T09 · Insecure Skill Coding Practices
- Location
scripts/enhanced_search.py:26- Finding
Plaintext arXiv metadata retrieval allows response tampering
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a real academic paper search tool, but it downloads files and contacts broader network destinations than its formal security metadata clearly covers.
Install only if you are comfortable with a skill that searches academic sites, automatically downloads remote files to your Desktop papers folder, and may contact Semantic Scholar or PDF hosts not fully listed in the manifest. Review any sudo install command before running it, and avoid opening downloaded PDFs from untrusted sources without validation.
scripts/enhanced_search.py:26Plaintext arXiv metadata retrieval allows response tampering
scripts/main.py:61Scraped download URLs are requested without destination validation
scripts/arxiv_search_v2.py:100Automatic downloads lack maximum-size and PDF-content validation
skill.json:48Formal network declarations omit actual third-party destinations
requirements.txt:2Python dependencies use open-ended version ranges without integrity hashes
All user-facing instructions and examples in the README are written in Chinese, and there is no indication that other languages are supported or that the skill is intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.
The listed triggers, activation condition, and dialogue examples are written exclusively in Chinese and imply the skill is invoked and operated in that language only. There is no indication that users may choose another language or that the Chinese-only behavior is a justified regional constraint.
The trigger 搜论文 and the when condition "用户需要检索论文、下载PDF、总结工作创新点、按引用量排序时" are broad natural-language activators without clear scope boundaries. They do not include exclusion conditions or negative examples, so the skill could be invoked for many ordinary research-related requests unintentionally.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 系统依赖安装(根据操作系统选择)
system:
ubuntu:
- sudo apt-get install -y poppler-utils
debian:
- sudo apt-get install -y poppler-utils
macos:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 系统依赖安装(根据操作系统选择)
system:
ubuntu:
- sudo apt-get install -y poppler-utils
debian:
- sudo apt-get install -y poppler-utils
macos:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 系统依赖安装(根据操作系统选择)
system:
ubuntu:
- sudo apt-get install -y poppler-utils
debian:
- sudo apt-get install -y poppler-utils
macos:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# 系统依赖安装(根据操作系统选择)
system:
ubuntu:
- sudo apt-get install -y poppler-utils
debian:
- sudo apt-get install -y poppler-utils
macos:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Ubuntu/Debian:
sudo apt-get install -y poppler-utils
macOS:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Ubuntu/Debian:
sudo apt-get install -y poppler-utils
macOS:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Ubuntu/Debian:
sudo apt-get install -y poppler-utils
macOS:
The script creates a fixed directory on the user's Desktop and later writes downloaded PDFs there automatically, without prompting the user or requiring explicit opt-in for filesystem changes. While this is not arbitrary file write, it is still a real safety issue because executing the skill causes persistent local side effects and network-fetched content to be saved to a prominent user location by default.
The script automatically downloads remote PDFs and writes them to a fixed Desktop directory without any user confirmation, dry-run mode, or opt-in flag. In an agent/skill context, this can cause unintended filesystem modification, silent disk usage, and retrieval of untrusted content from the network, which is risky even if the files are 'just PDFs'.
The script creates a Desktop subdirectory up front and later, by default, downloads PDFs into it without explicit user confirmation. While this appears intended functionality for a paper-search tool rather than malicious behavior, it still performs local writes and network-driven file downloads automatically, which can surprise users, consume disk space, and persist untrusted content on the host.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# API端点
ARXIV_API = "http://export.arxiv.org/api/query"
SEMANTIC_SCHOLAR_API = "https://api.semanticscholar.org/graph/v1/paper/search"
def clean_filename(title):
"""清理文件名"""
This Python file contains user-facing natural language entirely in Chinese, including the tool name, feature description, and later CLI messages, with no indication that the user can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""提取页面文字用于分析图片标题"""
try:
cmd = ["pdftotext", "-f", str(page_num), "-l", str(page_num), "-layout", pdf_path, "-"]
result = subprocess.run(cmd, capture_output=True, text=True, timeout=30)
return result.stdout.lower()
except:
return ""
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
# 使用pdfimages提取图片
cmd = ["pdfimages", "-png", "-f", str(page_num), "-l", str(page_num),
pdf_path, os.path.join(output_dir, f"{prefix}_p{page_num}")]
subprocess.run(cmd, capture_output=True, timeout=30)
# 找到生成的图片
for f in os.listdir(output_dir):
The script creates a Desktop folder automatically and later downloads remote PDF content into it without any explicit user confirmation, dry-run mode, or opt-in for filesystem writes. In an agent/skill context, this is risky because a user may trigger a search expecting read-only behavior, while the skill silently persists untrusted internet content to a highly visible local path and can clutter storage or introduce unsafe files disguised as PDFs.
The docstring and all user-facing usage/help text are entirely in Chinese, which imposes a language requirement on users without any opt-in or alternative locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.
The script automatically downloads PDFs for every search result and writes them to the user's Desktop without any confirmation, opt-in, or dry-run mode. This can cause unexpected network activity, disk consumption, and unreviewed file placement from remote content, which is risky in an agent skill context where users may expect search-only behavior.
The skill name and description are entirely in Chinese, with no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-language audience. This can violate language/locale policy when a skill implicitly forces one language without user choice or justification.
This is a manifest file, so vague-trigger review applies. The description is purely capability-focused and broad ('一键搜索学术论文,自动下载PDF,智能总结...') without any explicit activation phrases, boundaries, or negative examples, which can make invocation conditions unclear in systems that derive triggers from manifest text.
The install manifest instructs use of 'sudo apt-get install -y poppler-utils', which normalizes privileged execution during setup. While installing a package manager dependency is common, embedding sudo-based commands in a skill can lead users to run elevated commands they do not fully audit, increasing the blast radius if the manifest or surrounding install flow is ever tampered with.
"Pillow>=9.0.0"
],
"system": {
"ubuntu": "sudo apt-get install -y poppler-utils",
"debian": "sudo apt-get install -y poppler-utils",
"macos": "brew install poppler",
"fedora": "sudo dnf install -y poppler-utils",
The manifest includes 'sudo apt-get install -y poppler-utils' for Debian, encouraging privileged execution as part of installation. Even though the package itself appears legitimate, prompting users to run root-level commands from skill metadata creates avoidable trust and supply-chain risk.
],
"system": {
"ubuntu": "sudo apt-get install -y poppler-utils",
"debian": "sudo apt-get install -y poppler-utils",
"macos": "brew install poppler",
"fedora": "sudo dnf install -y poppler-utils",
"centos": "sudo yum install -y poppler-utils"
The Fedora install command uses 'sudo dnf install -y poppler-utils', again requiring elevated privileges based on manifest content. In the context of a skill that already requests network, file-write, and subprocess permissions, encouraging root-level setup increases risk if users broadly trust the package without scrutiny.
"ubuntu": "sudo apt-get install -y poppler-utils",
"debian": "sudo apt-get install -y poppler-utils",
"macos": "brew install poppler",
"fedora": "sudo dnf install -y poppler-utils",
"centos": "sudo yum install -y poppler-utils"
}
},
No suspicious patterns detected.