Back to skill

Security audit

Web Notepad

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a web form management integration, but its instructions overclaim security-scanning capabilities and request broad local tool authority that is not well scoped.

Review before installing. Use this only for trusted web-notepad form-management tasks, not as a security scanner or compliance auditor. If installed, run it without administrator privileges, limit filesystem access, use a least-privilege API key, and confirm any bulk form, RBAC, webhook, export, or submission changes before execution.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:27
Finding

Excessive Local Tool Permissions Violate Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27–31
Vulnerability Type: Excessive filesystem and command-execution permissions
Risk Level: Medium

Vulnerable Configuration

yaml
tools:
  - read
  - exec
  - write
  - glob

Technical Analysis

The skill declares unrestricted file reading, file writing, filesystem enumeration, and command-execution capabilities. Its documented primary purpose is managing forms through HTTPS API requests, so these local system capabilities exceed the permissions evidently required by the stated workflow.

In particular, combining glob and read permits discovery and retrieval of accessible local files, while write permits their creation or modification. The exec capability can invoke local processes and substantially increases the consequences of unsafe, attacker-controlled, or incorrectly interpreted instructions.

The documentation also recommends running with administrator privileges when file permissions are insufficient at SKILL.md:393. Although this is not an automatic privilege-escalation mechanism, following that guidance would increase the scope of the excessive tool permissions.

Attack Path

  1. A user loads the skill, making the declared read, write, glob, and exec tools available to the agent.
  2. The agent processes attacker-controlled or otherwise untrusted form content, API data, or user instructions.
  3. Malicious content induces the agent to enumerate files with glob, retrieve files with read, modify files with write, or invoke commands through exec.
  4. If the agent is running with elevated privileges, including after following the administrator guidance in the documentation, those operations inherit the broader access of the host process.
  5. Accessible local data may consequently be disclosed or altered, and commands may execute within the permissions and sandbox boundaries of the agent process.

This path ...[truncated 787 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove read, write, and glob unless a documented workflow demonstrably requires local file access.
  2. Replace unrestricted exec with a dedicated HTTPS client or narrowly scoped API tool restricted to the intended service and methods.
  3. If command execution is unavoidable, enforce an argument-aware allowlist, prohibit shell interpretation, reject user-controlled command fragments, and apply strict time, resource, and output limits.
  4. Restrict filesystem access to an isolated workspace containing no credentials or unrelated user files.
  5. Run the skill as a dedicated, unprivileged operating-system identity inside a sandbox or container with a read-only root filesystem where possible.
  6. Remove the recommendation to run as administrator. Document the exact minimum filesystem and network permissions instead.
  7. Require explicit user confirmation before sensitive file operations or command execution, and log tool invocations without recording secrets.
  8. Validate and treat all user content, imported form data, and remote API responses as untrusted data rather than executable instructions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description claims security detection, compliance auditing, vulnerability scanning, and encryption protection, but the rest of the skill is primarily a form-management/API integration tool. This kind of capability mismatch can cause an agent or user to invoke the skill in inappropriate high-trust security workflows, leading to unsafe reliance on outputs that do not correspond to the actual documented behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The input/output section describes generic content-review scoring fields such as overall grades and compliance scores, which contradict the rest of the document's form-management API behavior. In an agent setting, contradictory I/O contracts are dangerous because they can misroute sensitive data, trigger the wrong automation path, or cause downstream systems to trust fabricated security-style results.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says the skill should be used when there is a need for security detection, compliance audit, vulnerability scanning, or encryption protection, which are broad needs that overlap with many unrelated security tools. It does not provide specific trigger phrases, scope boundaries, or negative examples beyond unauthorized penetration testing, making unintended invocation more likely.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The capability matrix mixes claims about deep vulnerability scanning, compliance auditing, and risk scoring with a product otherwise described as an enterprise form system. This contradiction increases the chance that an agent will over-trust the skill for security decisions or use it outside its safe operational context.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

中型企业HR部门希望将纸质审批流程数字化,涉及请假、报销、调岗等多种审批单.

bash
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 136)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 167)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 177)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
# 1. 创建审批模板(可复用)
curl -X POST -H "Authorization: Bearer $WEB_NOTEPAD_API_KEY" \
  -H "Content-Type: application/json" \
  "https://api.web-notepad.example/v1/templates" \
  -d '{
    "name": "标准审批单模板",
    "fields": [

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The display name and operational description are written in Chinese and explicitly state '支持中文交互', but the document does not indicate that users may choose another language. This can violate language/locale policy where skills should not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.