Back to skill

Security audit

Content Forge

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Chinese content-conversion workflow, but it includes paywall-bypass instructions, raw cookie handling, and unsafe dependency installation patterns that need careful review before use.

Install only after reviewing the paywall and cookie workflows. Do not paste or export website cookies into chats, commands, or config files; prefer user-provided text/files or official authorized exports. Pin and verify dependencies before running the scripts, and assume content uploaded through NotebookLM, Feishu, IMA, or GetNote may leave your local machine.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
scripts/notebooklm.sh:1
Finding

Dynamic Execution of an Unpinned npm Package

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/installation-cn.md:26
Finding

Unpinned and Ambiguous Dependency Installation Instructions

Content
View full analysis
/dev/null || true # yt-dlp (required for Bilibili/YouTube video download in scenario 5) pip3 install yt-dlp # ffmpeg (audio extraction; use brew install ffmpeg on macOS) # Linux: sudo apt install ffmpeg # Node.js dependencies (required for scenario 5 html2pptx) npm install # if package.json exists ``` ## 3. Install NotebookLM CLI (if path A is needed) ```bash pip install notebooklm-cli # or npm install -g @notebooklm/cli ``` ``` Associated instructions also recommend unpinned global installations in `references/troubleshooting.md`, lines 95-98: ```bash # Global installation if missing npm install -g playwright @playwright/test npx playwright install chromium npm install -g sharp ``` ### Technical Analysis The installation instructions retrieve executable packages without exact version constraints or integrity verification. They also offer two different NotebookLM package identities—`notebooklm-cli` and `@notebooklm/cli`—without establishing which publisher or package is authoritative. The audited project structure does not contain the referenced `requirements.txt`, `package.json`, or lockfiles. Consequently: - Dependency versions are not reproducible. - Package integrity is not anchored to reviewed hashes. - Users may install a mutable package version substantially different from the version expected by the Skill. - Ambiguous package names increase the risk of dependency confusion or typosquatting. - Global npm installation broadens the impact to other projects and user sessions. - `2>/dev/null || true` suppresses dependency installation errors, allowing execution to continue with an ...[truncated 1662 chars]
Remediation
View remediation
/dev/null || true`. Treat installation failures as errors and report them clearly. 7. Use `npm ci` rather than `npm install` once a lockfile is committed. 8. Review package lifecycle scripts and consider `--ignore-scripts` where installation scripts are not required. 9. Document a supported dependency update process that includes security review and lockfile changes. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scenarios/04-caixin-to-podcast.md:40
Finding

Unsafe Workflow for Handling Reusable Session Cookies

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (64)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

描述将该技能定位为一个面向最终用户的 NotebookLM 内容转换/生成工具,核心承诺是接收多种中文内容源并生成播客、PPT、思维导图、报告等产物。但代码并没有实现这类用户功能,而是一个内部测试脚本,用于自动化验证 NotebookLM 各生成按钮是否可用。它创建测试 notebook、插入固定文本、轮询页面文案判断是否开始生成、处理每日限额、截图并写出 result.json。虽然代码确实接触到了思维导图、音频、视频、报告等生成类型,表面上与描述中的部分产物类别重合,但其主要目的明显是“功能验证/回归测试”,不是“根据用户输入进行内容生产”。此外,描述中强调的中文内容源接入、模板场景、与 IMA/飞书集成、本地 LLM 兜底等关键能力在代码中均未出现,因此属于明显的描述与实际行为不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

描述的核心方向与代码有部分重合:都是围绕 NotebookLM 导入内容并生成衍生内容。但声明明显更宽,承诺了多平台内容一键导入、模板化场景、外部工具联动以及本地 LLM 兜底,而代码实际只是一个 NotebookLM Web 自动化脚本,用于打开已有笔记本、上传粘贴文本、触发生成并下载结果。最主要的不一致在于声明强调多来源采集/联动能力,代码并未实现;同时代码的实际输入形式比描述窄得多。因此应判定为描述与行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

描述强调的是一个面向中文内容加工的 NotebookLM 增强工具,核心能力应是接收多种中文内容来源并产出多种内容形式。实际代码并未实现这些用户功能,而是一个内部/测试性质的 Playwright 全链路检查脚本,用固定文本验证 NotebookLM 网站的创建、添加来源和触发思维导图流程。它访问的是 NotebookLM 网页与本地 storage-state 文件,主要目的是自动化验收而非内容转换。两者主用途和能力明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
> - 上传改用:`scripts/notebooklm-playwright.js upload-text "<notebook标题>" "<source标题>" "<content>"`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
> - 上传改用:`scripts/notebooklm-playwright.js upload-text "<notebook标题>" "<source标题>" "<content>"`

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/installation-cn.md (reported line 101)May include surrounding context.

卸载

bash
rm -rf ~/.workbuddy/skills/ContentForge
# 协同 Skill 如不再需要,另删 lark-master / ima-skill

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/installation-cn.md (reported line 101)May include surrounding context.

卸载

bash
rm -rf ~/.workbuddy/skills/ContentForge
# 协同 Skill 如不再需要,另删 lark-master / ima-skill

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This reference document goes beyond legitimate content transformation and explicitly operationalizes paywall-circumvention strategies, including proxying, user-agent spoofing, cache/archive access, and local fetch fallbacks. In this skill context, that is dangerous because the skill is marketed for converting user-provided content, not for obtaining restricted content; embedding these instructions enables unauthorized access attempts and expands abuse capability.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document includes anti-paywall and anti-scraping methods such as bot UA disguise, generic disguise, mirror usage, and Playwright-style simulation to evade access controls. These are not justified by the stated skill purpose and materially increase the risk that the agent will bypass publisher restrictions or trigger platform abuse, especially when automated in a workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The scenario explicitly frames the workflow as '绕付费墙抓取' for paid Caixin content, which goes beyond ordinary format conversion and into paywall circumvention. Embedding bypass guidance in a reusable agent skill operationalizes unauthorized access and creates legal, policy, and abuse risk well outside the declared content-transformation purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scenario discusses paywall bypass and authenticated access techniques without a clear safety warning about handling cookies or other authentication data. In a skill context, omission of such warnings normalizes dangerous secret-sharing behavior and increases the likelihood users expose reusable session credentials.

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The ordered retrieval strategy normalizes a ladder of increasingly intrusive methods to obtain restricted article text, including subscriber-session use, alternate mirrors, app screenshot OCR, and manual copying. Packaging these as a standard decision tree makes unauthorized acquisition repeatable and lowers the barrier for abuse at scale.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

Instructing users to hand over authenticated Caixin cookies enables the system to impersonate a subscriber session and access full paid content. Cookies are sensitive authentication artifacts; collecting or injecting them risks account takeover, session hijacking, unauthorized access, and downstream misuse far beyond this single article.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The skill directly instructs users to provide authenticated site cookies so the system can retrieve subscriber-only content. This is a textbook unsafe secret-handling pattern that exposes reusable credentials and enables unauthorized access under the user's identity, with significant security and compliance consequences.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This configuration is explicitly dedicated to prioritizing methods for accessing paywalled content, including proxying, bot impersonation, spoofing, and browser automation. That materially exceeds a normal content-conversion skill’s stated purpose and creates a built-in path to unauthorized acquisition of restricted content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The overseas workflow enumerates multiple circumvention techniques such as proxy access, bot UA spoofing, generic disguise, Google cache, and Playwright-based fetching. These are classic paywall-evasion methods and enable the agent to retrieve content in ways designed to avoid publisher access controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Methods such as bot UA spoofing, proxying, referer/AMP/EU-IP disguise, and similar techniques are specifically designed to masquerade as a different client or context to obtain restricted material. In a content-ingestion skill, this is especially dangerous because it operationalizes deceptive access at scale.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The domestic workflow solicits subscriber cookies and recommends mirror sources to obtain content, which introduces both credential-handling risk and unauthorized content acquisition risk. Even if framed as convenience, this can expose sensitive session tokens and facilitate access outside intended publisher controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Accepting user-provided login cookies without warnings or isolation is a serious credential-security issue because cookies often function as bearer tokens for paid accounts. Exposure, logging, reuse, or mishandling of those tokens could let the system or others impersonate the user and access account data or subscriptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and usage instructions are presented entirely in Chinese and explicitly target processing '任何中文内容', which indicates a language-specific constraint. The file does not offer an opt-in, alternative locale, or justification that this is a region-specific compliance or localization-only tool.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill describes workflows that rely on network access, browser automation, and CLI/script execution, but it does not declare any explicit tool scope or allowed-tools boundary. This creates an authorization and review gap: an operator may not realize the skill can reach external services or invoke shell-capable components, increasing the chance of unintended data exfiltration or unsafe execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The statement「生成结果默认中文」sets a language default that may override user preference, and the document does not mention any option to select another language. This is a natural-language policy concern because it imposes a locale/language behavior without explicit user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad enough to match ordinary requests such as '做成 PPT' or '深度分析这篇', which can cause the skill to activate in contexts the user did not intend. In a skill that may fetch remote content, use browser automation, or send data to external services, overbroad invocation increases the risk of unintended data handling and tool execution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation explicitly discusses configuring network/proxy behavior to access and process paywalled or access-restricted content from sources such as 财新 and 知识星球, which goes beyond a narrow 'content conversion' skill and can enable unauthorized scraping workflows. In this skill context, that is more dangerous because the surrounding guidance operationalizes access and anti-blocking behavior, increasing the likelihood of misuse against restricted services.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 33)May include surrounding context.

通常通过 Skill Hub 一键装或 git clone:

bash
mkdir -p ~/.workbuddy/skills/
cd ~/.workbuddy/skills/
git clone https://github.com/SirKayZh/ContentForge
cd ContentForge

Static analysis

No suspicious patterns detected.