Back to skill

Security audit

Init User

Security checks for vulnerabilities and agentic risk

Overview

The skill is for a real onboarding workflow, but it uses broad administrator access and insecure account-linking/network defaults that need review before installation.

Review this skill before installing. Use it only in a controlled paper-kb deployment, move Gitea to HTTPS before any token is configured, avoid a site-wide admin token where possible, add proof that the Feishu user controls the requested Gitea account, protect or avoid storing Feishu tokens in users.json, and install dependencies in a dedicated virtual environment rather than the system Python.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gitea_api.py:34
Finding

Site-administrator token transmitted over plaintext HTTP

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/init_user.py:147
Finding

Gitea accounts can be bound without proof of account ownership

Content
View full analysis
None: # 0. Prerequisite check: token must be a site administrator if not g.token_is_site_admin(): _fail( "not_admin", "The current token is not associated with a Gitea site administrator.", ) # 1. Bootstrap system-config g.ensure_system_repo() users = g.read_users() # 2. Existing open_id registration if open_id in users: info = users[open_id] _out({ "success": True, "already_registered": True, "user": info, "repo_url": f"{g.GITEA_URL}/{info['gitea_username']}/{REPO_NAME}", "message": "This Feishu user has already been registered.", }) return # 3. Reject usernames already bound to another open_id for oid, info in users.items(): if info.get("gitea_username") == gitea_username: _fail( "username_taken", f"Gitea account {gitea_username} is already bound.", ) # 4. Verify only that the Gitea account exists gitea_user = g.get_user(gitea_username) if gitea_user is None: _fail( "gitea_user_not_found", f"Gitea user {gitea_username} was not found.", ) canonical = gitea_user.get("login", gitea_username) # 5. Create or reuse a private repository under that account repo = g.create_repo_for_user( canonical, REPO_NAME, description=f"Research knowledge base | Direction: {research_direction}", ) ``` The subsequently created mapping is written at `scripts/init_user.py:219-239`: ```python record = { "gitea_username": canonical, "r ...[truncated 2069 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/init_user.py:129
Finding

Registration metadata and Feishu table routing rely only on an asserted open_id

Content
View full analysis
None: users = g.read_users() info = users.get(open_id) if info: _out({ "success": True, "registered": True, "user": info, "repo_url": f"{g.GITEA_URL}/{info['gitea_username']}/{REPO_NAME}", }) else: _out({"success": True, "registered": False}) ``` ```python def do_update_feishu(open_id: str, feishu_app_token: str, feishu_table_id: str) -> None: users = g.read_users() if open_id not in users: _fail("user_not_found", "This open_id is not registered.") def mutate(u: dict) -> dict: if open_id in u: u[open_id]["feishu_app_token"] = feishu_app_token u[open_id]["feishu_table_id"] = feishu_table_id return u g.write_users(mutate) _out({ "success": True, "message": "Feishu table information was written to the user record.", "feishu_app_token": feishu_app_token, "feishu_table_id": feishu_table_id, }) ``` The command-line parser accepts the identifier directly at `scripts/init_user.py:277`: ```python parser.add_argument("--open_id", required=True, help="Current Feishu user's open_id") ``` ### Technical Analysis The script treats possession of an `open_id` string as sufficient authorization to read or modify that user’s record. It does not cryptographically bind the operation to an authenticated Feishu request, verify the calling principal, or require a registration-specific capability for updates. The check operation returns the complete stored record, including Gitea identity, research direction, and Feishu table identifiers. The update operation permits replacement of the Feishu app token and table ID for any e ...[truncated 1289 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
setup.sh:8
Finding

Unpinned dependencies are installed into the system Python environment

Content
View full analysis
=2.28 python-dotenv>=1.0 ``` The installation script modifies the system Python environment: ```bash echo "[1/3] Installing Python dependencies..." pip3 install -r requirements.txt --break-system-packages 2>/dev/null || pip3 install -r requirements.txt ``` ### Technical Analysis The requirements specify minimum versions but no upper bounds, exact versions, or integrity hashes. Future releases therefore become part of the Skill’s effective executable code without being covered by this audit. The `--break-system-packages` option bypasses protections intended to prevent `pip` from modifying an operating-system-managed Python installation. This can replace or alter libraries used by unrelated applications and expands the blast radius of dependency conflicts or package compromise. The reviewed package names are legitimate and no malicious dependency was identified. The risk arises from unsafe resolution and installation practices rather than an observed malicious package. ### Attack Path 1. A future dependency release or transitive dependency is compromised, malicious, or incompatible. 2. An operator runs `setup.sh`. 3. `pip` resolves the newest version satisfying each open-ended constraint. 4. Package installation or import-time code executes on the host. 5. Because installation targets the system interpreter, the affected package can also influence unrelated Python applications that share that environment. ### Impact Assessment A compromised dependency can execute with the privileges of the user running setup and access files, environment variables, network credentials, and project configuration available to that user. Even without a malicious package, system-wide installation can destabilize ...[truncated 117 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (33)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · env-example.txt (reported line 2)May include surrounding context.

text
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gitea_api.py (reported line 6)May include surrounding context.

python
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gitea_api.py (reported line 27)May include surrounding context.

python
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_user.py (reported line 279)May include surrounding context.

python
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 11)May include surrounding context.

sh
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 12)May include surrounding context.

sh
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 13)May include surrounding context.

sh
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 16)May include surrounding context.

sh
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 23)May include surrounding context.

sh
# paper-kb / init_user 环境配置
# 复制本文件为 .env 并填入真实值

# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The file instructs operators to create and use a Gitea administrator access token with broad privileges including admin write. Even though no live token is present, embedding a workflow that requires a highly privileged long-lived token increases the blast radius of compromise and encourages unsafe secret management if copied into a real .env file.

Content

Scanner excerpt · env-example.txt (reported line 7)May include surrounding context.

text
# Gitea 服务器地址(注意确认是哪台服务器!末尾不要带斜杠)
GITEA_URL=http://43.156.243.152:3000

# 机器人账号的 Access Token
# 要求:该账号必须是 Gitea 站点管理员(管理后台→用户管理→勾选"是管理员")
# Token 权限范围:repo 读写、admin 写、user 读
GITEA_ADMIN_TOKEN=在这里填入token

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gitea_api.py (reported line 33)May include surrounding context.

python
except ImportError:
        return
    here = Path(__file__).resolve().parent
    for candidate in (here / ".env", here.parent / ".env"):
        if candidate.exists():
            load_dotenv(candidate)
            return

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code explicitly implements admin-only capabilities such as enumerating admin access and creating repositories for arbitrary users. Those operations are powerful control-plane actions; if exposed through an agent skill or invoked unexpectedly, they can modify other users' resources and facilitate unauthorized persistence or lateral abuse in the Gitea instance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill provides fixed Chinese reply text and directs the agent to send it verbatim, which effectively forces a specific language for user communication. The file does not indicate that the language is optional, user-selected, or justified as a region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs users to register via a plain HTTP Gitea URL, which exposes credentials and session data to interception or modification by any network attacker on the path. This is especially risky because the step is part of account onboarding, where users are likely to submit usernames, passwords, or other sensitive setup data without noticing the absence of transport security.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This manifest description explains what the skill does but does not specify precise invocation phrases, scope boundaries, or exclusion conditions. For a manifest file, that can make activation criteria ambiguous and increase the chance of unintended invocation in contexts involving generic user initialization or registration guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language description is written to indicate Chinese-specific behavior and labels without any indication that users may choose another language or that the locale restriction is intentional and justified. This can violate language/locale policy when a skill implicitly enforces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code hardcodes the type display field as Chinese ("中文类型名") for outputs written to frontmatter, Feishu tables, and index section titles. That is a natural-language locale constraint, and the file does not provide any user choice, opt-in, or documented region-specific justification for requiring Chinese.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module loads a Gitea administrator token from the environment and prepares it for all API requests, giving this code broad administrative reach if the token is present. In the context of a reusable skill module, bundling admin-capable credential use with no visible scoping, least-privilege controls, or operation gating significantly increases the blast radius of misuse or compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code sends HTTP requests with an Authorization header derived from GITEA_ADMIN_TOKEN, which is a safety-relevant network operation involving credentials. Although the module docstring describes its technical role, there is no user-facing warning, confirmation, or disclosure here about outbound API calls using admin-level authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The put_file function creates or updates files in a remote repository, which is a persistent write operation affecting system data. While the function name and docstring describe behavior, there is no warning or disclosure about the side effect of modifying repository contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

ensure_system_repo bootstraps a repository and writes users.json, creating durable configuration state on the Gitea server. This is a safety-relevant change to system integrity, but the file lacks any explicit warning or user disclosure beyond routine implementation comments.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented '--check' mode implies a simple registration-status lookup, but do_check() returns the entire stored user record when a user exists. That record includes Feishu app/table identifiers and potentially other sensitive metadata, creating an unnecessary information disclosure path to any caller able to supply an open_id.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The update-feishu mode is described as writing back table information, but do_update_feishu() also echoes the provided feishu_app_token and feishu_table_id to stdout. Since stdout is consumed by orchestration systems and often logged, this leaks sensitive identifiers into logs and downstream tooling unnecessarily.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instruction 全部使用中文 imposes a fixed language policy on AI-generated content. There is no indication that users can choose another language or that the Chinese-only requirement is an explicitly justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script persists feishu_app_token and feishu_table_id in the user mapping record and also depends on GITEA_ADMIN_TOKEN, but the file lacks any warning comment or docstring explaining that credentials are stored and used for privileged operations. Because this involves sensitive tokens and administrator access, the absence of explicit disclosure is a safety concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.