Back to skill

Security audit

aaa

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned, but it embeds a real university account identifier and a user-specific executable path while enabling Feishu table writes, so users should review it before installing.

Install only after removing the hardcoded SZU username and replacing the fixed Windows lark-cli path with normal command discovery or an environment-based path. Before each run, confirm the Feishu Base link, target table, whether data should be appended or overwritten, and the language/database scope.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Hardcoded University Account Identifier in Reusable Skill Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:20
Vulnerability Type: Hardcoded personal authentication identifier
Risk Level: Medium

Complete Code Snippet:

markdown
- Default SZU username may be prefilled as `2410032057` for this user's local workflow, but keep the password runtime-only and do not persist it into the skill.

Technical Analysis

The reusable Skill contains a specific Shenzhen University username and explicitly permits agents to prefill it during authentication. Although the identifier is not a password, it is authentication-related personal data and should not be embedded in a distributable Skill.

Any user who can inspect or invoke the Skill can recover the identifier. Because the instruction is operational rather than merely descriptive, an agent may also submit authentication attempts under the disclosed identity when another user runs the workflow. The surrounding protections against storing passwords do not mitigate disclosure or misuse of the hardcoded username.

Attack Path

  1. An unauthorized party obtains or invokes the Skill package.
  2. The party reads the hardcoded university username from SKILL.md, or allows the agent to follow the prefill instruction.
  3. The workflow opens the Shenzhen University authentication portal.
  4. The disclosed username is entered automatically or manually.
  5. The party uses the identifier for account enumeration, targeted phishing, credential-stuffing attempts, or repeated failed authentication attempts.
  6. Depending on identity-provider controls, these attempts may disclose account validity or cause temporary account lockout.

Impact Assessment

The issue discloses a personal account identifier and facilitates targeted attacks against the associated university account. It does not directly expose a password or grant authenticated privileges. Successful compromise would still require an additional authentication factor or weakn ...[truncated 350 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the numeric username from the Skill and its documentation.
  • Ask the user to provide the account identifier at runtime only when authentication is required.
  • If local reuse is necessary, retrieve the identifier from an explicitly configured environment variable or operating-system credential manager.
  • Do not log, serialize, or write the runtime identifier into repository files, generated payloads, or temporary files.
  • Add a repository secret and personal-data scanning rule to detect institution identifiers and other authentication metadata before publication.
  • Preserve the existing requirement to pause for passwords, captchas, verification codes, and multifactor authentication.

T09 · Insecure Skill Coding Practices

Note
Location
references/playbook.md:418
Finding

Hardcoded User-Specific Windows Profile Path

Content
View full analysis

Vulnerability Details

File Location: references/playbook.md:418
Vulnerability Type: Embedded local user information and non-portable command path
Risk Level: Low

Complete Code Snippet:

powershell
C:\Users\32530\AppData\Roaming\npm\lark-cli.cmd auth status

Technical Analysis

The playbook embeds a specific Windows profile directory in an executable command. This discloses a local account name or identifier and couples the workflow to one user's filesystem layout.

An agent following the instruction on another system may probe or execute a binary from that fixed location. The project does not modify or replace the referenced executable, so there is no evidence of tool hijacking within the audited package. Nevertheless, trusting a hardcoded user-writable path instead of resolving the authenticated user's installation is an insecure and non-portable practice.

Attack Path

  1. An agent follows the PowerShell fallback command from the playbook.
  2. It attempts to execute lark-cli.cmd from the hardcoded C:\Users\32530 profile.
  3. On a shared or reused Windows system, that path may belong to another local user or contain an unexpected executable.
  4. If the invoking process can access the path and the file has been replaced or tampered with outside this project, attacker-controlled commands could execute with the invoking process's privileges.
  5. Even when execution is impossible, publishing the path exposes a user-specific local identifier and causes workflow failure on other systems.

Impact Assessment

The confirmed impact is disclosure of a local Windows profile identifier and reduced portability. The package itself contains no malicious replacement binary and does not grant elevated permissions.

Conditional code execution would require an attacker to control the referenced external lark-cli.cmd path and the victim process to execute it. In that scenario, commands would run with th ...[truncated 106 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the user-specific path with environment-based resolution, such as:

    powershell
    & "$env:APPDATA\npm\lark-cli.cmd" auth status
    
  • Prefer standard command discovery before using a fallback path:

    powershell
    Get-Command lark-cli.cmd -ErrorAction Stop
    
  • Verify that the resolved executable is a regular file in an expected installation directory before invoking it.

  • Avoid embedding local usernames, home directories, workstation identifiers, or other user-specific filesystem details in reusable documentation.

  • Where practical, document installation and integrity-verification procedures for lark-cli rather than assuming one global npm installation path.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
# WOS -> 飞书多维表格执行手册

这个手册给 `wos-feishu-literature` Skill 使用。目标是把 WoS 文献检索、深圳大学登录、筛选、摘要提取、飞书本地 CLI 写入,压成一套稳定可复用的流程。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/playbook.md (reported line 1)May include surrounding context.

md
# WOS -> 飞书多维表格执行手册

这个手册给 `wos-feishu-literature` Skill 使用。目标是把 WoS 文献检索、深圳大学登录、筛选、摘要提取、飞书本地 CLI 写入,压成一套稳定可复用的流程。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill declares it should trigger whenever the user mentions WoS/Web of Science, which is broader than the actual task scope of literature retrieval and Feishu writeback. This can cause unintended activation in unrelated conversations, increasing the chance of inappropriate workflow execution, credential-handling prompts, or accidental data operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Setting English as the default language without user confirmation can silently bias search results and exclude relevant non-English literature. In an academic retrieval workflow this can degrade completeness and correctness, especially for Chinese-language or multilingual review tasks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description and default prompt normalize writing data into Feishu Base, including use of a local CLI, without any user-facing warning or confirmation boundary around the external write operation. This is dangerous because an agent could perform side-effecting actions on local or connected systems unexpectedly, leading to unintended data creation, overwrites, or leakage of sensitive research topics into Feishu.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The playbook states '默认建议 English', which imposes a language preference as the default rather than offering a user choice first. This is a natural-language locale policy concern because the skill biases output toward a specific language without explicit opt-in or a documented compliance justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The default prompt describes activation as using the skill to search literature for "my topic," which is fairly broad and does not define clear boundaries or exclusions for when this skill should be invoked. The file provides no negative examples or narrower trigger scope to reduce accidental matching in general research-related requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.