reduces accidental execution risk but does not provide technical integrity enforcement. Review is optional, the source remains the mutable `main` branch, and the final command executes the downloaded file without verifying that it corresponds to a trusted release.

Although the document mentions setting `REPO_REF`, the initial installer itself is still retrieved from `main`. Because that remote installer is absent from the audited package, the audit cannot establish whether or how securely it 
...[truncated 1501 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash installation method.
  2. Package all installation logic inside the reviewed and versioned Skill artifact.
  3. Prefer a trusted package manager or Skill installer that supports immutable versions and integrity metadata.
  4. If a remote script is unavoidable, retrieve it from an immutable commit URL rather than main.
  5. Publish a SHA-256 digest through an independent trusted release channel and verify it before execution.
  6. Prefer cryptographic release signatures with a documented trusted public key.
  7. Download into a securely created temporary file, display its resolved source and expected digest, and require explicit user approval before execution.
  8. Ensure the installer runs without elevated privileges and clearly document every filesystem location it modifies.
  9. Include the installer in the repository artifact so static reviewers can inspect the exact code that will execute.

other

Note
Location
SKILL.md:28
Finding

Implicit Invocation Causes Mandatory Persistent Profile Access Without Separate Opt-In

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 28-30 and 62-95; agents/openai.yaml, lines 3-10 and 41; scripts/memory.py, lines 617-620
Vulnerability Type: Excessive local data collection and automatic persistence
Risk Level: Low

Relevant Code and Instructions:

text
<HARD-GATE>
Do NOT answer any Arknights question without first attempting to read the local Doctor profile. See Rule 0 below.
</HARD-GATE>
text
HARD-GATE: You MUST attempt to read the profile before answering.
yaml
default_prompt: |
  Use $arknights-skill to answer Arknights questions. Workflow:
  1. Read the local Doctor profile via memory.py read (mandatory, see SKILL.md Rule 0 HARD-GATE).
  2. Greet the user briefly. Use the profile silently for personalization; do not recite its contents.
  3. If the profile is empty, offer to help set it up by collecting their server, level, and key operators.
  4. Answer their question following the skill rules.
  5. After answering, if the user explicitly provided new facts this turn, update the profile with those facts.

policy:
  allow_implicit_invocation: true
python
def command_read(_: argparse.Namespace) -> int:
    profile, created = load_profile()
    if created:
        save_profile(profile, touch_updated_at=False)
    print_json(profile)

Technical Analysis

The Skill permits implicit invocation while requiring profile access before every Arknights answer. Consequently, a generic lore, terminology, or mechanics question can activate a stateful workflow even when the user did not explicitly request personalization.

The nominally read-oriented memory.py read command is not strictly read-only. If no profile exists, it creates ~/.config/arknights-skill/doctor-profile.json. Subsequent workflow instructions direct the Agent to store explicit account facts automatically after answering. Stored fields may incl ...[truncated 1908 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make profile personalization opt-in instead of a mandatory hard gate.
  2. Keep read strictly read-only; do not create a profile unless the user has consented to persistent storage.
  3. Disable implicit invocation for stateful operations, or require explicit confirmation before the first profile read or write.
  4. Allow ordinary lore, terminology, mechanics, and generic strategy questions to run without profile access.
  5. Avoid storing UID by default because it is not necessary for personalized gameplay advice.
  6. Add a documented command to delete the entire profile, not only individual operator entries.
  7. Clearly communicate the storage path, retained fields, retention duration, and deletion procedure before collection.
  8. Create the profile with restrictive user-only file permissions and verify permissions after atomic replacement.
  9. Separate the personalization feature from the core Skill so users can use the guidance functionality without persistent state.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/examples.md (reported line 130)May include surrounding context.

md
"Use SilverAsh, Thorns, Saria, Exusiai, Myrtle, Eyjafjalla."
→ Instead: "Core roles: a burst guard for wave clear (SilverAsh or alternatives), a sustained lane holder (Thorns or a strong Arts guard), a healer-tank (Saria or a healing defender + medic), fast DP generation (Myrtle or any flagbearer), and an AoE caster (Eyjafjalla or a splash caster)."

❌ Wrong pattern: Old version conclusion without caveat
"SilverAsh is still S-tier."
→ Instead: "SilverAsh was historically S-tier. I don't have live data on current CN meta. His burst role is still useful, but I recommend searching for the latest assessment from [current month/year]."

Lp1

High
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The script writes the profile, temporary files, and a migration marker to local storage, which is broader than a no-write or single-file-only permission claim. Undeclared write capability is dangerous because it permits persistent local state changes that may not be expected by the platform policy or the user.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The script writes the profile, temporary files, and a migration marker to local storage, which is broader than a no-write or single-file-only permission claim. Undeclared write capability is dangerous because it permits persistent local state changes that may not be expected by the platform policy or the user.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The script writes the profile, temporary files, and a migration marker to local storage, which is broader than a no-write or single-file-only permission claim. Undeclared write capability is dangerous because it permits persistent local state changes that may not be expected by the platform policy or the user.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The quickstart instructs users to install the skill via npx skills add from an unpinned GitHub repository reference, which allows whatever code is currently at the referenced repo/default branch to be fetched and executed. If the upstream repository, dependency chain, or account is compromised, users may install a tampered skill without noticing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The storage directory can be redirected via the ARKNIGHTS_MEMORY_DIR environment variable, so the profile is not actually confined to the fixed path implied by the skill description. In hostile or misconfigured environments, this can redirect reads and writes to arbitrary local locations, increasing the chance of clobbering unrelated files or exposing other local data through the skill's normal operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delete-operator command irreversibly removes an operator record and related pending confirmations, then writes the change to disk. Although the CLI help says 'Delete a recorded operator,' the code provides no confirmation prompt, dry-run mode, or stronger user-facing warning before performing the destructive action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The dismiss command permanently drops matching pending confirmations and immediately saves the modified profile. The operation changes stored state in a potentially irreversible way, but the code offers no confirmation step or stronger disclosure before executing it.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI requires a '--apply' flag for the confirm command, suggesting a safety gate, but command_confirm never checks that flag before modifying stored data. This creates a misleading interface where callers may believe confirmation is enforced more strictly than it is, enabling unintended state changes if the function is invoked directly or argument handling changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

During migration the code writes not only the main profile but also a '.migrated' marker file, and normal saves create temporary files in the profile directory. This is broader than a claim that only a single doctor profile file is updated, which can matter in tightly sandboxed or policy-driven environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.