Back to skill

Security audit

上海律协考核自动视频播放

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-built for automating a Chinese law-course site, but it creates a recurring background job that may keep using the browser after the requested courses finish.

Review this before installing because it can enroll in courses, play videos, send progress notifications, and create a recurring background job against your logged-in Chrome session. Only use it if automated course playback is allowed for your account, and make sure there is a clear way to inspect and remove the video-check-loop cron job and video_state.json when finished.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Error
Location
references/workflow.md:34
Finding

Recurring Agent Cron Job Persists After Task Completion

Content
View full analysis
" }, "delivery": { "mode": "none" } } ``` ``` The completion procedure does not remove or disable the scheduled job: ```text a. done_count++, completed.push(current), queue_index++ b. Send ✅ notification c. If done_count >= target_total → send 🎉 notification, done ``` The primary skill instructions also prescribe the recurring schedule: ```json { "schedule": { "kind": "every", "everyMs": 480000 }, "sessionTarget": "isolated", "payload": { "kind": "agentTurn", "timeoutSeconds": 120 } } ``` ### Technical Analysis The workflow installs an indefinitely recurring cron job that launches an isolated agent turn every eight minutes. This scheduled execution is intended to survive individual agent invocations so that it can monitor long-running video playback. However, the documented completion branch only sends a final notification and ends the current invocation. It does not delete, disable, or otherwise expire `video-check-loop`. No maximum invocation count, expiration time, cancellation procedure, or unrecoverable-error cleanup path is specified elsewhere in the audited project. Consequently, after all courses have completed, the scheduler can continue launching isolated agents across sessions. Each invocation may retain the ability to read the workspace state file and interact with the authenticated browser context identified by the stored Chrome `target_id`. ### Attack Path 1. A user invokes the skill to automate course pl ...[truncated 1233 chars]
Remediation
View remediation
= target_total`. 3. Add equivalent cleanup for user cancellation, invalid state, browser disconnection, repeated failures, and unrecoverable errors. 4. Configure a maximum lifetime, expiration timestamp, or invocation count as a fail-safe. 5. Make the completion operation idempotent so repeated invocations cannot continue performing browser or messaging actions. 6. Require explicit user confirmation before installing the recurring job and clearly disclose its interval and lifetime. 7. Add a documented manual cleanup command for stale jobs. 8. Prefer a bounded schedule when the platform supports one. A secure completion branch should follow this sequence: ```text if done_count >= target_total: send final notification disable or delete the stored cron job ID mark state as completed exit ``` Cron cleanup should occur in a `finally`-style failure path where appropriate so unexpected errors do not leave orphaned scheduled tasks. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill describes capabilities that require persistent state creation (video_state.json) and operational setup beyond simple browser use, but it does not declare an explicit tool scope such as file-write permissions. This creates a permission transparency gap: an operator may invoke the skill without understanding that it will write local state and support long-running automation, increasing the chance of unintended persistence or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description and operational instructions are centered on Chinese UI labels such as '选修并学习' and the document title is in Chinese, but there is no explicit note that the skill is Chinese-language/site-specific or that users may need to opt into this locale. This can violate language or locale policy when a skill implicitly forces one language without clear justification in the skill text.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The architecture section reveals that the skill creates a persistent state file and a recurring cron job, but the skill description does not clearly warn the user about those durable side effects. Persistent automation can continue acting after the initial session, which may surprise users, consume resources, or keep interacting with authenticated browser sessions without fresh confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The workflow creates a persistent cron-driven background automation loop in an isolated session without an explicit user warning or consent flow. Persistent automation can continue acting on the user's browser and account over time, causing unintended actions, resource consumption, or surprise notifications after the user believes the task has ended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill sends progress notifications via the message tool but does not warn users that course titles, completion state, and pacing information may be transmitted or stored in messaging history. While the data appears limited, it may still expose training activity or other personal workflow information to unintended recipients or logs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The example values for current and title are Chinese strings, which can imply a fixed language/locale expectation. Because the document does not explain that the skill is intentionally region-specific or provide language flexibility, this may violate the language/locale policy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown explicitly instructs the skill to rewrite the whole state file, which is a file-modifying operation affecting user data. Under the markdown-specific warning criteria, the description should disclose this behavior so users understand the file will be overwritten during operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file explicitly directs the skill to create video_state.json in the workspace, which affects user data on disk. The workflow does not include any warning or disclosure that it will write files locally, so users may be unaware of this side effect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The docstring for the duration parser specifies only a Chinese-language time format ('1小时12分29秒'), which indicates a locale-specific assumption in natural-language handling. The file does not mention any user choice, alternate formats, or justification for restricting parsing to that locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.