Back to skill

Security audit

DeepTutor 轻量辅导台

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent tutoring aid and not clearly malicious, but it needs review because it persistently stores student profiles and uses raw student IDs as file paths.

Review before installing. Use only with learners who have agreed to persistent profiling, avoid real names for student_id, keep tutor_memory out of shared or public workspaces, and add validation so student_id cannot contain path separators, '..', absolute paths, or other unsafe filename characters. Also add clear inspect/delete/export instructions for stored learner records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:223
Finding

Unsanitized Student Identifier Enables Path Traversal

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 223-255
Vulnerability Type: Path traversal through a user-controlled filename
Risk Level: Medium

Vulnerable Code

markdown
1. **定学习者身份**:`student_id`?检查 `tutor_memory/<student_id>.md`:存在→载 L2/L3 跳步骤1;不存在→新建(L3 空模板 + L2 表头 + p 初始化 0.5)。
markdown
3. **写文件**:Edit/Write 回 `tutor_memory/<student_id>.md`。

The same unsafe path convention is initially defined at line 46:

markdown
| **L2 掌握度矩阵** | 按知识点(KC)聚合:掌握概率 p + 状态 + 错误类型分布 + 证据 + 最近更新 | `tutor_memory/<student_id>.md` | 长期累积,随答随更新 |

Technical Analysis

The Skill obtains student_id from the user and interpolates it directly into a filesystem path used for both reading and writing. It does not require validation, canonicalization, separator rejection, or verification that the resolved path remains under tutor_memory/.

A crafted identifier containing traversal sequences could therefore resolve outside the intended profile directory. For example, ../../notes would produce:

text
tutor_memory/../../notes.md

Whether exploitation succeeds depends on the host Agent's filesystem permissions and any path-containment controls enforced by its file tools. The Skill itself provides no protective control.

Attack Path

  1. An attacker invokes the Skill and supplies a malicious student identifier, such as ../../existing-file.
  2. The Agent constructs tutor_memory/../../existing-file.md.
  3. During initialization, the Agent checks whether that resolved path exists and may read it as though it were a student profile.
  4. During session closeout, the Agent follows the instruction to write updated profile data to the same path.
  5. If the host permits access, a Markdown file outside tutor_memory/ may be read, created, or overwritten.

Impact Assessment

Successful exploitation could provide unauthorized read or write access to files reachable by the Agent's filesystem permissions. Potential consequences inclu ...[truncated 457 chars]

Remediation
View remediation

Remediation Suggestions

  1. Restrict student identifiers to a conservative allowlist, such as:

    regex
    ^[A-Za-z0-9_-]{1,64}$
    
  2. Explicitly reject:

    • .. path components.
    • Forward and backward slashes.
    • Absolute paths.
    • Drive prefixes.
    • Null bytes and control characters.
    • Encoded forms that decode into path separators or traversal components.
  3. Resolve and canonicalize the destination path before every read or write, then verify that it remains beneath the canonical tutor_memory/ directory.

  4. Generate an opaque internal filename, such as a UUID or a cryptographic hash of the validated identifier, rather than using raw user input as a filename.

  5. Refuse the operation if validation or containment verification fails; do not attempt to normalize an unsafe identifier silently.

  6. Apply least-privilege filesystem permissions so the Agent can access only the dedicated profile directory where practical.

  7. Add tests covering Unix and Windows traversal forms, absolute paths, mixed separators, encoded separators, excessively long identifiers, and filename collisions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is long, generic, and includes common educational phrases such as '个性化辅导', '长期陪学', and '我的学生档案', which increases the chance of accidental or overly broad invocation. In a skill that maintains persistent learner memory and can route into other workflows, unintended activation can lead to inappropriate collection or reuse of student-profile data and execution of tutoring-specific behaviors when the user did not explicitly request them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README explicitly states that student memory is stored in files under tutor_memory/ and must be carried across workspaces, but it does not present a clear user-facing warning, consent flow, retention policy, or deletion guidance. Because this skill is designed for long-term personalized tutoring and stores learner profiles, mastery probabilities, and weakness history, silent persistence creates a meaningful privacy and cross-session data exposure risk, especially in shared or transferred workspaces.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs persistent storage of detailed learner memory across sessions, including weaknesses, preferences, and interaction history. This creates a standing privacy risk because sensitive educational profiles accumulate over time and may be accessed, disclosed, or reused beyond the user's expectation, especially if identity binding and consent are weak.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown instructs the skill that chats must avoid LaTeX and use specific Chinese textbook conventions, and that conclusions must use 人教版 as the sole authoritative standard. This imposes a language/locale-specific constraint on users without offering a choice or opt-in, which matches the policy concern for forced language/locale behavior.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Reading back stored mastery snapshots and learner records to the user increases the chance of exposing accumulated personal data to the wrong person or in the wrong context. If student_id selection, session isolation, or authentication is imperfect, the feature could disclose historical performance, weaknesses, and preferences from prior sessions.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow requires writing persistent student memory files containing cumulative profiles, error patterns, and evidence from sessions, establishing a durable data-retention channel. Persistent local files increase risk of over-collection, unintended disclosure, and stale sensitive records remaining accessible long after the tutoring need has passed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The test prompt is broad enough to overlap with ordinary tutoring requests, which can cause the skill to activate in contexts where the user did not clearly intend this specific long-term memory and personalized tutoring workflow. In this skill, unintended activation is more sensitive because it may trigger learner profiling, memory writes, or pedagogical steering rather than a one-off answer.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The memory-setting prompt uses natural language that broadly asks the system to 'remember' student details without clearly defining consent, scope, or when the memory subsystem should engage. In a tutoring skill built around persistent learner profiles and weakness tracking, this increases the risk of over-collection, unintended retention, or accidental activation of stored-profile behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.