Back to skill

Security audit

Note Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a visual HTML note generator, but it includes reusable examples that can spread exploit and privilege-escalation commands without clear safety boundaries.

Review before installing. The skill does not appear to run malware or persist on the system, but its bundled examples include exploit-oriented commands and unsafe phrasing that could be copied into generated notes. It also produces HTML that contacts third-party CDNs when opened, despite being described as single-file local output. Install only if you are comfortable editing or removing those examples and remote dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
assets/template.html:7
Finding

Unpinned and Remotely Loaded Presentation Dependencies

Content
View full analysis
``` `assets/template-journal.html:7-8`: ```html ``` The remote dependencies are also prescribed by the supporting documentation: ```markdown - [ ] Lucide CSS introduced correctly (`https://unpkg.com/lucide-static@latest/font/lucide.min.css`) - [ ] Remix Icon CSS introduced correctly (`https://cdn.jsdelivr.net/npm/remixicon@3.5.0/fonts/remixicon.css`) ``` ### Technical Analysis The generated HTML automatically retrieves stylesheets and associated font resources from Google Fonts, unpkg, and jsDelivr when opened in a browser. Consequently, the output is not fully self-contained or offline despite being described as a single-file document that can be opened locally. The Lucide dependency uses the mutable `@latest` version selector. Its effective contents can therefore change after this Skill has been reviewed, without any corresponding change to the project. None of the remote stylesheet references includes Subresource Integrity verification. A compromised package release, CDN account, distribution path, or upstream service could return modified CSS. Remote CSS does not ordinarily provide arbitrary native code execution, but it can modify document prese ...[truncated 2029 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

该模板并非中性学习笔记示例,而是直接内置了针对目标主机的利用命令、攻击流程和明确的破坏性结果描述(如“内存锁死”)。在一个可复用的技能模板中提供这类可直接操作的攻击内容,会降低滥用门槛,使用户更容易将其用于未经授权的攻击。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

页面在展示 exploit 用法时,没有任何“仅限授权测试/教育用途”的警示、风险说明或防滥用约束;相反,文案强调“一行命令”“攻击成本极低”,具有明显的操作诱导性。结合技能是用于生成单文件 HTML 的场景,这会把危险内容包装成易传播的成品页面,进一步放大误用风险。

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The use of '&&' to chain an exploit script directly into a non-interactive sudo root shell increases operational abuse potential by turning two actions into a single copy/paste attack sequence. In the context of an HTML note layout library, this is not necessary for presentation and materially raises the risk that the skill could facilitate exploitation or unsafe command execution by downstream users.

Content

Scanner excerpt · references/layouts.md (reported line 134)May include surrounding context.

html
<div class="code-block write-in" style="animation-delay:Xs">
  python3 exploit/exp.py && sudo -n /bin/bash -p
</div>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger word “笔记” is overly broad and likely to collide with ordinary user requests unrelated to this skill. That can cause unintended activation, making the agent apply this skill in inappropriate contexts and potentially override user intent or route sensitive content into an unnecessary HTML-generation workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The English trigger “note” is a very common everyday term and is highly prone to accidental matches. In an agent environment, this can lead to frequent false activations on benign requests, causing misrouting, unexpected transformations, or application of this skill when the user did not ask for notebook-style HTML output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML root sets lang="zh-CN", which imposes a specific language/locale on all rendered content. Under the policy, locale constraints should either be user-selectable or clearly justified as region-specific; this template provides neither.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims to generate single-file HTML notes, but the template requires external CDN-hosted resources to render as intended. This mismatch can mislead users into trusting the artifact as portable and offline-safe when it actually performs network fetches, introducing privacy, reliability, and supply-chain risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template loads Google Fonts and Lucide assets from third-party CDNs, which breaks the stated self-contained model and creates an external trust dependency. If those resources are unavailable, changed, or maliciously served, generated notes may leak access metadata, fail to render correctly, or inherit attacker-controlled content through the supply chain.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file includes a natural-language requirement that all Chinese content use lang="zh-CN". Under the policy rule for language/locale constraints, forcing a specific locale without user opt-in or an explicit region-specific justification is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The title and entire document are written in Chinese, and the skill branding '学霸笔记' indicates a Chinese-only presentation. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions and labels exclusively in Chinese, and does not mention that the skill is Chinese-only or offer any language selection. That can violate a language/locale policy when users are not given an explicit choice or notice.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
96% confidence
Finding

The example code block contains a chained command that runs an 'exploit' script and then attempts to spawn a preserved-privilege root shell via 'sudo -n /bin/bash -p'. Even as sample content, embedding realistic privilege-escalation commands in a reusable note-generation skill is dangerous because user-controlled content or copy/paste workflows could propagate or operationalize the command.

Content

Scanner excerpt · references/layouts.md (reported line 134)May include surrounding context.

html
<div class="code-block write-in" style="animation-delay:Xs">
  python3 exploit/exp.py && sudo -n /bin/bash -p
</div>

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description defines usage in broad terms, including technical content, vulnerability analysis, and knowledge summaries, without clearly stating the boundaries for when the skill should or should not activate. This increases ambiguity in skill selection and makes accidental invocation more likely, especially combined with already-broad trigger words.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document hard-codes the page language as zh-CN, which indicates a fixed language/locale choice. There is no visible opt-in, alternative locale support, or justification that this is a region-specific skill, so it conflicts with the language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The comment states 禁止 emoji alongside guidance for decorative icons, which imposes a fixed representational constraint without any visible user opt-in or justification. This can be read as a policy-style restriction on how content is expressed rather than a documented technical requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.