Back to skill

Security audit

Knowledge Habit Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate local habit tracker wrapper, but its installer fetches and executes mutable external Node/Electron code that was not bundled for review.

Review this before installing because the skill package is mainly an installer wrapper. Only install if you trust the GitHub repository and are comfortable with npm scripts running under your user account. Safer installation would pin a reviewed release or commit, verify a checksum or signature, and avoid npm install fallbacks or lifecycle scripts where possible.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
install.sh:41
Finding

Mutable Remote Payload Retrieval and Execution During Installation

Content
View full analysis
/dev/null || npm install --silent else echo "📦 安装npm依赖..." npm install --silent fi ``` ### Technical Analysis The installer clones the current default branch of an external GitHub repository without selecting an immutable commit, verifying a release signature, or validating a cryptographic checksum. The effective application payload can therefore change after this Skill package has been reviewed. After obta ...[truncated 2656 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 232)May include surrounding context.

sh
if [ ! -f "$SKILL_DIR/.env.example" ]; then
    cat > "$SKILL_DIR/.env.example" << 'EOF'
# 知识习惯追踪器环境配置
# 复制此文件为 .env 并修改配置

# Web服务配置
PORT=3000

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire skill description is presented only in Chinese, which can constitute a language/locale policy issue when no alternative language option or opt-in is provided. The file does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares a shell-based installer (./install.sh) and requires bash, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where a host agent may execute shell commands without clear, least-privilege constraints or user-visible approval boundaries. In this skill’s context, the risk is elevated because installation scripts can perform arbitrary local actions beyond the privacy-focused claims in the description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing help text is entirely in Chinese, and the status/backup messages continue this pattern. Under the policy rule, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest emphasizes a privacy-first, offline-first habit tracker, but this installer offers cloning the application from GitHub over the network as a built-in path. While installation-time network access can be practical, it goes beyond a purely offline-first behavior as described and should be explicitly reflected in the skill's operational description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The generated .env.example defines DATA_DIR, BACKUP_DIR, and backup retention settings, which indicate filesystem-based persistence and backup behavior. This conflicts with the later statement that all habit data is by default stored in browser localStorage and only feedback logs are written to disk when a local service is started, creating a documentation-to-code intent mismatch.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · install.sh (reported line 239)May include surrounding context.

sh
HOST=127.0.0.1

# Electron配置
ELECTRON_DISABLE_SECURITY_WARNINGS=false

# 开发模式
NODE_ENV=development

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
79% confidence
Finding

The installer generates .env.example with NODE_ENV=development as the default suggested setting. If users copy this file into production-like use, the application may run with development behaviors such as verbose errors, debug output, weaker hardening, or altered dependency/runtime behavior, increasing information exposure and reducing security posture.

Content

Scanner excerpt · install.sh (reported line 242)May include surrounding context.

sh
ELECTRON_DISABLE_SECURITY_WARNINGS=false

# 开发模式
NODE_ENV=development
DEBUG=knowledge-habit-tracker:*

# 数据目录

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script's comments, prompts, status messages, and usage instructions are written entirely in Chinese, including all generated helper scripts. This imposes a specific language on users without opt-in or an alternative locale path, which matches the language/locale policy violation criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest is a JSON file, so SQP-3 applies. The description is entirely in Chinese and does not indicate that other languages are supported or that Chinese is a required locale, which can violate a language/locale policy requiring user choice or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's user-facing echo messages are entirely in Chinese, which imposes a specific language on all users. This is a natural-language policy concern because the file does not offer an opt-in, fallback, or explanation that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script prints all user-facing status messages in Chinese, which imposes a specific language on users without any opt-in or indication that the skill is intended only for a Chinese-speaking audience. This matches the policy category for language or locale constraints expressed in natural-language strings.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.