Back to skill

Security audit

一键生成知乎高质量回答网页(可自由剪裁)

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate research-page skill, but it asks the agent to expand local permissions and may use private workspace context in external searches without clear user approval.

Install only if you are comfortable with a high-cost, network-heavy workflow. Provide an explicit topic, review search terms before execution, avoid running it in sensitive repositories, do not let it auto-edit .claude/settings.local.json unless you accept the permission expansion, and inspect generated HTML before opening or sharing it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
README.md:56
Finding

Unpinned npx Installer Creates a Supply-Chain Execution Risk

Content
View full analysis
Remediation
View remediation
add \ https://github.com/timeRATE-966/zhihu-research-page-skill# ``` 2. Pin the Skill repository to a full immutable commit hash or a signed release rather than the default branch. 3. Publish SHA-256 checksums for release archives and document how users can verify them before installation. 4. Use signed Git tags or release attestations and document the expected signer identity. 5. Provide a non-executing manual installation option based on a verified archive. 6. Document the exact npm package name, publisher, and expected version so users can detect package substitution. 7. Re-audit dependencies whenever the pinned installer or repository revision changes. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:264
Finding

Private Workspace Context May Be Sent to External Search Services Without Confirmation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/assemble.py:85
Finding

Generated HTML Fragments Are Assembled Without Active-Content Sanitization

Content
View full analysis
]*?)(>)', rf'\1 id="{aid}"\2', frag, count=1, flags=re.S ) vc = valid_chars(frag) all_chapters.append((name, aid, frag, vc)) # ---- 4) Insert all fragments into the skeleton ---- if '' not in html: print("[error] The skeleton is missing the assembly marker.") sys.exit(1) chapters_html = '\n\n'.join( frag for _, _, frag, _ in all_chapters ) html = html.replace('', chapters_html, 1) ``` The source uses localized log messages, but the executable behavior above is unchanged: draft files are read and inserted verbatim into the final HTML document. ### Technical Analysis Chapter drafts are generated by writing agents using information gathered from external web sources. `assemble.py` treats the resulting HTML as trusted and inserts it directly into `index.html`. The pre-scan scripts only check selected `` nesting conditions. The assembler also performs CSS normalization and structural checks, but it does not reject or sanitize: - `
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (39)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
output: "自动搜索 ≥500 次,生成 10 章节完整深度网页(≥100,000 字),约 100 分钟"
---

<!-- VERSION:v21 | 2026-07-21 | 教程模式+自动同步+版本头 -->
# 一句话生成知乎高质量回答网页(可自由剪裁)

## 用法示例

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
output: "自动搜索 ≥500 次,生成 10 章节完整深度网页(≥100,000 字),约 100 分钟"
---

<!-- VERSION:v21 | 2026-07-21 | 教程模式+自动同步+版本头 -->
# 一句话生成知乎高质量回答网页(可自由剪裁)

## 用法示例

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly directs the agent to create or modify .claude/settings.local.json to grant broad Write/Edit/Bash permissions to subagents. Expanding local execution permissions is a privileged action unrelated to merely generating a webpage, and it lowers the safety boundary for all subsequent actions in the workspace, enabling unintended file modification or command execution if the skill or subagents misbehave.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 280)May include surrounding context.

md
1. 读取 skill 源 `SKILL.md` 顶部的 `<!-- VERSION:v{N} -->` 注释,与工作区记录的版本对比

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 427)May include surrounding context.

md
<span style="font-size:14px;color:var(--text-secondary);margin-left:12px;">5 个回答</span>
  </div>

  <!-- 预留 1~2 条引导回答(可选) -->

  <!-- ASSEMBLE -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 427)May include surrounding context.

md
<span style="font-size:14px;color:var(--text-secondary);margin-left:12px;">5 个回答</span>
  </div>

  <!-- 预留 1~2 条引导回答(可选) -->

  <!-- ASSEMBLE -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 846)May include surrounding context.

6.4 幂等性注意事项

assemble.py 首次运行后会消费骨架中的 <!-- ASSEMBLE --> 占位标记。如果需要在同一次会话中重跑(如补完章节后再次拼接),需先手工恢复占位符:

bash
# 用 sed/Python 把已注入的章节替换回占位标记

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 846)May include surrounding context.

6.4 幂等性注意事项

assemble.py 首次运行后会消费骨架中的 <!-- ASSEMBLE --> 占位标记。如果需要在同一次会话中重跑(如补完章节后再次拼接),需先手工恢复占位符:

bash
# 用 sed/Python 把已注入的章节替换回占位标记

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README highlights token and time costs but does not clearly warn that the skill performs large-scale web searching and creates versioned output folders automatically. Users may unknowingly trigger extensive outbound queries and local file creation, which can have privacy, operational, and cost implications in agent environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The README instructs users to install and run a remote skill via npx skills add without pinning a specific immutable version or commit. This creates a supply-chain risk: if the referenced package or upstream repository changes, users may fetch different code than expected, including malicious updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This installation command again relies on an unpinned remote source through npx skills add, allowing the installed skill contents to drift over time. An attacker who compromises the upstream repo or publishes a malicious update could cause users to install altered instructions or code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match common requests such as tutorials, guides, and research pages, increasing the chance the skill activates unexpectedly. In this skill's context, accidental activation is risky because it can launch very large web-search workflows and generate substantial local output, causing cost, time, and filesystem side effects the user may not have intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill plans to create and modify many files and directories (index.html, images/, other/, research_result/, copied scripts, archives) but the top-level description does not clearly warn users about the breadth of local filesystem changes. Insufficient disclosure increases the risk of unexpected workspace modification, clutter, or overwriting of local artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The language parameter is set to 中文 as the default, and the skill title/description emphasize Chinese output, but the instructions do not clearly present language choice or require user consent before using that locale. This can violate language/locale policy when a skill implicitly forces a specific language instead of offering a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill says it will infer the topic by scanning conversation context, open files, folder names, and CLAUDE.md when the user does not specify one, but this behavior is not prominently disclosed in the user-facing description. That creates a transparency and consent problem because the agent may read more contextual material than users reasonably expect for a simple page-generation request.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The skill instructs the agent to contact third-party services such as DiceBear and avatar CDNs to generate or retrieve avatar content. Even if the transmitted data seems limited, requests can disclose task metadata, timing, network identifiers, or topic-linked seeds to external services, which is broader than many users expect from local webpage generation.

Content

Scanner excerpt · SKILL.md (reported line 618)May include surrounding context.

md
| 优先级 | 来源 | 判定标准 |
|--------|------|----------|
| 1 级 | 真实人物公开头像 | 公开可独立验证的直链(GitHub CDN `avatars.githubusercontent.com/u/<id>`、豆瓣影人页、雪球/掘金/丁香园等平台公开头像、个人官网) |
| 2 级 | DiceBear 风格化 SVG | `https://api.dicebear.com/7.x/{bottts-neutral|avataaars|notionists}/svg?seed=<英文短语>&backgroundColor=<hex>&radius=50`,三种风格交替配合不同配色 |
| 3 级 | 单字符占位 | `<div class="zh-avatar" aria-hidden="true">{首字}</div>`(仅在前两级均不可用时使用) |

**铁律**:

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The connectivity-test instructions use curl against external avatar services and optional enterprise proxies, causing outbound network requests unrelated to core content generation. These requests can leak environment/network information and normalize unnecessary external probing behavior inside a content-creation skill.

Content

Scanner excerpt · SKILL.md (reported line 637)May include surrounding context.

md
curl -sI --max-time 5 "https://avatars.githubusercontent.com/u/1" | head -3

# 测 DiceBear API
curl -sI --max-time 5 "https://api.dicebear.com/7.x/bottts-neutral/svg?seed=test" | head -3

# 如有企业代理,补充 -x <代理地址>
curl -x http://proxy:port -sI --max-time 5 "https://avatars.githubusercontent.com/u/1" | head -3

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The skill downloads avatar assets from external services into the workspace, which is a real external transmission and supply-chain touchpoint. Remote content retrieval introduces privacy, integrity, and reproducibility risks, especially when not essential to the requested research-page functionality.

Content

Scanner excerpt · SKILL.md (reported line 673)May include surrounding context.

DiceBear SVG:直接保存为 .svg(远程 API 可能失效或限流)

curl -sL -o "./images/ch-02.svg"
"https://api.dicebear.com/7.x/avataaars/svg?seed=arduino-fan&backgroundColor=f4b400&radius=50"

text

**缓存规则**:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the agent to persist task records into .workbuddy/memory/YYYY-MM-DD.md, which is outside the core need of producing the requested HTML page. Persistent memory writes can retain user/project details longer than expected and create unnecessary cross-task data exposure or privacy leakage within the workspace.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document title and mandatory usage instructions are written entirely in Chinese, and L003-L004 require agents to follow this file first without offering any language choice. This creates a locale/language policy issue because the skill effectively forces Chinese as the operating language for troubleshooting guidance with no opt-in or explicit region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

All headings, prompts, and behavior examples are presented exclusively in Chinese, and the command examples imply Chinese-language usage as the default interaction mode. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation unless a justified region-specific constraint is documented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example explicitly encourages automatic large-scale web research, very high token/time consumption, and substantial output generation without any warning, confirmation step, or guardrails. In an agent skill context, this can lead to unexpected resource exhaustion, excessive network activity, and uncontrolled file creation, especially if users copy the example verbatim without understanding the side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example normalizes repeated generation of versioned outputs in the same directory without warning that files will accumulate over time. In practice, this can create storage sprawl, overwrite confusion, or unintended persistence of large generated artifacts, especially when users iterate frequently.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The examples advertise extensive automated external searching without warning users that prompts or derived topics may be sent to third-party services or that fetched content may influence outputs. In a research skill, this omission can mislead users about privacy exposure, data sharing, and trustworthiness of externally sourced information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill example says it will automatically extract a research topic from conversation history, but it gives no warning that prior chat context may be inspected and reused. This can expose sensitive user information or confidential discussion content if users do not realize historical messages are being mined for external research queries or content generation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.