Back to skill

Security audit

笔记

Security checks for vulnerabilities and agentic risk

Overview

This meeting-note skill appears non-malicious, but it asks for and documents broader command, file, API, credential, and administrator-style operational access than its note-summarization purpose needs.

Review before installing. Use this only in a constrained environment, do not run the agent as administrator, do not provide broad filesystem access or shell execution for ordinary meeting-note work, and avoid giving it API keys or sensitive meeting content unless the exact destination and permissions are clear.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:18
Finding

Excessive Command-Execution and Filesystem Capabilities

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:18-21 and SKILL.md:263-265
Vulnerability Type: Excessive tool permissions and violation of least privilege
Risk Level: High

Vulnerable Code

yaml
tools:
  - read
  - exec
  - write

The document also advertises broad file, API, and command-execution functionality:

markdown
- **文件处理**: 支持多种文件格式的读取、解析和写入操作
- **API集成**: 通过标准化接口调用外部服务并处理响应
- **命令执行**: 在安全沙箱中执行系统命令并收集结果

Technical Analysis

The Skill's stated purpose is to transform supplied meeting content into structured notes. This task does not inherently require arbitrary system command execution. It may require limited reading of an explicitly selected source and writing to a designated output location, but the declared exec, read, and write tools expose substantially broader capabilities.

Granting exec to a Skill that processes potentially untrusted meeting transcripts creates a dangerous capability boundary. A transcript could contain prompt-injection content that resembles operational instructions. If the hosting Agent does not reliably separate data from instructions, it could invoke exec or perform unintended filesystem operations.

The documentation mentions sandboxing and command allowlisting, but it does not define or enforce an allowlist, path restrictions, argument validation, user confirmation, or a sandbox policy. Because the repository contains only SKILL.md, there is no implementation demonstrating that these controls are actually applied.

Attack Path

  1. An attacker places instruction-like content in a meeting transcript or another file submitted for summarization.
  2. A user invokes the Skill and supplies that untrusted content.
  3. The Agent loads the Skill with read, write, and exec capabilities.
  4. The Agent interprets embedded content as an instruction rather than inert meeting data.
  5. The Agent invokes a system command or accesse ...[truncated 1185 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the declared tool list because meeting-note generation does not require system command execution.
  2. Accept meeting content directly as a bounded text parameter whenever possible instead of allowing arbitrary filesystem reads.
  3. If file input is required, restrict read to files explicitly selected by the user and to approved file types and directories.
  4. Restrict write to a dedicated output directory using canonical-path validation, and reject path traversal, absolute paths, symbolic-link escapes, and overwriting of existing files unless separately confirmed.
  5. Treat all meeting content as untrusted data. Explicitly instruct the Agent not to follow commands, tool requests, links, or policy changes found inside the content being summarized.
  6. Require explicit user confirmation before any operation outside ordinary note generation.
  7. If command execution is introduced for a legitimate future feature, use a fixed command allowlist, fixed argument schemas, a low-privilege sandbox, disabled network access, resource limits, and auditable invocation logs.
  8. Align the documented capabilities with the actual implementation and remove unsupported claims about API integration and generic command execution.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:301
Finding

Unsafe Recommendation to Run the Agent with Administrator Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:301
Vulnerability Type: Unsafe privilege-escalation guidance
Risk Level: Medium

Vulnerable Code

markdown
| 权限不足 | 当前用户无读写权限 | 检查文件权限,以管理员身份运行 |

Technical Analysis

The troubleshooting guidance recommends running with administrator privileges when file read or write permissions are insufficient. Administrative execution is not a proportionate remedy for a meeting-note Skill. Permission failures should instead be handled by selecting a user-owned input or output location, correcting narrowly scoped permissions, or terminating safely.

This recommendation is particularly hazardous because the Skill also declares the exec, read, and write tools. If a user follows the guidance and launches the Agent as an administrator, every tool operation performed by the Agent may inherit elevated permissions. This converts an ordinary file-permission problem into a substantially larger security boundary.

The instruction does not directly elevate privileges automatically, and no privilege-escalation exploit is included in the project. The vulnerability is the unsafe operational guidance that encourages the user to expand privileges beyond the legitimate requirements of the task.

Attack Path

  1. A meeting-note operation encounters or appears to encounter a file-permission error.
  2. Following the documented troubleshooting advice, the user restarts the Agent with administrator or root-equivalent privileges.
  3. The Skill is loaded with broad read, write, and exec capabilities.
  4. Malicious transcript content, an Agent error, or an unintended tool call causes a command or filesystem operation outside the intended task.
  5. The operation executes with administrative permissions rather than the original restricted user permissions.
  6. Files and system resources normally protected from the user-level process may consequently be accessed or modified.

...[truncated 799 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to run the Agent as an administrator or root user.
  2. Replace it with guidance to use user-owned input and output directories.
  3. On permission failure, report the exact inaccessible path and terminate without attempting elevation.
  4. Recommend narrowly correcting ownership or permissions only for the required file, rather than elevating the entire Agent process.
  5. Never invoke privilege-elevation utilities such as sudo, su, or platform-equivalent mechanisms from the Skill.
  6. Add an explicit requirement that the Skill run under a dedicated, non-privileged account with only the minimum filesystem access needed.
  7. Combine this change with removal of the unnecessary exec capability and restriction of file access to approved directories.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is advertised as a meeting-note summarization tool, but the manifest and body broaden it into API integration, file handling, and command execution. This scope mismatch is dangerous because users or orchestrators may grant powerful tools under the assumption of a low-risk note-taking skill, enabling capability smuggling and increasing the chance of unintended code execution or data access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Documenting system command execution as a core capability is not justified by the stated purpose of producing meeting notes. In an agent environment, this invites operators to authorize shell access for a task that should be text-only, creating unnecessary exposure to command injection, filesystem abuse, or lateral actions if future prompts or wrappers pass untrusted input to exec.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says 'Use when 用户要整理会议纪要、复盘讨论、把多方探讨变成可执行资产' and also references API integration and system connection, but it does not define concrete trigger phrases, activation constraints, or negative examples. This broad wording could overlap with many ordinary note-taking or general workflow requests, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Lines L032-L036 say advanced workflow and execution capabilities are unsupported in the free version, but later sections present broad automation features such as command execution, API integration, logs, and operational runbooks as part of the skill. This creates contradictory intent signals about what the skill actually does and supports.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The FAQ says '目前本技能仅支持中文', which imposes a language restriction in natural-language policy terms. The file does not provide user opt-in, fallback behavior, or a documented regional/compliance justification for limiting the skill to Chinese only.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises general external API integration even though its core purpose is meeting-note generation. This expands the attack surface by normalizing credential use, outbound data transfer, and connector behavior that could expose sensitive meeting content to third parties or be repurposed beyond the user's expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.