Back to skill

Security audit

个人知识库

Security checks for vulnerabilities and agentic risk

Overview

This personal knowledge-base skill is coherent in purpose, but its local file handling has serious safety gaps that could let crafted knowledge-base files run code or let names write outside the intended folder.

Install only if you are comfortable with this skill managing local document copies and potentially sending document text or questions to ZhipuAI. Use a dedicated low-privilege workspace, avoid untrusted or shared knowledge-base directories, do not open knowledge bases from other people, and require explicit confirmation before delete/update actions. The pickle and path-traversal issues should be fixed before using it with sensitive files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/knowledge_base_manager.py:454
Finding

Unsafe Pickle Deserialization Enables Arbitrary Code Execution

Content
View full analysis
Dict[str, Any]: """Load knowledge-base metadata.""" if os.path.exists(self.kb_metadata_file): try: with open(self.kb_metadata_file, 'rb') as f: return pickle.load(f) except Exception as e: logger.warning(f"Failed to load knowledge-base metadata: {str(e)}") return {"chunk_size": DEFAULT_CHUNK_SIZE} ``` ```python if os.path.exists(self.index_file) and os.path.exists(self.metadata_file): logger.info(f"Loading existing FAISS index: {self.index_file}") with open(self.index_file, 'rb') as f: vectors_data = pickle.load(f) with open(self.metadata_file, 'rb') as f: self.metadata = pickle.load(f) ``` ```python kb_metadata_file = os.path.join( vectordb_dir, KnowledgeBaseManager.KB_METADATA_FILE ) chunk_size = DEFAULT_CHUNK_SIZE if os.path.exists(kb_metadata_file): try: with open(kb_metadata_file, 'rb') as f: kb_metadata = pickle.load(f) chunk_size = kb_metadata.get( "chunk_size", DEFAULT_CHUNK_SIZE ) except Exception: pass ``` ### Technical Analysis Python pickle data is executable serialization rather than a data-only format. During `pickle.load()`, objects can invoke attacker-defined reconstruction functions through methods such as `__reduce__`. A malicious pickle can therefore execute arbitrary Python callables before the application validates or uses the resulting object. The implementation loads three persistent files without validating their origin, ownership, type, permissions, or integrity: - `vectordb/kb_metadata.pkl` - `vectordb/fais ...[truncated 1742 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/knowledge_base_manager.py:407
Finding

Knowledge-Base Name Path Traversal Allows Writes Outside the Workspace

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
scripts/knowledge_base_manager.py:850
Finding

Untrusted Retrieved Documents Can Inject Instructions into the RAG Prompt

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:269
Finding

Dependency Installation Instructions Use Unpinned Packages Without Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README states that deleting a file removes both vector data and the original source file, and that it can no longer be retrieved, but it does not mention confirmation, backup, undo, or recovery limitations. In a skill managing personal documents, this creates a real risk of accidental irreversible data loss, especially when actions are triggered through natural-language requests that may be ambiguous or misinterpreted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly describes a workflow where retrieved document content and user questions are sent to external AI services for embeddings and answer generation, but it does not warn users that their local knowledge-base contents may leave the local environment. In a personal knowledge-base skill, users are likely to upload sensitive notes, documents, or work files, so the lack of a clear privacy/data-transmission disclosure can lead to unintended exposure of confidential data.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes capabilities that access environment variables, read files, and write files, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it easier for an agent runtime to invoke broader file or env access than users may expect, especially given the skill handles API keys and filesystem operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The update flow explicitly deletes an existing source file and its vectorized content before replacing it, but the skill does not warn that this is a destructive operation or require confirmation. If triggered accidentally or through ambiguous prompting, user data could be irreversibly removed before a successful replacement occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The removal flow permanently deletes both vector data and the original file from sourcefiles, but the documentation does not clearly warn users that deletion is irreversible. In a knowledge-base skill managing personal documents, accidental invocation could cause permanent loss of important user data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as a personal knowledge-base manager, but document chunks and queries are sent to external ZhipuAI services for embeddings and answer generation. This creates a confidentiality risk because private knowledge-base content may be transmitted off-host without clear disclosure, consent, or data-classification controls. In the context of a personal KB, users are likely to store sensitive notes and documents, making the mismatch more dangerous.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The system prompt instructs the model in Chinese and implicitly fixes the interaction language, while the file does not provide any user opt-in or language-selection mechanism. This can violate language/locale policy when users are not given a choice.

Content

No source excerpt is available for this finding.

Insecure deserialization: pickle.load()

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

The code deserializes kb_metadata.pkl with pickle.load() from disk. Pickle is code-executing by design, so if an attacker can replace or tamper with that file, opening the knowledge base can trigger arbitrary code execution under the current user context. In a skill that manages local files and knowledge-base directories, this is especially dangerous because these files are expected to be routinely loaded.

Content

Scanner excerpt · scripts/knowledge_base_manager.py (reported line 458)May include surrounding context.

python
if os.path.exists(self.kb_metadata_file):
            try:
                with open(self.kb_metadata_file, 'rb') as f:
                    return pickle.load(f)
            except Exception as e:
                logger.warning(f"加载知识库元数据失败: {str(e)}")
        return {"chunk_size": DEFAULT_CHUNK_SIZE}

Insecure deserialization: pickle.load()

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The FAISS vector data file is loaded with pickle.load(), allowing arbitrary Python object deserialization from a file on disk. If an attacker can plant or modify faiss_index.bin, the load path can execute attacker-controlled code when the knowledge base initializes. Because this occurs during normal startup/index loading, exploitation could be low-friction in a shared or synced workspace.

Content

Scanner excerpt · scripts/knowledge_base_manager.py (reported line 567)May include surrounding context.

python
# 加载向量和元数据
                with open(self.index_file, 'rb') as f:
                    vectors_data = pickle.load(f)

                # 加载元数据
                with open(self.metadata_file, 'rb') as f:

Insecure deserialization: pickle.load()

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The metadata file is also deserialized using pickle.load(), creating another arbitrary code execution sink from attacker-controlled local content. Since metadata is read automatically whenever the index is initialized, a malicious file dropped into the vectordb directory could compromise the host without further user interaction beyond using the skill.

Content

Scanner excerpt · scripts/knowledge_base_manager.py (reported line 571)May include surrounding context.

python
# 加载元数据
                with open(self.metadata_file, 'rb') as f:
                    self.metadata = pickle.load(f)

                # 重建FAISS索引
                if len(vectors_data) > 0:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

When answering questions, the code builds a prompt from retrieved knowledge-base text and sends it to an external LLM service if enabled, without any user-facing warning at that decision point. This can expose sensitive query text and document excerpts to a third party, which is particularly risky for a 'personal knowledge base' workflow where users may expect local-only processing.

Content

No source excerpt is available for this finding.

Insecure deserialization: pickle.load()

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The catalog path reads each knowledge base's metadata file with pickle.load() while enumerating databases. That means merely listing knowledge bases can trigger unsafe deserialization and code execution if a malicious kb_metadata.pkl exists in any subdirectory. This broadens exposure because even read-only discovery operations become dangerous.

Content

Scanner excerpt · scripts/knowledge_base_manager.py (reported line 1213)May include surrounding context.

python
if os.path.exists(kb_metadata_file):
                try:
                    with open(kb_metadata_file, 'rb') as f:
                        kb_metadata = pickle.load(f)
                        chunk_size = kb_metadata.get("chunk_size", DEFAULT_CHUNK_SIZE)
                except Exception:
                    pass

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
68% confidence
Finding

The manifest description and all invocation examples are presented solely in Chinese, implying a fixed language expectation for using the skill. SQP-3 covers locale or language policy issues when a skill forces a specific language without offering user opt-in or an explicit justified constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This plain-text config file contains user-facing natural-language instructions solely in Chinese, which can impose a language requirement on users or maintainers without opt-in. The file does not indicate that the skill is region-specific or provide an alternative language option.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Beyond managing a knowledge base, the code retrieves a ZHIPUAI_API_KEY from environment variables or config and initializes a remote API client. Accessing external credentials and remote model infrastructure is not stated in the manifest and is a distinct capability from basic KB file/vector management.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.