Back to skill

Security audit

KMind Markdown To Mind Map

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local Markdown-to-mind-map renderer with disclosed Node and browser use, and I found no evidence of hidden exfiltration, persistence, or destructive behavior.

Install if you are comfortable with a local Node script launching Chromium to render your Markdown. Treat the Markdown you render as visible to the temporary local browser session, choose output paths carefully, and avoid running it on a machine where untrusted local processes may race localhost render endpoints.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/vendor/cli.mjs:9633
Finding

Unauthenticated and Unbounded Local Render Session Endpoints

Content
View full analysis
{ try { const requestUrl = new URL(req.url ?? "/", "http://127.0.0.1"); if (req.method === "GET" && requestUrl.pathname === "/favicon.ico") { res.writeHead(204, noStoreHeaders()); res.end(); return; } if (req.method === "GET" && requestUrl.pathname === "/") { sendText(res, 200, buildHtmlPage(), "text/html; charset=utf-8"); return; } if (req.method === "GET" && requestUrl.pathname === "/renderer.js") { sendText(res, 200, rendererJs, "text/javascript; charset=utf-8"); return; } if (req.method === "GET" && requestUrl.pathname === "/job") { sendJson(res, 200, payload); return; } if (req.method === "POST" && requestUrl.pathname === "/result") { const bytes = await readRequestBytes(req); const mimeType = String(req.headers["content-type"] ?? "").trim() || (payload.format === "svg" ? "image/svg+xml" : "image/png"); await mkdir2(path4.dirname(outputPath), { recursive: true }); await writeFile2(outputPath, bytes); const done = { schema: "kmind-cli-render-session@v1", status: "done", format: payload.format, outputPath, byteLength: bytes.byteLength, mimeType }; sendJson(res, 200, done); settleResult?.({ kind: "success", done }); return; } if (req.method === "POST" && request ...[truncated 4332 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code appears to be a vendor dependency file (render-job-browser.js) containing standard React/ReactDOM/Scheduler development code. Its primary purpose is generic browser-side UI rendering and task scheduling support. While such libraries could be used by a real mind-map renderer elsewhere, this chunk itself does not implement the declared functionality. Because the evaluated code chunk’s behavior is materially different from the declared skill purpose and includes unrelated rendering/runtime capabilities, this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not parse Markdown, generate mind maps, apply KMind themes/layouts, or export PNG/SVG images. Instead, it is generic React browser rendering/runtime infrastructure. Its primary purpose is managing DOM updates, events, hydration, validation, and Fiber internals in the browser. That is materially unrelated to the declared skill description, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code does not implement Markdown parsing, KMind mind-map generation, theming, layout selection, branch coloring, dark mode, or PNG/SVG export. Instead, it is vendor framework runtime code for React rendering in the browser. This is a materially different primary purpose and indicates the description does not accurately represent the behavior of the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a Markdown-to-mind-map conversion/export skill with visual theming and image output. The supplied code does not parse Markdown, build mind maps, apply themes, or export PNG/SVG. Instead, it implements generic React rendering engine behavior: hooks like effects/memo/callback/ref, state dispatch, transitions, suspense, hydration recovery, reconciliation, and class/function component updates. This is a materially different primary purpose and indicates the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement Markdown parsing, heading-outline conversion, mind-map generation, KMind-specific formatting, theming controls, or PNG/SVG export logic. Instead, it is generic React runtime/rendering infrastructure dealing with Fiber work tags, hydration mismatch detection, host instance creation, effect mounting/unmounting, suspense retries, and DOM mutations. That is a materially different primary purpose from the declared skill description, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is about a content transformation/export skill for Markdown-to-mind-map generation. The supplied code does not parse Markdown, build mind maps, apply themes, or export PNG/SVG. Instead, it implements low-level React browser renderer behavior: commit/mount/unmount passive effects, scheduling updates on fibers, handling suspense and hydration, profiling/logging, and root commit orchestration. This is a materially different primary purpose and indicates the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a Markdown-to-KMind mind map conversion/export skill. The supplied code does not implement Markdown parsing, KMind generation, theming, layout selection, edge routing, dark mode, rainbow branches, or image export. Instead, it is a large segment of React DOM vendor code concerned with browser rendering internals: scheduling root work, listening to native events, dispatching synthetic events, handling form actions, setting DOM properties, hydration diffing, and related runtime behaviors. These are materially different capabilities and indicate the code chunk does not match the stated purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared skill describes a content-conversion/export tool for transforming Markdown outlines into KMind mind maps with theming and image export options. The supplied code does not parse Markdown, build mind maps, apply visual themes for KMind, or export PNG/SVG. Instead, it is vendor React DOM runtime code for browser rendering, hydration, event handling, stylesheet/script resource management, and root creation. While such code could support a web UI in a broader application, this chunk’s actual behavior is materially different from the declared primary purpose and introduces undeclared browser/runtime capabilities unrelated to the stated skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description is for a Markdown-to-mind-map rendering/export skill, but the supplied code is clearly unrelated framework internals from a browser React bundle. It does not parse Markdown, build KMind mind maps, apply themes/layouts, or export PNG/SVG. Instead, it implements React lifecycle invocation, hook dispatchers, warnings, reconciliation-related helpers, event registration, and preload/preconnect logic. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/vendor/render-job-browser.js (reported line 833)May include surrounding context.

js
ved a `memo` component. Instead of forwardRef(memo(...)), use memo(forwardRef(...))."
        ) : "function" !== typeof render3 ? console.error(
          "forwardRef requires a render function but was given %s.",
          null === render3 ? "null" : typeof render3
        ) : 0 !== render3.length && 2 !== render3.length && console.error(
          "forwardRef render functions accept exactly two parameters: props and ref. %s",
          1 === render3.length ? "Did you forget to use the ref parameter?" : "Any additional parameter will be undefined."
        );
        null != render3 && null != render3.defaultProps && console.error(
          "forwardRef render functions do not support defaultProps. Did you accidentally pass a React component?"
        );
        var elementType = { $$typeof: REACT_FORWARD_REF_TYPE, render: render3 }, ownName;
        Object.defineProperty(elementType, "displayName", {
          enumerable: false,
          configurable: true,
          get: function()

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The embed mounting logic executes arbitrary trusted mount hooks from an embed registry against parsed HTML nodes, giving code execution capability inside the render context for any allowed embed type. In a rendering skill, this is dangerous because untrusted job content can trigger active plugin behavior, DOM mutation, network access, or data exfiltration well beyond passive markdown-to-image conversion.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares no explicit tool/permission scope even though its documented workflow invokes Node.js, reads user-provided Markdown or files, and may launch a local browser. Missing scope boundaries increases the chance the runtime grants broader capabilities than intended, making abuse or accidental overreach harder to contain.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation (allow_implicit_invocation: true) without any visible constraint on when it should auto-trigger. That can cause the agent to invoke this skill on loosely related user input, potentially sending unintended Markdown content to the tool and producing outputs the user did not explicitly request. In this context the capability is not inherently high-risk, but broad auto-invocation expands attack surface and can contribute to prompt-routing abuse or unexpected tool use.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CLI starts a localhost HTTP server and can auto-launch a local Chromium-based browser process to load attacker-influenced content for rendering. Even though it binds to 127.0.0.1, this materially expands the attack surface: malformed or hostile SVG/project content can be funneled into a browser context, and auto-execution removes an explicit trust boundary that users would otherwise control.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill that converts Markdown heading outlines into themed KMind mind maps and exports PNG/SVG images. This CLI also supports inspecting existing KMind projects, full-text searching across project content, exporting project internals to JSON/Markdown/docs-zip, and multiple non-conversion management commands, which materially exceeds the stated conversion-focused behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This bundle includes support for importing legacy KMind, ZIP packages, XMind files, FreeMind XML, and arbitrary HTML-backed content, which exceeds the manifest's stated purpose of converting Markdown heading outlines. These capabilities are substantial product features, not necessary implementation details for a Markdown-to-mindmap exporter.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a narrowly scoped skill that converts Markdown heading outlines into themed mind maps and exports PNG/SVG. This bundled browser code fetches arbitrary render jobs, instantiates a full MindMapCanvas, and includes broad document editing/import/export capabilities from the KMind app stack rather than only Markdown-outline conversion logic.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes local Markdown-to-mindmap conversion and image export, but this file performs HTTP fetches to retrieve jobs and upload results. Network communication is not an obvious requirement of the stated purpose as written, especially since the manifest does not mention remote rendering or browser-worker orchestration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code posts the rendered output bytes to the /result endpoint, transmitting document-derived content over the network. In this file there is no confirmation prompt or user-facing warning before the upload, only status text updates after the workflow has already begun.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The node body HTML logic wires external link activation, hover preview, and host-mediated URL handling into the rendered mindmap UI. That interactive external-navigation behavior is not needed to convert Markdown headings into a mind map image and therefore exceeds the justified capability for the stated skill purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code performs file writes to user-specified output paths in both text and binary modes, but there is no confirmation prompt or explicit user-facing warning that existing files may be overwritten. For a CLI that can emit project data or rendered assets to disk, a brief disclosure or overwrite warning would improve transparency around this safety-relevant operation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest frames the skill as a Markdown-to-mindmap converter/exporter, but the code also exposes a general search tool over imported KMind project contents. Searching project data, especially with regex and fuzzy matching, is a separate analysis capability not implied by the conversion/export purpose.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/kmind-render.mjs:10

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/vendor/cli.mjs:6647