Back to skill

Security audit

腾讯文档Markdown

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed Tencent Docs Markdown tool, but it handles account-level cookies and has concrete URL-validation and scoping issues that deserve review before installation.

Install only if you are comfortable granting this skill Tencent Docs account-session access and document mutation authority. Use a dedicated Tencent Docs account where possible, provide only explicit HTTPS docs.qq.com document URLs, keep the cookie file private, clear it with logout when finished, and update the flagged dependencies and URL-validation behavior before using it with sensitive documents.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
src/api.py:329
Finding

Session Cookies Can Be Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
`. 3. Do not attach authentication to arbitrary caller-provided URLs. Parse the document identifier and reconstruct the URL from the trusted constant `https://docs.qq.com`. 4. Disable automatic redirects for authenticated requests or manually validate every redirect destination before following it. 5. Use a `requests.Session` with properly scoped secure cookies rather than manually constructing a raw `Cookie` header. 6. Add regression tests confirming rejection of: - `http://docs.qq.com/...` - `https://docs.qq.com:444/...` - `https://user@example.com@docs.qq.com/...` - URLs with unauthorized hosts or paths ]]>

T09 · Insecure Skill Coding Practices

Note
Location
src/auth.py:384
Finding

Predictable Temporary QR Image Path Allows Symlink-Based File Overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (28)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill manages 腾讯文档 Markdown documents and supports document CRUD-like operations plus download/rename. The actual code shown does not interact with 腾讯文档, Markdown document content, or related APIs/resources at all. Instead, it is a release automation script for bumping semantic versions, editing package.json, optionally creating a git commit, and publishing the skill/package using clawhub. These are materially different capabilities and indicate a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a document-management skill focused on Markdown file operations in Tencent Docs. However, this code chunk does not implement document creation, reading, updating, downloading, renaming, or deletion. Its primary function is authentication: launching a browser, guiding QR login, retrieving cookies, validating them against Tencent Docs, and storing them locally as credentials. Authentication can be a supporting component of such a skill, but this chunk introduces significant undeclared capabilities around credential handling and browser-based login that are not represented in the declared description. Therefore this code chunk does not accurately match the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill performs Markdown document operations in Tencent Docs (create/read/update/delete/download/rename). However, the supplied code chunk does not implement any document manipulation. Its primary purpose is authentication: it starts a QR login flow, polls for cookies, validates them, and manages login state and exit behavior. This is a materially different purpose from the declared Markdown file operations, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 320)May include surrounding context.

md
- **依赖版本锁定:** `requirements.txt` 中所有运行时依赖都被锁定到确定版本以减少供应链风险;请在可信任的环境中安装并审查任何依赖更新。

Known Vulnerable Dependency: click==8.1.8 — 1 advisory(ies): CVE-2026-7246 (Pallets Click, versions 8.3.2 and below, contain a command injection vulnerabili)

High
Category
Supply Chain
Confidence
80% confidence
Finding

The dependency click==8.1.8 is reported as affected by a command-injection advisory. Even if this skill mainly uses Click for CLI argument parsing, a vulnerable CLI framework can become dangerous when untrusted input is passed into command-related helpers or shell-adjacent workflows, especially in agent tooling that may expose commands indirectly.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: Pillow==11.1.0 — 16 advisory(ies): CVE-2026-55379 (Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()`); CVE-2026-55798 (Pillow: WindowsViewer.get_command() OS command injection via unescaped shell pat); CVE-2026-54060 (Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_) +13 more

High
Category
Supply Chain
Confidence
88% confidence
Finding

The dependency Pillow==11.1.0 is associated with multiple advisories, including decompression-bomb and command-injection related issues. Skills that read, transform, preview, or otherwise handle downloaded files may end up processing attacker-influenced images, making image parsing bugs materially relevant rather than theoretical.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 284)May include surrounding context.

md
- 默认 `domain_id` 为 `300000000`
- XSRF Token 从 `TOK` Cookie 中提取
- Cookies 存储在 `.cookies.json` 中(已加入 `.gitignore`)
- **安全提示:** `.cookies.json` 包含敏感的会话 Cookie,请勿提交到版本控制或分享给他人,建议限制其文件权限(如 `chmod 600 .cookies.json`)
- 删除操作会将文档移至回收站(可恢复)
- 下载/读取/更新操作会自动解析 URL 中的标识符为真实 padId
- 建议在受控或受信环境中运行此工具,因为 Playwright 会下载 Chromium 并使用浏览器自动化权限

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 317)May include surrounding context.

md
- 默认 `domain_id` 为 `300000000`
- XSRF Token 从 `TOK` Cookie 中提取
- Cookies 存储在 `.cookies.json` 中(已加入 `.gitignore`)
- **安全提示:** `.cookies.json` 包含敏感的会话 Cookie,请勿提交到版本控制或分享给他人,建议限制其文件权限(如 `chmod 600 .cookies.json`)
- 删除操作会将文档移至回收站(可恢复)
- 下载/读取/更新操作会自动解析 URL 中的标识符为真实 padId
- 建议在受控或受信环境中运行此工具,因为 Playwright 会下载 Chromium 并使用浏览器自动化权限

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares substantial capabilities—local file read/write, network access, and shell execution—but does not specify any explicit tool scope or permissions boundaries. In an agent environment, this increases the chance of overbroad tool access and unintended execution of destructive or privacy-impacting actions beyond what the user expects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases include broad requests such as uploading, syncing, or submitting .md files and local files, which could match ordinary file-management intents not specifically meant for Tencent Docs. In an agent setting, ambiguous activation can cause unintended exfiltration of local document contents to a remote service or accidental destructive operations in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Login triggers like '重新登录' or 'Cookie过期了' are generic enough to fire outside this specific skill context. Unintended activation could launch browser automation, prompt for QR login, or alter local credential state when the user was referring to another service or a general troubleshooting request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description advertises broad natural-language document operations ('create, upload, download, and delete Markdown documents via natural language') without indicating any trigger constraints, confirmation requirements, or scope limits. In an agent ecosystem, this can cause the skill to be invoked for loosely related prompts and expose sensitive document actions such as deletion or download through ambiguous user intent.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: requests==2.32.3 — 4 advisory(ies): CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2026-25645 (Requests has Insecure Temp File Reuse in its extract_zipped_paths() utility func); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs) +1 more

Medium
Category
Supply Chain
Confidence
92% confidence
Finding

The dependency pin requests==2.32.3 is flagged with known security advisories, including credential leakage via malicious URLs in .netrc-related handling. In a skill that interacts with remote document services, outbound HTTP requests are expected, so retaining a version with known request-handling flaws creates realistic exposure if attacker-controlled URLs or redirects are ever processed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/api.py (reported line 157)May include surrounding context.

python
xsrf = get_xsrf_token(cookies)
    url = f'{BASE_URL}/api/markdown/read/data?xsrf={xsrf}'

    resp = requests.post(
        url,
        json={'file_id': file_id},
        headers={

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/api.py (reported line 190)May include surrounding context.

python
xsrf = get_xsrf_token(cookies)
    url = f'{BASE_URL}/api/markdown/read/data?xsrf={xsrf}'

    resp = requests.post(
        url,
        json={'file_id': file_id},
        headers={

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/api.py (reported line 225)May include surrounding context.

python
xsrf = get_xsrf_token(cookies)
    url = f'{BASE_URL}/api/markdown/read/data?xsrf={xsrf}'

    resp = requests.post(
        url,
        json={'file_id': file_id},
        headers={

Tainted flow: 'doc_id' from requests.get (line 86, network input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · src/api.py (reported line 225)May include surrounding context.

python
xsrf = get_xsrf_token(cookies)
    url = f'{BASE_URL}/cgi-bin/online_docs/doc_info?xsrf={xsrf}'

    resp = requests.post(
        url,
        json={'file_id': doc_id},
        headers={

Tainted flow: 'doc_url' from requests.get (line 94, network input) → requests.get (network output)

Medium
Category
Data Flow
Confidence
90% confidence
Finding

This function performs a GET to a user-controlled URL while attaching authenticated cookies, and then follows redirects. Although it checks for docs.qq.com before the initial request, redirects can still send the request to another host and leak session cookies or enable SSRF-like behavior if the requests library reuses sensitive headers across redirects or the upstream service redirects unexpectedly.

Content

Scanner excerpt · src/api.py (reported line 341)May include surrounding context.

python
except Exception:
        raise RuntimeError(f"Invalid docUrl: {doc_url}")

    resp = requests.get(
        doc_url,
        headers={
            **get_headers(cookies),

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · src/auth.py (reported line 48)May include surrounding context.

python
"""
    # Write the file first, then tighten permissions immediately after.
    # On POSIX we create the file with mode 0600 via os.open() to avoid
    # any window where the file is world-readable.
    flags = os.O_WRONLY | os.O_CREAT | os.O_TRUNC
    try:
        # 0o600 = rw-------  (owner read/write only)

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · src/auth.py (reported line 835)May include surrounding context.

python
"""
    # Write the file first, then tighten permissions immediately after.
    # On POSIX we create the file with mode 0600 via os.open() to avoid
    # any window where the file is world-readable.
    flags = os.O_WRONLY | os.O_CREAT | os.O_TRUNC
    try:
        # 0o600 = rw-------  (owner read/write only)

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/auth.py (reported line 236)May include surrounding context.

python
return False

    try:
        resp = requests.post(
            target_url,
            json={},
            headers={

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/auth.py (reported line 460)May include surrounding context.

python
try:
        system_name = platform.system()
        if system_name == 'Darwin':
            subprocess.Popen(['open', tmp_file], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
        elif system_name == 'Linux':
            subprocess.Popen(['xdg-open', tmp_file], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
        elif system_name == 'Windows':

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/auth.py (reported line 462)May include surrounding context.

python
if system_name == 'Darwin':
            subprocess.Popen(['open', tmp_file], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
        elif system_name == 'Linux':
            subprocess.Popen(['xdg-open', tmp_file], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
        elif system_name == 'Windows':
            os.startfile(tmp_file)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes document CRUD-style Markdown operations such as creating, reading, updating, downloading, deleting, and renaming Tencent Docs content. This file instead implements a QR-code login flow, cookie polling, cookie-file checks, and session validation against the Tencent Docs API, which is a separate authentication capability not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.