Back to skill

Security audit

知识库大师

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Obsidian vault-management helper, but it asks agents to run missing relative helper scripts that can modify or delete local files.

Install only if you are comfortable with an agent modifying your Obsidian vault. Before using cleanup or attachment operations, verify exactly which executable is being run, prefer packaged or trusted scripts, run dry-run first, review the file list, keep a backup or Git snapshot, and avoid granting terminal Full Disk Access unless there is a clearly diagnosed need.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:142
Finding

Unbundled Relative Executables May Resolve to Attacker-Controlled Tools

Content
View full analysis
" --attachments "Attachments" # Output: orphan-attachments.csv, including file path, size, and modification time ``` ```bash # Move images to Attachments/Images/, PDFs to Attachments/PDF/ scripts/organize-attachments --vault "" \ --rule "image:Attachments/Images" \ --rule "pdf:Attachments/PDF" \ --rule "audio:Attachments/Audio" ``` ```bash # Delete attachments that have not been referenced for 90 days scripts/clean-orphans --vault "" --days 90 --dry-run scripts/clean-orphans --vault "" --days 90 ``` ```bash scripts/cross-vault-search "OKR" --vaults work,personal ``` ### Technical Analysis The Skill directs the Agent to execute several helpers through relative paths under `scripts/`. The audited project contains only `SKILL.md`; the referenced executables are not included, defined, version-pinned, or authenticated. Relative executable paths are resolved according to the process working directory rather than a trusted, canonical Skill installation directory. If the Agent runs from a directory containing an attacker-created `scripts/clean-orphans`, `scripts/orphan-scan`, `scripts/organize-attachments`, or `scripts/cross-vault-search`, that executable can be invoked as though it were a legitimate component of the Skill. The helpers receive vault locations and are expected to possess filesystem access. In particular, `clean-orphans` is represented as performing deletion, making substitution especially dangerous. The use of `--dry-run` does not establish a security boundary because a substituted executable can ignore that argument. ### Attack Path 1. An attacker gains the ability to place files in, or influence, the Agent's current ...[truncated 1118 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:264
Finding

Troubleshooting Guidance Recommends Excessive Full Disk Access

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes very broad, common terms such as 'obsidian', '笔记', '移动', and '重命名', which can cause the skill to activate during ordinary note-taking or file-management conversations that were not intended for this capability. Because the skill has exec access and performs filesystem operations, unintended invocation increases the chance of accidental state changes, vault switching, or destructive follow-on actions in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents deletion-oriented cleanup flows for 'orphan' attachments and even notes that detection can produce false positives, but it does not present a strong, upfront safety warning or mandatory confirmation model before destructive execution. In a local knowledge-base context, false orphan detection or path mistakes can permanently delete user data, and the presence of exec makes this materially more dangerous than a purely informational skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill presents its primary display name and summary entirely in Chinese, and the document continues in Chinese without indicating that users may choose another language. This can violate language or locale choice expectations when the skill is intended for a general multi-platform agent environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.