Back to skill

Security audit

多平台文章排版发布助手 (MPA)

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a coherent article publishing helper, but its dependency install step asks users to run mutable remote shell code without verification.

Review the installer before using this skill. Prefer a pinned release, checksum-verified download, or package-manager install for mpa instead of the documented curl | sh command. Before publishing, confirm that the Markdown file, embedded images, cover image, and configured WeChat credentials are intended for that external platform.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:14
Finding

Execution of an Unverified Remote Installation Script

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 14
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Complete Code Snippet:

bash
curl -fsSL https://raw.githubusercontent.com/shijianzhong/multi-platform-articles/main/scripts/install.sh | sh

Technical Analysis

The installation instruction downloads a shell script from a personal GitHub repository and immediately pipes it into sh. The URL references the mutable main branch rather than an immutable release or commit. Consequently, the effective code executed by users can change after the Skill has been reviewed.

No version pinning, cryptographic checksum, signature verification, or inspection step is provided. The -f and -s options also reduce diagnostic visibility. Although the documentation states that the installer places mpa in ~/.local/bin, that statement does not technically constrain the remote script: it executes with all privileges and filesystem access available to the invoking user.

Direct remote execution is not required for the declared Markdown conversion and publishing functionality. A versioned, integrity-verified installation mechanism would provide the dependency without granting mutable remote content an immediate shell execution channel.

Attack Path

  1. A user requests article formatting or publication.
  2. The agent determines that the mpa command is unavailable.
  3. Following SKILL.md, the agent directs the user to execute the documented installation pipeline.
  4. The command retrieves the current install.sh content from the repository's mutable main branch.
  5. The downloaded content is passed directly to sh without integrity verification or review.
  6. If the repository, maintainer account, or delivery path supplies malicious content, arbitrary commands execute under the user's account.
  7. A malicious installer could alter the installed mpa executable, access user d ...[truncated 864 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | sh installation workflow.
  2. Distribute mpa through a reputable package registry using a fixed, documented version.
  3. If a standalone installer is necessary, reference an immutable release asset or commit rather than the mutable main branch.
  4. Publish and verify a SHA-256 checksum or cryptographic signature before execution.
  5. Separate download from execution so users can inspect the script:
    bash
    curl -fSLo install-mpa.sh "https://example.invalid/immutable/version/install.sh"
    echo "<expected-sha256>  install-mpa.sh" | sha256sum -c -
    less install-mpa.sh
    sh install-mpa.sh
    
  6. Document all files, network requests, and configuration changes performed by the installer.
  7. Ensure installation is restricted to the user's application directory and does not request elevated privileges unless a clearly justified operation requires them.
  8. Pin and verify any artifacts or dependencies subsequently downloaded by the installer.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to run a remote installation script fetched via curl and piped directly to sh, without any integrity verification, pinning, or warning about execution risk. This creates a direct remote code execution path: if the upstream content or transport trust is compromised, arbitrary shell commands will execute on the user's machine.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The use of '| sh' is a classic chaining-abuse pattern because it converts downloaded network content directly into shell execution with no review boundary. In a skill that may be auto-invoked from broad publishing-related prompts, this materially increases the risk of users being funneled into unsafe command execution.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

🔧 前置要求 (依赖安装)

如果用户的终端中没有 mpa 命令,请首先指导用户在终端中执行以下命令安装底层依赖:

bash
curl -fsSL https://raw.githubusercontent.com/shijianzhong/multi-platform-articles/main/scripts/install.sh | sh

安装完成后,mpa 会自动配置在用户的 ~/.local/bin 中。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description uses broad terms like '排版/主题/发布公众号/草稿/小红书/头条', which can cause the skill to activate in situations broader than intended. Overbroad invocation increases the chance that users are steered into installation or publishing workflows unexpectedly, including workflows that perform network actions or request sensitive credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

文件整体说明内容均以中文呈现,且围绕调用条件与操作指令未说明是否支持其他语言或允许用户选择语言。若组织要求不得在未获用户选择的情况下强制特定语言,这种默认单一语言行为构成自然语言策略风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes uploading article content and images to a third-party platform but does not clearly warn users that local Markdown content, embedded images, and generated cover assets will be transmitted externally. This can lead to accidental disclosure of sensitive drafts, unpublished content, or metadata if users do not understand the network behavior.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
99% confidence
Finding

Fetching and executing an external script from a raw GitHub URL delegates trust to mutable remote content outside the skill itself. In this skill's context, the command is presented as the first installation step, making compromise especially dangerous because users are encouraged to execute it before understanding the tool's behavior.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

🔧 前置要求 (依赖安装)

如果用户的终端中没有 mpa 命令,请首先指导用户在终端中执行以下命令安装底层依赖:

bash
curl -fsSL https://raw.githubusercontent.com/shijianzhong/multi-platform-articles/main/scripts/install.sh | sh

安装完成后,mpa 会自动配置在用户的 ~/.local/bin 中。

Static analysis

No suspicious patterns detected.