Back to skill

Security audit

网盘同步专家

Security checks for vulnerabilities and agentic risk

Overview

This Baidu Netdisk skill is coherent overall, but it needs review because it can run unaudited installer scripts and upload broad agent memory files to cloud storage.

Install only after reviewing the missing scripts and the bdpan binary source yourself. Avoid memory backup unless you have inspected the listed memory files for secrets or private context and are comfortable storing them in Baidu Netdisk; prefer a sandboxed install and do not use the remote installer in sensitive environments without pinned integrity checks.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:327
Finding

Unverified Remote Dependency Download and Execution

Content
View full analysis
Remediation
View remediation

other

Error
Location
SKILL.md:343
Finding

Overbroad Collection and Cloud Backup of Sensitive Agent State

Content
View full analysis
//manual// Backup contents: AGENTS.md, SOUL.md, USER.md, IDENTITY.md, TOOLS.md, MEMORY.md, HEARTBEAT.md, memory/*.md, and manifest.json ### Back Up Memory bash ${CLAUDE_SKILL_DIR}/scripts/memory-backup.sh backup ``` ### Technical Analysis The backup operation collects a broad predefined set of Agent files, including user information, identity state, instructions, tool configuration, long-term memory, and all Markdown files under `memory/`. Such files can contain private user information, operational instructions, local paths, service details, or credentials accidentally stored in text. A general request to “back up memory” can therefore cause substantially more information to leave the local environment than a user may reasonably expect. The design does not document per-file consent, secret scanning, client-side encryption, retention limits, or a default exclusion policy. The referenced `memory-backup.sh` implementation is not present in the submitted project. Consequently, the audit could not verify its claimed path validation, manifest generation, filtering, encryption, or safety-net behavior. ### Attack Path 1. A user asks the Agent to back up its memory. 2. The Skill interprets that phrase as authorization to run the memory-backup script. 3. The script is expected to collect the fixed set of identity, user, tool, instruction, and memory files. 4. Those files are uploaded to the configured Baidu Netdisk account. 5. Sensitive content becomes exposed if the cloud account, backup directory, generated share link, or authenticated local session is later compromised or ...[truncated 667 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:284
Finding

Predictable Shared Temporary File in Incremental Synchronization

Content
View full analysis
/tmp/remote-files.json # 2. Compare local files for file in ./local-dir/*; do filename=$(basename "$file") local_size=$(stat -c%s "$file") remote_size=$(jq -r ".[] | select(.name==\"$filename\") | .size" /tmp/remote-files.json) if [ "$local_size" != "$remote_size" ]; then echo "File $filename changed; uploading..." bdpan upload "$file" "remote-dir/$filename" else echo "File $filename unchanged; skipping" fi done ``` ### Technical Analysis The synchronization template uses the fixed path `/tmp/remote-files.json`. On multi-user systems, `/tmp` is commonly shared and writable. The template does not securely create the file, check whether it is a symbolic link, restrict its permissions, verify its ownership, or remove it after use. A local attacker may pre-create that path as a symbolic link to another file writable by the Agent. Shell redirection would then overwrite the linked target. An attacker with sufficient local access may also replace or modify the JSON between its creation and use, influencing which files the synchronization logic uploads or skips. ### Attack Path 1. A local attacker predicts the documented `/tmp/remote-files.json` path. 2. Before synchronization starts, the attacker creates it as a symbolic link to another file writable by the Agent, or prepares to replace its contents. 3. The Agent executes the redirection to the fixed path. 4. The linked target is overwritten with Netdisk metadata, or the metadata file is modified before `jq` reads it. 5. Manipulated sizes cause synchronization to upload files unnecessarily or skip files that should have been uploaded. ### Impact Assessment The symlink case may overwrite files writable by the Agent account. Metada ...[truncated 358 chars]
Remediation
View remediation
"$remote_files" || exit 1 ``` Additionally: 1. Verify that the generated object is a regular file owned by the current user. 2. Quote the temporary filename on every access. 3. Avoid globally predictable names. 4. Stop processing if metadata generation or JSON parsing fails. 5. Store temporary data in an Agent-private runtime directory when available. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:273
Finding

Unsafe Filename Handling in Batch and Incremental Processing Templates

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 173)May include surrounding context.

bash
# 清理日志
rm -f /tmp/bdpan-dl-<PID>.log

Agent执行大文件后台下载行为规范:

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs uploading a broad set of Agent memory files and manifests to remote storage. These files can contain system prompts, user data, preferences, credentials, operational notes, or other high-value context; centralizing them in cloud storage significantly raises exposure in the event of account compromise, over-sharing, or retention beyond intended scope.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger rules intentionally activate backup and restore operations for Agent memory even when the user does not mention cloud storage explicitly. This lowers the friction for shipping potentially sensitive memory artifacts off-host and makes accidental data disclosure more likely, especially because users may interpret '备份记忆' as a local-only action unless warned otherwise.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 163)May include surrounding context.

bash
# 启动后台下载
nohup bdpan download <远端路径> <本地路径> > /tmp/bdpan-dl-$$.log 2>&1 & echo $!
bash

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 445)May include surrounding context.

bash
# 启动后台下载
nohup bdpan download <远端路径> <本地路径> > /tmp/bdpan-dl-$$.log 2>&1 & echo $!
bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The install flow instructs the agent to run an installer script that downloads and executes code from a remote CDN, and even notes that no local SHA256 verification is performed. Although HTTPS is mentioned, the skill does not clearly warn that this results in execution of remote code on the user's system, creating supply-chain risk if the CDN content, transport, or upstream script is compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly supports backing up and restoring Agent memory to Baidu Netdisk, including files like AGENTS.md, MEMORY.md, and memory/*.md, but it does not prominently warn that these may contain sensitive prompts, secrets, personal data, or operational context that will leave the local system. In a security-sensitive agent environment, transmitting comprehensive memory artifacts to cloud storage materially increases confidentiality risk and may expose credentials or sensitive internal state if the cloud account is compromised or shared.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.