Back to skill

Security audit

ChatDOC Studio--KnowledgeMate

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate ChatDOC helper, but it uploads local documents to a third-party API with a bearer key and has scoping weaknesses users should review first.

Install only if you are comfortable sending the selected PDF/DOC/DOCX contents to PaodingAI/ChatDOC Studio. Use a narrowly scoped API key, upload explicit files or carefully curated folders, avoid regulated or confidential documents unless approved, and prefer a pinned or verified install source.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Remote Package Execution During Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/knowledge-mate.mjs:204
Finding

Bearer-Authenticated API Path Injection Through Unvalidated Identifiers

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
node scripts/knowledge-mate.mjs upload-and-create \

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares access to environment variables and implicitly requires network access, but it does not specify an explicit tool scope such as permissions or allowed-tools. In an agent environment, that weakens enforcement boundaries and can allow the skill to be invoked with broader capabilities than users or operators expect, especially since it reads a bearer API key and uploads local files to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages uploading local PDF/DOC/DOCX files to a remote API but does not clearly warn users that document contents leave the local environment and are transmitted to a third-party service. This creates a meaningful privacy and data-handling risk because users may upload sensitive internal or regulated documents without informed consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
76% confidence
Finding

Using npx skills add PaodingAI/skills without a pinned version makes installation non-reproducible and exposes users to supply-chain risk if the upstream package changes or is compromised. A later malicious or broken release could be fetched at install time without any review, altering skill behavior or introducing data exfiltration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads local PDF/DOC/DOCX files and uploads their full contents to a third-party remote service, but it provides no explicit runtime disclosure, confirmation, or data-handling warning before transmission. In an agent-skill context, this increases the risk of unintentional exfiltration of sensitive local documents because automation may invoke the upload path with broad directory inputs and users may not realize content leaves the local environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The client reads PAODINGAI_API_KEY from the environment, which is a sensitive credential access path covered by the warning requirement for code files. The code explains that the variable is required if absent, but it does not provide a user disclosure about credential use or handling when the skill runs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.