Back to skill

Security audit

i-skill

Security checks for vulnerabilities and agentic risk

Overview

This personalization skill is not malicious, but it needs Review because it stores and mutates a sensitive local profile while the code does not enforce the consent and sanitization protections its instructions promise.

Install only if you are comfortable with a local skill storing a persistent personalization profile and related consent/audit logs. Use a dedicated private data directory, avoid putting sensitive identifiers in the profile, and treat the consent/sanitization protections as incomplete until the code enforces them directly.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/myself_manager.py:273
Finding

Profile Operations Do Not Enforce User Consent or Activation State

Content
View full analysis
Dict[str, Any]: """Securely read myself.md file content""" try: if not self.myself_file.exists(): return { "success": False, "message": "myself.md file does not exist", "file_path": str(self.myself_file), "content": "" } with open(self.myself_file, 'r', encoding='utf-8') as f: content = f.read() self._log_operation("read", f"Read myself.md ({len(content)} characters)") return { "success": True, "message": "myself.md read successfully", "file_path": str(self.myself_file), "content": content, "content_length": len(content) } except Exception as e: return { "success": False, "message": f"Failed to read myself.md: {str(e)}", "file_path": str(self.myself_file), "content": "" } ``` The same absence of authorization checks affects the public create, update, and delete operations in `scripts/myself_manager.py:216-394`, as well as their convenience wrappers in `scripts/myself_manager.py:468-491`. ### Technical Analysis `MyselfManager` exposes methods that read, create, overwrite, and delete the user's personalization profile. These methods do not consult `ConsentManager`, verify the status in `i-skill_state.json`, or require a confirmation capability for destructive operations. The enforcement boundary therefore exists only in the natural-language instructions in `SKILL.md`, not in the code that performs the protected operation. Any local component that can import this module can invoke the profile APIs directly and bypass the documented consent lifecycle. This violates ...[truncated 1243 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit_log.py:115
Finding

Recursive Initialization Prevents Reliable Consent and Audit Persistence

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/audit_log.py:402
Finding

Audit Export Directory Restriction Can Be Bypassed with a Shared Path Prefix

Content
View full analysis
Tuple[bool, str]: try: # [P1修复] 路径安全校验:输出文件必须在 user_data_path 下 output_file = Path(output_path).resolve() if not str(output_file).startswith(str(self.user_data_path)): return False, f"安全拒绝:导出路径必须位于 {self.user_data_path} 目录内" if log_type == "audit": log = self._load_audit_log() elif log_type == "defensive": log = self._load_defensive_log() else: return False, f"未知日志类型: {log_type}" if filters: if filters.get("skill_name"): log = [e for e in log if e.get("skill_name") == filters["skill_name"]] if filters.get("action"): log = [e for e in log if e.get("action") == filters["action"]] if filters.get("level"): log = [e for e in log if e.get("level") == filters["level"]] output_file.parent.mkdir(parents=True, exist_ok=True) if format == "json": with open(output_file, 'w', encoding='utf-8') as f: json.dump(log, f, indent=2, ensure_ascii=False) elif format == "csv": import csv if log: with open(output_file, 'w', newline='', encoding='utf-8') as f: writer = csv.DictWriter(f, fieldnames=log[0].keys()) writer.writeheader() writer.writerows(log) ``` ### Technical Analysis The method uses string-prefix comparison to decide whether the destination is inside `user_data_path`. A shared textual prefix does not imply filesystem ancestry. For example, if the trusted root is `/tmp/user_data`, the resolved path ...[truncated 1423 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/myself_manager.py:112
Finding

Profile Writes Do Not Apply the Documented PII Sanitization

Content
View full analysis
Dict[str, Any]: """Validate guidance content for security and quality""" if not content or not content.strip(): return {"valid": False, "message": "Content cannot be empty"} if len(content) > MAX_CONTENT_LENGTH: return {"valid": False, "message": f"Content too large (max {MAX_CONTENT_LENGTH:,} characters)"} if not content.startswith('#'): # 允许无标题的内容,但给出提示 return {"valid": True, "message": "Content validated (warning: missing header)"} return {"valid": True, "message": "Content validated successfully"} ``` The accepted input is then written unchanged: ```python def create_myself(self, guidance_content: str) -> Dict[str, Any]: """Securely create myself.md file with personalized guidance""" try: self._ensure_initialized() if not self._validate_file_path(self.myself_file): return { "success": False, "message": "Security violation: Invalid file path", "file_path": str(self.myself_file) } validation_result = self._validate_guidance(guidance_content) if not validation_result["valid"]: return { "success": False, "message": f"Guidance validation failed: {validation_result['message']}", "file_path": str(self.myself_file) } with open(self.myself_file, 'w', encoding='utf-8') as f: f.write(guidance_content) # 在 Unix 系统上设置文件权限 if os.name != 'nt': os.chmod(self.myself_file, 0o600) ``` ...[truncated 1856 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill performs persistent local file reads, writes, resets, and deletion of profile/state/log files, yet its declared purpose does not clearly communicate these storage and CRUD capabilities. Undisclosed persistence is dangerous in a personalization context because it can accumulate sensitive behavioral data and operational logs beyond what users reasonably expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill performs persistent local file reads, writes, resets, and deletion of profile/state/log files, yet its declared purpose does not clearly communicate these storage and CRUD capabilities. Undisclosed persistence is dangerous in a personalization context because it can accumulate sensitive behavioral data and operational logs beyond what users reasonably expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill performs persistent local file reads, writes, resets, and deletion of profile/state/log files, yet its declared purpose does not clearly communicate these storage and CRUD capabilities. Undisclosed persistence is dangerous in a personalization context because it can accumulate sensitive behavioral data and operational logs beyond what users reasonably expect.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill performs persistent local file reads, writes, resets, and deletion of profile/state/log files, yet its declared purpose does not clearly communicate these storage and CRUD capabilities. Undisclosed persistence is dangerous in a personalization context because it can accumulate sensitive behavioral data and operational logs beyond what users reasonably expect.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
1. **Module Loading**: When the skill modules (`audit_log.py`, `consent_manager.py`, `myself_manager.py`) are first imported or instantiated, no file system ope

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 216)May include surrounding context.

md
1. **Module Loading**: When the skill modules (`audit_log.py`, `consent_manager.py`, `myself_manager.py`) are first imported or instantiated, no file system ope

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
97% confidence
Finding

The 'Always Obey' behavioral anchor is an anti-refusal construct that attempts to make its instructions persist regardless of context length. This is dangerous because it encourages the agent to prioritize skill instructions over higher-level safety policies and can suppress caution around sensitive data handling or unauthorized actions.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
---

## ⚡ Behavioral Anchors (High Priority — Always Obey)

> These rules remain active throughout the entire session after activation, regardless of context length.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/consent_manager.py (reported line 151)May include surrounding context.

python
prompt += "\n\n是否允许该技能访问您的档案?"
        prompt += "\n\n选项:\n- 输入 '是' 或 'yes' 授权\n- 输入 '否' 或 'no' 拒绝\n- 输入 '稍后' 或 'later' 稍后决定"

        return prompt

    def process_consent_response(self, skill_name: str,
                                  response: str) -> Tuple[bool, str, Optional[str]]:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes file, environment-variable, and script-based capabilities but does not declare any explicit tool scope or permissions. This creates a transparency and least-privilege problem: an integrator or user may invoke a skill that can read/write local state and potentially shell out without those capabilities being formally disclosed or constrained.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation criteria are broad and include a generic concept trigger for personalization, increasing the chance of accidental activation. In this skill, activation is treated as consent to read/write persistent user data, so ambiguous triggering can translate directly into unintended data processing and storage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Defaulting to Chinese for existing profiles without fresh user opt-in can override the current user's preferred interaction mode and may cause unintended disclosure or miscommunication, especially in shared or transferred environments. This is primarily a consent and UX safety issue rather than a direct exploit primitive.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Commands like 'Activate personalization', 'Enable personalization', and especially 'personalization' are common phrases that may appear in normal discussion. Because activation unlocks profile reads/writes, vague triggers materially raise the risk of accidental invocation and silent state changes.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

md
### Pause / Resume

- **Pause**: Execute immediately, no confirmation required. Change state `status` to `paused`, retain all profile data
- **Resume**: Execute immediately, no confirmation required. Change state `status` back to `active`, re-read profile to resume personalization service

---

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
86% confidence
Finding

Resume executes immediately without confirmation and re-reads the stored profile to restart personalization. Since resuming re-enables persistent context use and data access, doing so without explicit re-consent can restart sensitive processing unexpectedly, especially after a prior pause intended for privacy.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
### Pause / Resume

- **Pause**: Execute immediately, no confirmation required. Change state `status` to `paused`, retain all profile data
- **Resume**: Execute immediately, no confirmation required. Change state `status` back to `active`, re-read profile to resume personalization service

---

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This module implements broad audit logging, defensive logging, metrics, anomaly reporting, and cross-skill activity analysis that exceed the declared purpose of generating personalized interaction guides from conversations. In a skill whose stated function is personalization, collecting and analyzing operational activity across skills creates unnecessary surveillance and data-retention surface, increasing privacy and misuse risk if the logs are accessed, exported, or repurposed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code records per-skill access counts and generates summaries for arbitrary skills, including denied access and error patterns, even though the skill is supposed to personalize user interactions. This expands visibility into other skills' operational behavior without a clear need-to-know, enabling unnecessary profiling of agent/tool usage and increasing the blast radius of any compromise or misuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Exporting and clearing logs adds administrative data-management capabilities unrelated to personalization and allows sensitive audit data to be copied or deleted from disk. These functions can be abused to exfiltrate user/skill activity records or destroy forensic evidence, especially because they are directly exposed as module methods with no authorization checks in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The export function writes potentially sensitive audit and defensive logs to an arbitrary file within the configured data directory without any confirmation, consent, or purpose check. Even with path restriction, this can facilitate quiet duplication of user-related activity records and make later unauthorized access easier if exported files are broadly readable or retained indefinitely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The clear_log function permanently deletes audit or defensive log contents without any confirmation workflow, authorization check, or tamper-evident record of the deletion. This is dangerous because an attacker or misbehaving component could erase forensic history and accountability data, hindering incident response and compliance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The changelog explicitly states that the consent prompt text was changed to Chinese, and the implementation returns Chinese-language user-facing messages and prompts. This imposes a specific language choice without providing the user a language selection or opt-in path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code writes consent state and conversation logs to disk, but the user-facing consent prompt only asks about profile access and does not clearly disclose that these decisions and related events will be stored persistently. This is a privacy transparency failure that can lead to uninformed consent and unnecessary retention of sensitive metadata.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module persists consent state and conversation-related audit records to disk and provides APIs to retrieve them, creating a broader data-retention surface than the skill’s stated personalization purpose suggests. This increases privacy risk because historical consent and interaction metadata can be accessed later, repurposed, or exposed if the skill storage area is read by other components or compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code implements a general cross-skill consent registry, status tracker, and audit system rather than a narrowly scoped consent check for this single personalization skill. That broader capability can become a privacy and trust boundary issue because it centralizes information about multiple skills’ authorization states and exposes query methods that may reveal user decisions across skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module allows its storage root to be selected from an environment variable and, in CLI mode, a user-supplied argument, then treats that path itself as trusted. An attacker who can influence either input can redirect reads, writes, deletions, and audit-log creation to arbitrary filesystem locations, defeating the intended confinement to the skill's own data directory and potentially overwriting or removing sensitive files accessible to the process.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill that generates personalized interaction guides by analyzing user conversations, but this code implements a full local persistence layer: creating, updating, deleting, and inspecting files plus maintaining a state JSON and operation log. Persistent storage may support the feature, but delete/file-info/audit-log management are broader operational behaviors not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.