Back to skill

Security audit

Kb Review

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent knowledge-base review purpose, but it asks for and uses administrator-level Gitea access with broad persistent write capability and unsafe default transport settings.

Review carefully before installing. Use this only with a repository-scoped token over HTTPS, not a site-admin token; require explicit user confirmation before saving; constrain allowed repositories and draft-file paths; and separate the system-config/control-plane functions from the review-generation skill.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
env-example.txt:1
Finding

Administrator Token Transmitted over Cleartext HTTP

Content
View full analysis
dict: return {"Authorization": f"token {ADMIN_TOKEN}", "Content-Type": "application/json"} def api(method: str, path: str, *, json_body: dict | None = None, params: dict | None = None, ok: tuple[int, ...] = (200, 201, 204)): if not GITEA_URL: raise GiteaError("GITEA_URL is not configured") resp = requests.request( method, f"{GITEA_URL}/api/v1{path}", headers=headers(), json=json_body, params=params, timeout=30, ) ``` ### Technical Analysis The distributed environment template configures Gitea through an unencrypted HTTP URL on a public IP address. The setup script copies this template into `.env`, making the insecure endpoint the default installation configuration. The API client places `GITEA_ADMIN_TOKEN` in the HTTP `Authorization` header for every request. HTTP provides neither transport confidentiality nor server authentication. Consequently, a network-positioned attacker can observe the token or alter API traffic. The 30-second timeout does not mitigate interception, and no code rejects non-HTTPS endpoints. ### Attack Path 1. An operator runs `setup.sh`, which copies `env-example.txt` to `.env`. 2. The operator populates `GITEA_ADMIN_TOKEN` without replacing the default HTTP endpoint. 3. The Skill performs an operation such as reading a catalog or saving a review. 4. `gitea_api.api( ...[truncated 846 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/gitea_api.py:28
Finding

Review Skill Uses a Site-Administrator Credential Beyond Its Functional Requirements

Content
View full analysis
dict: return {"Authorization": f"token {ADMIN_TOKEN}", "Content-Type": "application/json"} ``` ```python # scripts/gitea_api.py:60-64 def token_is_site_admin() -> bool: try: api("GET", "/admin/users", params={"limit": 1}) return True except GiteaError: return False ``` ```python # scripts/gitea_api.py:105-110 def create_repo_for_user(username: str, name: str, description: str, private: bool = True) -> dict: if repo_exists(username, name): return {"created": False, "html_url": f"{GITEA_URL}/{username}/{name}"} data = api("POST", f"/admin/users/{username}/repos", json_body={ "name": name, "private": private, "description": description, "auto_init": True, "default_branch": "main", }) ``` ### Technical Analysis The Skill's stated purpose is to generate and save knowledge-base reviews and onboarding documents. Those operations require access only to the specific personal or team repositories involved in a request. Instead, the metadata requires `GITEA_ADMIN_TOKEN`, and the common client attaches that token to all API calls. The module also contains administrator-only functionality, including enumerating administrative users and creating repositories on behalf of arbitrary users. This combines routine content operations and instance-level provisioning in one privilege ...[truncated 1531 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/save_review.py:15
Finding

Caller-Controlled Repository and Local File Arguments Permit Cross-Scope Writes and File Disclosure

Content
View full analysis
None: parser = argparse.ArgumentParser() parser.add_argument("--owner", required=True) parser.add_argument("--repo", required=True) parser.add_argument("--title", required=True) parser.add_argument("--review_file", required=True) parser.add_argument("--brief", default="") parser.add_argument("--scope", default="personal") parser.add_argument("--project_id", default="") args = parser.parse_args() src = Path(args.review_file) if not src.exists(): out(json_fail("review_file_not_found", f"找不到综述草稿:{src}")) return safe = sanitize_filename(args.title) path = f"reviews/{safe}.md" try: g.put_file(args.owner, args.repo, path, src.read_text(encoding="utf-8"), f"paper-kb review: {safe}") ``` ```python # scripts/generate_onboarding.py:15-32 def main() -> None: parser = argparse.ArgumentParser() parser.add_argument("--owner", required=True) parser.add_argument("--repo", required=True) parser.add_argument("--title", required=True) parser.add_argument("--file", required=True) parser.add_argument("--brief", default="") parser.add_argument("--project_id", default="") args = parser.parse_args() src = Path(args.file) if not src.exists(): out(json_fail("file_not_found", f"找不到 onboarding 草稿:{src}")) return safe = sanitize_filename(args.title) path = f"onboarding/{safe}.md" try: g.put_file(args.owner, args.repo, path, src.read_text(encoding="utf-8"), f"paper-kb onboarding: {safe}") cat = catalog.read(args.owner, args.repo) ``` ### Technical Analysis Both persistence scripts accept the destination owner, destinat ...[truncated 2642 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Dependencies Are Installed into the Active Python Environment

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The analysis indicates functionality for creating and managing a private system repository containing operational metadata such as users, teams, permissions, jobs, and chat bindings. Embedding control-plane persistence in a content-review skill is highly dangerous because compromise or misuse could expose sensitive organizational metadata and alter authorization-relevant records outside the user’s expected task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The analysis indicates functionality for creating and managing a private system repository containing operational metadata such as users, teams, permissions, jobs, and chat bindings. Embedding control-plane persistence in a content-review skill is highly dangerous because compromise or misuse could expose sensitive organizational metadata and alter authorization-relevant records outside the user’s expected task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The analysis indicates functionality for creating and managing a private system repository containing operational metadata such as users, teams, permissions, jobs, and chat bindings. Embedding control-plane persistence in a content-review skill is highly dangerous because compromise or misuse could expose sensitive organizational metadata and alter authorization-relevant records outside the user’s expected task.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The analysis indicates functionality for creating and managing a private system repository containing operational metadata such as users, teams, permissions, jobs, and chat bindings. Embedding control-plane persistence in a content-review skill is highly dangerous because compromise or misuse could expose sensitive organizational metadata and alter authorization-relevant records outside the user’s expected task.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gitea_api.py (reported line 20)May include surrounding context.

python
except ImportError:
        return
    here = Path(__file__).resolve().parent
    for candidate in (here / ".env", here.parent / ".env"):
        if candidate.exists():
            load_dotenv(candidate)
            return

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code is designed to operate with a site-admin token and even probes admin capability via /admin/users, despite the skill being described as a review-generation tool. Using administrative credentials for routine content generation violates least privilege and, if the skill is abused or misconfigured, enables broad compromise of the Gitea instance rather than just the intended repository.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This helper exposes broad remote-write and repository administration capabilities, including creating repositories for arbitrary users and adding collaborators, which materially exceeds the stated purpose of generating and saving knowledge-base reviews. In the context of an agent skill, these functions create a dangerous privilege surface: if invoked by prompt-driven logic or chained tooling, they can modify other users' repos or provision access without clear authorization boundaries.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file provisions and maintains a private 'system-config' control-plane repository that stores operational state far beyond the stated scope of generating knowledge-base reviews. In a skill advertised for KB review generation, hidden infrastructure for system-wide bot state, users, teams, and permissions is a strong scope mismatch that expands the blast radius if invoked or modified improperly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code initializes and manages user, team, chat-binding, pending binding, event, job, active task, and permission state, none of which is necessary for producing literature reviews or onboarding notes. This unauthorized breadth creates an unexpected identity and access management surface inside a content-generation skill, increasing the risk of privilege abuse, state tampering, or covert tracking.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · setup.sh (reported line 4)May include surrounding context.

sh
#!/usr/bin/env bash
set -e
python3 -m pip install -r requirements.txt
if [ ! -f .env ]; then cp env-example.txt .env; fi
echo "setup complete"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill declares no explicit tool restrictions even though it clearly invokes local scripts and implies access to files, environment-backed credentials, and repository/network operations. Without a declared allowlist, an agent may execute the skill with broader capabilities than users expect, increasing the chance of unauthorized data access or modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill states that outputs are saved back to the knowledge base by default, but it does not require an explicit consent or confirmation step. Automatic persistence can leak sensitive drafts, create inaccurate records, or overwrite/expand shared knowledge unintentionally, especially in team-scoped contexts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file returns multiple natural-language error messages in Chinese via json_fail, and there is no indication that users can choose their preferred language or that the skill is intentionally limited to a Chinese-only locale. This can violate organizational language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes generating and saving knowledge-base reviews such as literature reviews, research gaps, and onboarding notes based on existing KB sources. This script does not generate review content from KB sources; instead, it uploads an arbitrary local file into a remote Gitea repository and mutates repository catalog/index state, which is a broader repository-management behavior than the description suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code writes onboarding content into a repository via g.put_file and then updates catalog metadata and regenerates an index, but the script provides no confirmation prompt, visible user-facing log, or explanatory comment/docstring disclosing these write operations. Because these actions modify repository state and generated content, they match the code-file warning requirement for file writes and potentially irreversible changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code loads a Gitea admin token from the environment and uses it to make authenticated HTTP requests, including administrative endpoints such as creating repositories and managing collaborators. There is no confirmation prompt, print/log message, or explanatory docstring/comment warning that the skill will access credentials and transmit data to a remote Gitea server.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Functions in this range create repositories, add collaborators, and create or update repository contents, which are write operations affecting user or system data on the remote Gitea instance. The code contains no user-facing warning, confirmation, logging, or inline documentation explaining these side effects.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The schema template contains the instruction "所有回答必须基于知识库来源,不允许补通用知识。" within an otherwise fully Chinese-language generated document, and the other templates at L15 and L23 also hard-code Chinese output labels. This indicates the skill enforces a specific language/locale in generated content without any opt-in or user choice, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scope-resolution logic relies on Chinese trigger words such as "我的", "团队", and related phrases to classify personal versus team requests. This creates a language-specific behavior that may exclude users who ask the same question in another language, and there is no visible opt-in or documented justification in the file for this locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code uploads review content to a remote repository via g.put_file(...), which is a network-backed file write that can modify persistent project data. There is no confirmation prompt, user-facing log message, or explanatory comment/docstring in this file disclosing that the script will publish the supplied review file to the repository.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

After uploading the review, the script updates catalog metadata and regenerates an index, which are additional persistent write operations affecting repository state beyond the main review file. The file provides no user-facing notice that running the script will also modify catalog/index data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

write_json writes structured data to a remote repository through g.put_file, but this file shows no visible user-facing disclosure, consent, or policy gating around persistence of system state. In an agent skill context, silent remote writes can create unauthorized data retention and make behavior materially different from what users expect from a review-generation tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

update_json performs read-modify-write updates against remote system configuration with retries, enabling durable mutation of shared state while providing no visible disclosure or authorization checks in this file. Because it can update arbitrary JSON-backed control data, misuse or unexpected invocation could alter permissions, bindings, or jobs without transparent user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file presents the skill name, purpose, triggers, and response requirements primarily in Chinese, while also including some English headings, but it does not state that language is user-selectable. This can amount to an implicit language policy constraint without opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency 'requests' is unpinned, so builds may resolve to different versions over time, reducing reproducibility and potentially pulling in a vulnerable or breaking release. In a skill that may fetch external knowledge-base sources, this increases supply-chain uncertainty even if it is not an immediately exploitable code flaw by itself.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests
python-dotenv

Static analysis

No suspicious patterns detected.