Back to skill

Security audit

书签智析专业版

Security checks for vulnerabilities and agentic risk

Overview

The skill’s bookmark-analysis purpose is coherent, but it asks users to run a persistent automation that uses X cookies, fetches linked content, stores analyses locally, and sends data to external services with incomplete upfront privacy scoping.

Review before installing. Only use this skill if you are comfortable giving it X session-cookie access, letting it run as a background process, storing bookmark analyses under the local knowledge-base path, and sending bookmark/article/project context to AI services and Telegram. Prefer narrowing its trigger to X bookmark analysis only and configure short retention, conservative polling, and explicit notification settings.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The documentation gives users a misleading assurance that credentials or sensitive data never leave the machine, while nearby text admits data is sent to external services for X fetching and AI analysis. This can cause users to disclose cookies, tokens, bookmarks, and linked article content under false privacy expectations, increasing the risk of unintended third-party exposure.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill advertises itself with a very broad invocation scope for generic data analysis and reporting, even though it also has exec, write, polling, scraping, and outbound notification behavior. Overbroad positioning can cause the agent to invoke a high-privilege automation skill in contexts unrelated to bookmark analysis, exposing unrelated user data to local execution and external services.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill performs ongoing polling, fetches linked content, writes local JSON knowledge bases, and pushes results to Telegram, but lacks a prominent consolidated warning up front about continuous collection, retention, and external transmission. Users may enable the skill without understanding that bookmarked content, article bodies, project context, and derived analysis may be stored locally and shared with third parties on an ongoing basis.

Static analysis

No suspicious patterns detected.