Back to skill

Security audit

Philosophy Dialogue

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a philosophy persona aggregator, but it ships a manual maintenance script with broad file-copying and deletion behavior that is not safely bounded.

Review before installing. The dialogue concept is not itself malicious, and there is no evidence of network exfiltration or automatic execution, but do not run scripts/update_perspective.py unless you trust the workspace registry and have backups. The publisher should add path validation, remove destructive rmtree on registry-derived paths, declare tool/file scope, and include or clearly document the referenced perspective content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/update_perspective.py:122
Finding

Registry-Controlled Path Traversal Enables Out-of-Scope Directory Deletion and Copying

Content
View full analysis
mozi-perspective parts = skill_path.replace("\\", "/").split("/") # 找到 *-perspective 目录 perspective_dir = None for p in parts: if p.endswith("-perspective"): perspective_dir = p break if not perspective_dir: # 尝试从路径推断 if len(parts) >= 2: perspective_dir = parts[-2] if parts[-1].endswith(".md") else parts[-1] else: print(f" ⚠️ 无法解析路径: {skill_path} ({entry['cn_name']})") failed += 1 failed_list.append(entry["cn_name"]) continue src_dir = os.path.join(workspace_root, "skills", perspective_dir) dst_dir = os.path.join(dest_base, perspective_dir) if not os.path.exists(src_dir): print(f" ⚠️ 源目录不存在: {src_dir} ({entry['cn_name']})") failed += 1 failed_list.append(entry["cn_name"]) continue # 拷贝(已存在则覆盖) if os.path.exists(dst_dir): shutil.rmtree(dst_dir) shutil.copytree(src_dir, dst_dir) ``` The same unsafe extraction logic is also repeated in `generate_new_registry()` at lines 195–198: ```python parts = skill_path.replace("\\", "/").split("/") perspective_dir = None for p in parts: if p.endswith("-perspective"): perspective_dir = p ``` ### Technical Analysis The `skill_path` value comes from `memory/philosopher-registry.md`. The script extracts a directory name from that value but does not validate it before combining it with trusted base directories ...[truncated 2993 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is for an end-user conversational capability: activating a philosopher's perspective for dialogue via triggers like '用哲学家的视角' and '哲学对话'. The supplied code does not implement any dialogue, persona activation, input handling, or multi-perspective conversation behavior. Instead, it is an internal utility script for repository maintenance: it locates the workspace, parses a markdown registry, copies perspective skill folders, and emits a rewritten registry under skills/philosophy-dialogue/references/. This is a materially different primary purpose from the declared skill behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description is entirely in Chinese and states the interaction model in Chinese without offering any language choice or noting that the skill is Chinese-only. This can violate language/locale policy when users have not opted into Chinese-language responses.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and generic, making accidental activation plausible during ordinary conversation about philosophy or viewpoints. Unintended activation can cause prompt/context injection into unrelated chats, override the assistant's expected behavior, or route user requests into a persona framework the user did not explicitly request.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/update_perspective.py (reported line 128)May include surrounding context.

python
failed_list = []

    for entry in entries:
        skill_path = entry["skill_path"]  # e.g. skills/mozi-perspective/SKILL.md
        # 提取目录名: skills/mozi-perspective/SKILL.md -> mozi-perspective
        parts = skill_path.replace("\\", "/").split("/")
        # 找到 *-perspective 目录

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/update_perspective.py (reported line 129)May include surrounding context.

python
failed_list = []

    for entry in entries:
        skill_path = entry["skill_path"]  # e.g. skills/mozi-perspective/SKILL.md
        # 提取目录名: skills/mozi-perspective/SKILL.md -> mozi-perspective
        parts = skill_path.replace("\\", "/").split("/")
        # 找到 *-perspective 目录

Static analysis

No suspicious patterns detected.