Back to skill

Security audit

Markdown导出工具

Security checks for vulnerabilities and agentic risk

Overview

This Markdown conversion skill mostly matches its stated purpose, but it adds under-explained API/callback behavior, broad agent routing, unpinned package installation, and administrator-use guidance.

Review before installing. Use only for explicit Markdown conversion tasks, install the converter in an isolated non-admin environment, pin and verify the `md-exporter` package, avoid providing API keys or callback URLs unless you understand exactly what will be sent, and choose output paths carefully because the skill creates files and may extract code blocks.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:137
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 137
Vulnerability Type: Unpinned and unverifiable third-party dependency
Risk Level: Medium

Relevant snippet:

bash
pip install md-exporter

Technical Analysis

The skill instructs users or agents to install md-exporter directly from the package index without specifying an exact version, integrity hash, lock file, or verified source repository. Consequently, the dependency resolved during installation can differ from the version reviewed when the skill was published.

If the package account, distribution channel, or a future release is compromised, package-controlled code may execute during source-package builds or when the installed conversion commands are invoked. The skill metadata claims version 3.6.11, but the installation command does not constrain the dependency to that version.

No evidence establishes that the current package is malicious. The vulnerability is the absence of supply-chain controls around executable third-party code.

Attack Path

  1. An agent or user activates the skill and follows its installation instructions.
  2. pip resolves the latest available md-exporter distribution rather than a reviewed version.
  3. An attacker compromises the package, publisher account, release process, or another component involved in dependency resolution.
  4. The victim installs the attacker-controlled release.
  5. Malicious code executes during a source build or when a documented markdown-exporter command is invoked.
  6. The code operates with the privileges and file or network access of the account running the installation or conversion.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope may include access to Markdown inputs, generated documents, environment variables, API credentials available to the process, writable files, and reachab ...[truncated 141 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to an explicitly reviewed version, such as md-exporter==3.6.11, after verifying that this is the intended release.
  • Use hash-verified installation with a constraints or requirements file containing approved SHA-256 hashes.
  • Publish the canonical source repository and package-index URL so users can verify package ownership.
  • Maintain a lock file or signed software bill of materials covering all transitive dependencies.
  • Install and execute the converter in an isolated virtual environment, container, or sandbox under a non-privileged account.
  • Disable unnecessary network access during conversion and expose only required input and output directories.
  • Re-audit dependency updates before changing the pinned version.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:289
Finding

Unsafe Recommendation to Run Conversion Operations with Administrator Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 289
Vulnerability Type: Unnecessary privilege escalation guidance
Risk Level: Medium

Relevant snippet, translated into English from the source documentation:

text
Insufficient permissions | The current user lacks read/write permission | Check file permissions and run as administrator

Technical Analysis

The troubleshooting guidance recommends running the operation as an administrator when file permissions are insufficient. Markdown conversion ordinarily requires access only to the selected input file, output destination, and narrowly scoped temporary storage. Elevating the entire converter bypasses least-privilege boundaries instead of correcting ownership, access-control settings, or the output location.

This becomes particularly dangerous because the converter is installed as an unpinned third-party dependency and processes potentially untrusted Markdown, templates, and embedded content. A dependency compromise or exploitable parser defect would consequently execute in an elevated security context.

The documentation does not itself elevate privileges automatically, and no embedded privilege-escalation implementation was found. The vulnerability is unsafe operational guidance that encourages users or agents to grant excessive privileges.

Attack Path

  1. A conversion fails because the selected input or output path is not accessible to the current account.
  2. The user or agent follows the troubleshooting recommendation and reruns the installation or conversion with administrator privileges.
  3. The converter loads a compromised dependency or processes a maliciously crafted Markdown or template file.
  4. Attacker-controlled behavior executes in the elevated process.
  5. The behavior accesses or modifies resources that would have been protected from the ordinary user account.

Impact Assessment

Conditional exploitation could expand arbit ...[truncated 440 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the recommendation to run the converter as an administrator.
  • Direct users to inspect file ownership and grant only the minimum required read or write permission.
  • Recommend writing output to a user-owned directory rather than protected system locations.
  • Run the converter under a dedicated, non-privileged account with access restricted to the required files.
  • Use isolated temporary directories with restrictive permissions and unpredictable names.
  • Add an explicit warning that package installation and document conversion must not be performed with administrator or root privileges.
  • If elevated file placement is genuinely necessary, generate the document without elevation and use a separate, narrowly scoped operation to move the completed output.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The invocation guidance is extremely broad, recommending the skill for general efficiency, automation, batch processing, and workflow optimization. That makes it likely to be auto-selected for many unrelated tasks, which is dangerous because the skill also advertises exec/write capabilities and ambiguous external behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill exposes callback_url and discusses API-style integration without a prominent warning that document data, filenames, status, or results may be sent to external endpoints. For a file-conversion skill, hidden outbound delivery paths create meaningful privacy and exfiltration risk, especially when processing internal or sensitive Markdown.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill performs writes and generates new files, including extracted code files and archives, but does not prominently warn users about filesystem side effects. In an agent context, silent file creation can overwrite data, spread sensitive content into new locations, or create executable artifacts from embedded code blocks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill repeatedly states it is a local file-path Markdown conversion tool, but later introduces API-key setup, API calls, and callback behavior without reconciling that expansion of scope. This mismatch can cause users or agents to route document contents or metadata to external systems unexpectedly, undermining trust boundaries and safe invocation assumptions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a Markdown exporter but also claims broad powers such as API integration, information retrieval, and generalized command execution. Overbroad and unrelated capabilities increase the chance an agent invokes the skill in contexts far beyond document conversion, enabling unnecessary access to files, commands, and external services.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documented external API integration is not justified by the skill's stated purpose of local Markdown export, creating an unnecessary channel for data egress. In the context of document processing, users may provide sensitive content, so undeclared or weakly justified API behavior materially raises exfiltration and privacy risks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Claiming information-retrieval/search capability in a Markdown export skill expands operational scope without clear necessity. While less severe than command execution or API calls, this can still prompt unintended data access or broaden agent behavior in ways users would not expect from a format-conversion tool.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.