Back to skill

Security audit

多源研究助手

Security checks for vulnerabilities and agentic risk

Overview

This research skill is not clearly malicious, but it asks for broad local file and command authority that is not well-scoped to research tasks.

Install only if you are comfortable giving this skill local file search/read access and command execution through the host agent. Keep it in a sandbox or restricted workspace, do not run the agent as administrator, and require explicit approval before it reads local files or executes commands.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:19
Finding

Overprivileged Tool Access and Unsafe Elevation Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–23; supporting guidance at lines 259–261 and 274
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: Medium

Vulnerable Code Snippet

yaml
tools:
- read
- exec
- glob
- grep

The later documentation also claims support for arbitrary file processing and system-command execution. At line 274, its generic response to insufficient permissions is to check permissions and run with administrator privileges.

Technical Analysis

The skill requests filesystem discovery, filesystem reading, content searching, and command-execution tools despite providing no executable implementation, command allowlist, path restrictions, or concrete justification for why unrestricted local execution is necessary for multi-source research.

Combining glob, grep, and read can expose files outside the intended research workspace, including configuration files and locally stored credentials, if the hosting Agent does not impose separate boundaries. The exec capability can modify files, invoke installed programs, or initiate network connections under the Agent process's identity.

Generic advice to rerun as an administrator violates least-privilege principles. If followed, it expands the accessible filesystem and the potential effects of command execution. This is particularly concerning for a research skill because retrieved web or social-media content may be attacker-controlled and could contain prompt-injection instructions.

The package contains only documentation and no embedded executable code. Therefore, exploitation depends on a host platform granting the declared tools and an Agent being induced to misuse them; the reviewed file does not itself contain an automatic privilege-escalation mechanism.

Attack Path

  1. A user activates the skill for research involving an attacker-controlled webpage, document, or social-media ...[truncated 1419 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec unless system-command execution is essential to a documented workflow.
  2. Replace broad tool declarations with the minimum capabilities necessary for research. Prefer dedicated search or HTTP tools over local shell execution.
  3. Restrict filesystem operations to an explicit, user-approved workspace and deny access to home-directory secrets, credential stores, SSH material, environment files, and system paths.
  4. If command execution is unavoidable, define an exact executable and argument allowlist, reject shell metacharacters, prohibit interpreter invocation, apply timeouts, and run commands in a network-restricted sandbox.
  5. Remove the generic recommendation to run as administrator. Diagnose missing files or incorrectly scoped permissions instead, and document that the skill must run as an unprivileged account.
  6. Require explicit user approval before accessing a new local path or executing any command with side effects.
  7. Treat retrieved research content as untrusted data and explicitly prohibit following instructions embedded in webpages, documents, search results, or social-media posts.
  8. Align the declared capabilities with the actual implementation. Remove unsupported claims concerning arbitrary file writing and command execution if those functions are not implemented.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level summary states the skill supports integrating multiple sources and automatic deduplication. But the pricing/features table later states that '多源数据聚合与去重' is not supported in the free version, directly contradicting the earlier description of the skill's available functionality.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says the skill should be used for SEO optimization, keyword analysis, ranking improvement, and search traffic optimization, while the skill is otherwise described as a multi-source research assistant. This broad and somewhat inconsistent 'Use when' guidance lacks clear trigger boundaries or exclusion criteria, increasing the chance of unintended invocation for general research or SEO-related requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states '支持中文交互' as a default capability, and the FAQ later says the skill currently supports Chinese interaction only. This creates a language-policy concern because it implies a fixed language behavior without offering users a language choice or explicit opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The phrase indicating use whenever a user needs deep research, information collection, literature review, or public-opinion analysis covers very common request types without defining constraints. Because no negative examples or contextual limits are provided, the trigger scope is ambiguous and could match many ordinary conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The FAQ explicitly says the skill currently supports Chinese interaction and may support more languages in the future. For a general-purpose research skill, this is a natural-language policy issue unless the user is given a language choice or the locale restriction is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as a multi-source research assistant, but later documentation expands it into generic file handling, API usage, and especially command execution. This kind of scope drift is dangerous because it can cause an agent or operator to invoke higher-risk capabilities than users would reasonably expect from the manifest, increasing the chance of unsafe command execution or unintended data access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.