Back to skill

Security audit

Math Notes KaTeX

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its renderer disables important browser isolation while processing user-controlled notes, so it should be reviewed before installation.

Install only if you are comfortable with a local renderer that launches Brave with browser sandboxing disabled. Avoid rendering untrusted notes, do not run it as root, prefer an isolated low-privilege container/user, and consider removing the sandbox-disabling flags before regular use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_note_png.js:379
Finding

Headless Brave Runs with Browser Sandboxing Disabled

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The troubleshooting guide instructs operators to run Chromium/Brave with --no-sandbox and --disable-setuid-sandbox when executing as root, but it does not warn that this removes a major browser security boundary. In this skill's context, the browser renders KaTeX/HTML and opens local files with --allow-file-access-from-files, so disabling sandboxing materially increases risk if untrusted content is ever rendered or a browser bug is exploited.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script launches Brave with --no-sandbox and --disable-setuid-sandbox while rendering untrusted, user-provided content. Even though the HTML is mostly locally generated, KaTeX output and browser parsing still process attacker-controlled input, so any browser or rendering-engine exploit would run without the normal containment layer, substantially increasing the consequence of compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The top-level description uses Russian-only wording ("конспект"), and later user-facing warnings also include Russian-only text. This imposes a language choice in natural-language interactions without offering an alternative or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The preflight lint comment and related warning context include Russian-only wording ("казусы"), reinforcing a fixed locale in user-facing messaging. Under the policy, language constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script enables --allow-file-access-from-files, which weakens local file:// isolation and can permit a locally opened page to load other local files. In this skill, attacker-controlled note content is rendered into HTML and opened by Brave; if any HTML/script injection becomes possible through KaTeX output or a browser quirk, this flag can expand impact to local file disclosure.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/render_note_png.js:379