Back to skill

Security audit

用间隔重复与主动回忆结构化追踪学习

Security checks for vulnerabilities and agentic risk

Overview

This learning skill is Markdown-only, but it asks for broad file, API, and command-execution authority without clear limits.

Review before installing. Only use this skill in an agent environment that requires confirmation for file writes, command execution, and network/API calls; avoid granting unrestricted exec or administrator privileges for normal learning tasks.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:34
Finding

Excessive and Underspecified Agent Tool Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:34-37
Related Locations: SKILL.md:224-228, SKILL.md:240
Vulnerability Type: Excessive filesystem and command-execution permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
  - read
  - exec
  - write

Technical Analysis

The Skill requests unrestricted reading, writing, and command execution even though its documented purpose is to create learning plans, spaced-repetition material, and active-recall exercises. These operations do not inherently require arbitrary system command execution or broad filesystem access.

The additional feature description claims generic file processing, API integration, and system command execution capabilities. The troubleshooting guidance also suggests elevated administrator execution when permissions are insufficient. However, the Skill defines no:

  • Filesystem path restrictions
  • Command allowlist
  • Argument validation requirements
  • External endpoint allowlist
  • Explicit user-approval boundary
  • Concrete sandbox restrictions
  • Least-privilege execution policy

Consequently, an agent loading the Skill could receive permissions beyond those legitimately required for the learning task. Because this package contains only Markdown and no executable implementation, the risk depends on the host agent interpreting and granting the declared tools.

Attack Path

  1. A user or platform loads the Skill and grants its declared read, write, and exec tools.
  2. An attacker supplies a crafted learning topic, document, filename, path, or embedded instruction.
  3. The agent interprets that input as requiring file processing or command execution.
  4. In the absence of path restrictions and command allowlisting, the agent reads or modifies files outside a dedicated learning-data directory, or executes an unnecessary system command.
  5. If the operation fails due to permissions, the troubleshoot ...[truncated 1102 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec because the documented learning functionality does not require arbitrary command execution.
  2. Remove generic API access unless a specific external service is required and documented.
  3. Restrict read and write operations to a dedicated learning-data directory controlled by the user.
  4. Require explicit user confirmation before reading an existing file, overwriting data, or contacting an external service.
  5. Define allowed file types, maximum file sizes, canonical-path validation, and protections against path traversal and symbolic-link attacks.
  6. If command execution is genuinely required, define an exact command and argument allowlist, reject shell metacharacters, disable shell interpolation, and execute with minimum privileges in a sandbox.
  7. Remove the recommendation to run as administrator. Replace it with least-privilege diagnostics and instructions for granting only the narrowly required resource permissions.
  8. Document the precise sandbox, network, retention, and data-handling boundaries instead of making a generic claim that commands execute securely.
  9. Ensure learning content and imported documents are treated as untrusted data and cannot issue instructions that authorize tool use.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Advertising system command execution for a learning-management skill is unjustified and violates least privilege. If an agent enables exec based on this documentation, the skill could be used to run arbitrary shell commands, exposing the host to data loss, credential theft, or broader system compromise.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Conflicting statements about whether the skill is MD+execute() or pure Markdown create ambiguity about the trust and permission model. That ambiguity can cause an agent or user to underestimate the skill's privileges and permit execution pathways they did not intend to allow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is presented as a learning/spaced-repetition tool, but later documentation broadens it into generic automation with file handling, API calls, and command execution. This scope mismatch can mislead users and agents into granting powerful capabilities that are unrelated to the stated purpose, increasing the chance of unsafe or unintended actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares impactful capabilities such as file writing, command execution, and external API use without prominent upfront warning. Users may invoke a seemingly harmless learning tool without realizing it can modify files, run commands, or transmit data, which undermines informed consent and safe operation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims external API integration without clearly connecting that capability to its learning-focused purpose. Unnecessary network access increases exposure to data exfiltration, accidental disclosure of learning content or environment metadata, and dependency on untrusted remote services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill metadata and documentation prominently use Chinese alongside English, but the file does not state whether users can choose their preferred language. This can amount to a language/locale policy issue when a skill implicitly imposes a language presentation without user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.