Back to skill

Security audit

zijiyong

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about its WoS-to-Feishu workflow, but it embeds a specific university login identifier and uses a broad trigger for actions that can touch login sessions and modify Feishu data.

Review before installing. Remove the embedded SZU username, require explicit user confirmation before any institutional login or Feishu writeback, and verify the target Feishu Base/table before allowing lark-cli to create, update, or upsert records. Do not store passwords, SMS codes, captchas, or session tokens in the skill or generated files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:19
Finding

Hardcoded Institutional User Identifier

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 19
Vulnerability Type: Hardcoded sensitive account metadata
Risk Level: Low

Complete Code Snippet:

markdown
- Default SZU username may be prefilled as `2410032057` for this user's local workflow, but keep the password runtime-only and do not persist it into the skill.

Technical Analysis

The Skill embeds a specific Shenzhen University username directly in its instructions. Although this is not a password and the surrounding instructions prohibit storing passwords and verification codes, an institutional account identifier is still sensitive account metadata that should not be distributed with a reusable Skill.

When the Skill is loaded, an agent may automatically prefill this identifier on the documented university authentication page. This leaks information associated with a particular user and creates a risk that unrelated users will initiate authentication attempts under the wrong account. The identifier may also assist account enumeration, targeted phishing, or social-engineering activity when combined with the disclosed institutional affiliation and login route.

Attack Path

  1. An attacker or unrelated operator obtains or loads the Skill package.
  2. They inspect SKILL.md and recover the embedded institutional username.
  3. They associate the identifier with the Shenzhen University authentication route documented by the Skill.
  4. They may use it for account-enumeration attempts, targeted phishing, social engineering, or repeated authentication attempts.
  5. Separately, a legitimate agent following the instructions may prefill the identifier for another user, causing accidental use or disclosure of the account identity.

Impact Assessment

The issue does not directly disclose a password, MFA token, authenticated session, or system privilege. It therefore does not independently grant account access. Its scope ...[truncated 319 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the literal username from SKILL.md.
  2. Ask the user to provide their institutional username at runtime when authentication is required.
  3. Keep the username, password, MFA codes, and session tokens out of the Skill repository, generated files, command history, and logs.
  4. If account reuse is necessary, retrieve the username from a user-controlled credential manager or environment-specific configuration that is excluded from version control.
  5. Require explicit confirmation before filling any login identifier so that a reusable Skill cannot silently authenticate under another person's identity.
  6. Review repository history and distributed copies for the identifier and remove it where practical.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
# WOS -> 飞书多维表格执行手册

这个手册给 `wos-feishu-literature` Skill 使用。目标是把 WoS 文献检索、深圳大学登录、筛选、摘要提取、飞书本地 CLI 写入,压成一套稳定可复用的流程。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/playbook.md (reported line 1)May include surrounding context.

md
# WOS -> 飞书多维表格执行手册

这个手册给 `wos-feishu-literature` Skill 使用。目标是把 WoS 文献检索、深圳大学登录、筛选、摘要提取、飞书本地 CLI 写入,压成一套稳定可复用的流程。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description contains broad invocation phrases like reusable workflow, academic literature collection, and SSCI-focused retrieval, which extend beyond a tightly scoped task definition. Broad routing criteria can cause misfires, invoking a workflow that performs browser automation, institutional login, and local CLI writeback when a simpler or safer response would have been appropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs automatic activation whenever the user mentions generic WoS terms, without requiring clear intent to perform the specific workflow. This can cause the agent to enter a high-privilege academic-login and data-writeback flow in contexts where the user only mentioned Web of Science incidentally, increasing the risk of inappropriate tool use and unintended actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file defines activation conditions, so SQP-1 applies. The rule says to use the playbook whenever the user merely mentions “wos” or its variants, which can collide with incidental mentions rather than an actual request to perform this workflow; the trigger scope is not constrained by intent or negative examples.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

SQP-3 applies to all file types, including markdown. The document states the default recommendation is English for language-limited searching, which forces a locale/language preference unless the user overrides it; no opt-in or neutral default is offered at that point.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

In the default retrieval plan, the skill hard-codes English as the default language. This is a natural-language policy issue because it constrains language/locale behavior without explicit user choice or documented justification for a region- or compliance-specific need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This summary section reiterates that the workflow should default to English. Repeating the same language constraint in the operative default strategy reinforces a mandatory language preference without opt-in, which matches the policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.