T08 · Insecure Dependencies
- Location
scripts/notebooklm.sh:1- Finding
Dynamic Execution of an Unpinned npm Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a Chinese content-conversion workflow, but it includes paywall-bypass instructions, raw cookie handling, and unsafe dependency installation patterns that need careful review before use.
Install only after reviewing the paywall and cookie workflows. Do not paste or export website cookies into chats, commands, or config files; prefer user-provided text/files or official authorized exports. Pin and verify dependencies before running the scripts, and assume content uploaded through NotebookLM, Feishu, IMA, or GetNote may leave your local machine.
scripts/notebooklm.sh:1Dynamic Execution of an Unpinned npm Package
references/installation-cn.md:26Unpinned and Ambiguous Dependency Installation Instructions
scenarios/04-caixin-to-podcast.md:40Unsafe Workflow for Handling Reusable Session Cookies
描述将该技能定位为一个面向最终用户的 NotebookLM 内容转换/生成工具,核心承诺是接收多种中文内容源并生成播客、PPT、思维导图、报告等产物。但代码并没有实现这类用户功能,而是一个内部测试脚本,用于自动化验证 NotebookLM 各生成按钮是否可用。它创建测试 notebook、插入固定文本、轮询页面文案判断是否开始生成、处理每日限额、截图并写出 result.json。虽然代码确实接触到了思维导图、音频、视频、报告等生成类型,表面上与描述中的部分产物类别重合,但其主要目的明显是“功能验证/回归测试”,不是“根据用户输入进行内容生产”。此外,描述中强调的中文内容源接入、模板场景、与 IMA/飞书集成、本地 LLM 兜底等关键能力在代码中均未出现,因此属于明显的描述与实际行为不符。
描述的核心方向与代码有部分重合:都是围绕 NotebookLM 导入内容并生成衍生内容。但声明明显更宽,承诺了多平台内容一键导入、模板化场景、外部工具联动以及本地 LLM 兜底,而代码实际只是一个 NotebookLM Web 自动化脚本,用于打开已有笔记本、上传粘贴文本、触发生成并下载结果。最主要的不一致在于声明强调多来源采集/联动能力,代码并未实现;同时代码的实际输入形式比描述窄得多。因此应判定为描述与行为存在实质性不匹配。
描述强调的是一个面向中文内容加工的 NotebookLM 增强工具,核心能力应是接收多种中文内容来源并产出多种内容形式。实际代码并未实现这些用户功能,而是一个内部/测试性质的 Playwright 全链路检查脚本,用固定文本验证 NotebookLM 网站的创建、添加来源和触发思维导图流程。它访问的是 NotebookLM 网页与本地 storage-state 文件,主要目的是自动化验收而非内容转换。两者主用途和能力明显不一致,因此应判定为描述与行为不匹配。
Referenced artifact was not completely inspected
> - 上传改用:`scripts/notebooklm-playwright.js upload-text "<notebook标题>" "<source标题>" "<content>"`
Referenced artifact was not completely inspected
> - 上传改用:`scripts/notebooklm-playwright.js upload-text "<notebook标题>" "<source标题>" "<content>"`
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.workbuddy/skills/ContentForge
# 协同 Skill 如不再需要,另删 lark-master / ima-skill
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.workbuddy/skills/ContentForge
# 协同 Skill 如不再需要,另删 lark-master / ima-skill
This reference document goes beyond legitimate content transformation and explicitly operationalizes paywall-circumvention strategies, including proxying, user-agent spoofing, cache/archive access, and local fetch fallbacks. In this skill context, that is dangerous because the skill is marketed for converting user-provided content, not for obtaining restricted content; embedding these instructions enables unauthorized access attempts and expands abuse capability.
The document includes anti-paywall and anti-scraping methods such as bot UA disguise, generic disguise, mirror usage, and Playwright-style simulation to evade access controls. These are not justified by the stated skill purpose and materially increase the risk that the agent will bypass publisher restrictions or trigger platform abuse, especially when automated in a workflow.
The scenario explicitly frames the workflow as '绕付费墙抓取' for paid Caixin content, which goes beyond ordinary format conversion and into paywall circumvention. Embedding bypass guidance in a reusable agent skill operationalizes unauthorized access and creates legal, policy, and abuse risk well outside the declared content-transformation purpose.
The scenario discusses paywall bypass and authenticated access techniques without a clear safety warning about handling cookies or other authentication data. In a skill context, omission of such warnings normalizes dangerous secret-sharing behavior and increases the likelihood users expose reusable session credentials.
The ordered retrieval strategy normalizes a ladder of increasingly intrusive methods to obtain restricted article text, including subscriber-session use, alternate mirrors, app screenshot OCR, and manual copying. Packaging these as a standard decision tree makes unauthorized acquisition repeatable and lowers the barrier for abuse at scale.
Instructing users to hand over authenticated Caixin cookies enables the system to impersonate a subscriber session and access full paid content. Cookies are sensitive authentication artifacts; collecting or injecting them risks account takeover, session hijacking, unauthorized access, and downstream misuse far beyond this single article.
The skill directly instructs users to provide authenticated site cookies so the system can retrieve subscriber-only content. This is a textbook unsafe secret-handling pattern that exposes reusable credentials and enables unauthorized access under the user's identity, with significant security and compliance consequences.
This configuration is explicitly dedicated to prioritizing methods for accessing paywalled content, including proxying, bot impersonation, spoofing, and browser automation. That materially exceeds a normal content-conversion skill’s stated purpose and creates a built-in path to unauthorized acquisition of restricted content.
The overseas workflow enumerates multiple circumvention techniques such as proxy access, bot UA spoofing, generic disguise, Google cache, and Playwright-based fetching. These are classic paywall-evasion methods and enable the agent to retrieve content in ways designed to avoid publisher access controls.
Methods such as bot UA spoofing, proxying, referer/AMP/EU-IP disguise, and similar techniques are specifically designed to masquerade as a different client or context to obtain restricted material. In a content-ingestion skill, this is especially dangerous because it operationalizes deceptive access at scale.
The domestic workflow solicits subscriber cookies and recommends mirror sources to obtain content, which introduces both credential-handling risk and unauthorized content acquisition risk. Even if framed as convenience, this can expose sensitive session tokens and facilitate access outside intended publisher controls.
Accepting user-provided login cookies without warnings or isolation is a serious credential-security issue because cookies often function as bearer tokens for paid accounts. Exposure, logging, reuse, or mishandling of those tokens could let the system or others impersonate the user and access account data or subscriptions.
The skill description and usage instructions are presented entirely in Chinese and explicitly target processing '任何中文内容', which indicates a language-specific constraint. The file does not offer an opt-in, alternative locale, or justification that this is a region-specific compliance or localization-only tool.
The skill describes workflows that rely on network access, browser automation, and CLI/script execution, but it does not declare any explicit tool scope or allowed-tools boundary. This creates an authorization and review gap: an operator may not realize the skill can reach external services or invoke shell-capable components, increasing the chance of unintended data exfiltration or unsafe execution.
The statement「生成结果默认中文」sets a language default that may override user preference, and the document does not mention any option to select another language. This is a natural-language policy concern because it imposes a locale/language behavior without explicit user opt-in.
The trigger phrases are broad enough to match ordinary requests such as '做成 PPT' or '深度分析这篇', which can cause the skill to activate in contexts the user did not intend. In a skill that may fetch remote content, use browser automation, or send data to external services, overbroad invocation increases the risk of unintended data handling and tool execution.
The documentation explicitly discusses configuring network/proxy behavior to access and process paywalled or access-restricted content from sources such as 财新 and 知识星球, which goes beyond a narrow 'content conversion' skill and can enable unauthorized scraping workflows. In this skill context, that is more dangerous because the surrounding guidance operationalizes access and anti-blocking behavior, increasing the likelihood of misuse against restricted services.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
通常通过 Skill Hub 一键装或 git clone:
mkdir -p ~/.workbuddy/skills/
cd ~/.workbuddy/skills/
git clone https://github.com/SirKayZh/ContentForge
cd ContentForge
No suspicious patterns detected.