Back to skill

Security audit

Epiphany Collector

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it can automatically publish user learning notes with a bearer token to a configured server without clear per-submission consent or HTTPS enforcement.

Install only if you intend your agent to publish structured learning notes to the configured organization server. Use an HTTPS endpoint, protect the token file, treat submissions as visible to the learning circle, and require the agent to ask before sending anything that was not an explicit publish request. Do not submit secrets, private reflections, customer data, internal debugging details, or other sensitive material.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/submit.js:35
Finding

Bearer Token and Submitted Content Can Be Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/submit.js, lines 35 and 54–68
Vulnerability Type: Plaintext transmission of sensitive information
Risk Level: High

Vulnerable Code

javascript
const API_BASE = config.api_base || 'http://localhost:18999';
javascript
function apiRequest(method, pathname, body) {
  return new Promise((resolve, reject) => {
    const url = new URL(pathname, API_BASE);
    const isHttps = url.protocol === 'https:';
    const transport = isHttps ? https : http;

    const options = {
      hostname: url.hostname,
      port: url.port || (isHttps ? 443 : 80),
      path: url.pathname,
      method,
      headers: {
        'Content-Type': 'application/json',
        ...(TOKEN ? { 'Authorization': `Bearer ${TOKEN}` } : {}),
      },
    };

Technical Analysis

The client supports both HTTPS and plaintext HTTP for its configured API endpoint. It does not enforce HTTPS before placing the reusable bearer token in the Authorization header. Submission requests also carry the user-provided title, thoughts, related URL, and display name.

Consequently, if api_base uses the http: scheme, the credentials and request body are transmitted without transport encryption or server authentication. Documentation merely recommends HTTPS rather than making it mandatory. An empty api_base also silently selects the plaintext http://localhost:18999 fallback.

Attack Path

  1. The user configures an http:// API endpoint, or leaves api_base empty and triggers the localhost fallback.
  2. The client constructs a request using Node.js's plaintext http transport.
  3. The client includes the bearer token in the Authorization header.
  4. For a submission, the client also sends the title, thoughts, URL, and display name in the request body.
  5. A network-positioned attacker, an intercepting proxy, or an untrusted service listening on the fallback loc ...[truncated 899 chars]
Remediation
View remediation

Remediation Suggestions

  1. Validate api_base during startup and reject an empty value instead of silently falling back to an HTTP endpoint.
  2. Require the https: scheme for all non-loopback API destinations.
  3. If plaintext HTTP is needed for local development, permit it only for explicitly validated loopback hosts such as localhost, 127.0.0.1, and ::1, and require an explicit development-only opt-in.
  4. Reject unsupported URL schemes and malformed endpoint configurations before constructing any request.
  5. Do not attach the bearer token to the health-check endpoint unless that endpoint requires authentication.
  6. Update the documentation to state that HTTPS is mandatory for production rather than merely recommended.
  7. Consider certificate or public-key pinning in centrally managed deployments where the API identity is fixed.
  8. Rotate any token that may previously have been transmitted over plaintext HTTP.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill markets itself as a Feishu learning-circle client, but the documentation explicitly allows sending token-authenticated POST requests to an arbitrary user-configured api_base. That mismatch matters because users may trust it as a narrow Feishu integration while it actually functions as a generic exfiltration-capable HTTP client carrying a bearer token and user-supplied content to any endpoint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the agent to act whenever a human shares learning insights in natural language, without requiring explicit consent or a clear submission trigger. In practice this can cause unintended transmission of sensitive or internal information that a user meant only for discussion, especially because the target is a shared pool visible to others' agents.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Mandating submission 'every time' a user shares心得 creates an overbroad automation rule with no exceptions for ambiguity, confidentiality, or user intent. That increases the chance of privacy leakage, accidental publication to a shared document, and propagation of sensitive internal material into downstream indexing or literature-enrichment workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module comment claims that no personal information is collected, but the script can transmit user-identifying data through the --from argument or config.default_from field. This is a security/privacy issue because users may rely on the stated guarantee and unknowingly send identifying metadata to the configured server along with their submission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This is a natural-language policy issue because the skill presents its usage, safety notes, and operational guidance only in Chinese. The file does not offer an alternate language or indicate that the Chinese-only behavior is a documented, justified locale constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.