Back to skill

Security audit

基于输入知识图谱个性生成节点学习内容

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended for learning-content generation, but it needs review because it includes under-disclosed web retrieval, plugin-loading configuration, and overconfident hardcoded content behavior.

Review before installing. Use this only if you are comfortable with Chinese/domestic-source defaults, local output/progress files, and possible third-party lookups of learning topics. Disable or remove the RAG and plugin-loading pieces unless explicitly needed, and independently verify generated educational claims.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/rag_content_enhancer.py:108
Finding

Unsanitized Remote Content Embedded in Generated Markdown

Content
View full analysis

Vulnerability Details

File Location: scripts/rag_content_enhancer.py:108-109, 154, 287-301
Vulnerability Type: Untrusted remote content injection
Risk Level: Medium

Vulnerable Code

python
return {
    "source": "wikipedia",
    "exists": True,
    "title": page.title,
    "summary": page.summary,
    "key_points": self._extract_key_points(page.summary),
    "url": page.fullurl,
    "retrieved_at": datetime.now().isoformat()
}
python
papers.append({
    "title": paper.title,
    "authors": [str(author) for author in paper.authors][:3],
    "summary": paper.summary[:300] + "..." if len(paper.summary) > 300 else paper.summary,
    "published": paper.published.strftime("%Y-%m") if paper.published else "unknown",
    "pdf_url": paper.pdf_url,
    "primary_category": paper.primary_category,
    "relevance_score": self._calculate_paper_relevance(paper, topic)
})
python
enhanced = f"""# {topic}
## Real-Time Authority Validation

**Generated At**: {datetime.now().strftime('%Y-%m-%d %H:%M')}
**Authority Validation Time**: {authoritative_info['retrieved_at']}
**Confidence**: {authoritative_info['confidence_score']:.0%}

---

## Authoritative Information

### Wikipedia Definition
{authoritative_info['wikipedia'].get('summary', 'No relevant definition found')}

**Key Points**:
{chr(10).join([f'- {point}' for point in authoritative_info['wikipedia'].get('key_points', [])])}
"""

Technical Analysis

The RAG enhancer retrieves Wikipedia summaries and arXiv abstracts and interpolates them directly into generated Markdown. The implementation does not escape Markdown metacharacters, remove raw HTML, validate embedded URLs, block remote images, or distinguish externally retrieved instructions from trusted application content.

Wikipedia and arXiv content must be treated as untrusted because external contributors can influence it. An attacker who can publish or modify content relevant to a requested topic may insert Mar ...[truncated 1946 chars]

Remediation
View remediation

Remediation Suggestions

  1. Treat every Wikipedia and arXiv field as untrusted data.
  2. Escape Markdown control characters before interpolation.
  3. Strip raw HTML and disallow active elements, embedded images, and automatic resource loading.
  4. Permit only explicitly approved URL schemes such as https.
  5. Validate citation URLs against expected source domains before including them.
  6. Apply strict length limits to titles, summaries, authors, URLs, and key points.
  7. Place retrieved text inside clearly marked quotation blocks and state that it must not be interpreted as an instruction.
  8. If output is consumed by another agent, pass retrieved content through a separate data channel or structured field rather than concatenating it into the instruction context.
  9. Add tests containing malicious Markdown, raw HTML, embedded images, unsafe URL schemes, and prompt-injection phrases.
  10. Configure the final renderer to disable raw HTML and remote-resource loading.

T08 · Insecure Dependencies

Note
Location
references/content_config.yaml:130
Finding

Unpinned Third-Party Package Installation Instruction

Content
View full analysis

Vulnerability Details

File Location: references/content_config.yaml:130-136
Vulnerability Type: Unpinned dependency installation
Risk Level: Low

Vulnerable Code

yaml
audio_generation_config:
  recommended_tools:
    - name: "gTTS"
      installation: "pip install gtts"

Technical Analysis

The configuration recommends installing gtts without pinning an audited version or requiring package hashes. The command therefore resolves the package and its transitive dependencies from the configured Python package index at installation time.

No evidence shows that gtts is malicious, and this project does not automatically execute the installation command. The risk is that users following the documented instruction receive mutable dependency content. A compromised future release, compromised transitive dependency, package-index configuration error, or dependency-resolution change could introduce hostile installation or runtime code.

Attack Path

  1. A user follows the recommended pip install gtts instruction.
  2. Pip contacts the user's configured package index and resolves the latest compatible package and transitive dependencies.
  3. If a resolved package version or dependency has been compromised, its installation or import behavior runs under the user's account.
  4. Malicious package code could then access resources available to that account.

This path is conditional on an upstream compromise or unsafe package-index configuration; no such compromise was identified in the audited files.

Impact Assessment

The instruction itself grants no privileges and is not automatically run by the Skill. If the dependency supply chain were compromised and a user executed the command, malicious package code would generally run with the privileges of the Python or pip process.

That could expose files, environment variables, network access, and credentials available to the invoking user. The scope would be ...[truncated 113 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specifically reviewed version, for example gTTS==<audited-version>.
  2. Maintain dependencies in a lock file generated from reviewed direct and transitive versions.
  3. Use hash verification, such as pip install --require-hashes -r requirements.txt.
  4. Document the approved official package index and disable untrusted extra indexes.
  5. Scan pinned packages for known vulnerabilities before release.
  6. Reassess and update dependency pins through a controlled review process.
  7. Recommend installation inside an isolated virtual environment or container with minimal credentials and network privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch is more serious because the implementation reportedly uses undeclared external knowledge sources and validation flows, which amount to hidden network/RAG capability. Undisclosed retrieval can exfiltrate user data in prompts, introduce untrusted content into outputs, and violate deployment assumptions in offline or restricted environments.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This mismatch is more serious because the implementation reportedly uses undeclared external knowledge sources and validation flows, which amount to hidden network/RAG capability. Undisclosed retrieval can exfiltrate user data in prompts, introduce untrusted content into outputs, and violate deployment assumptions in offline or restricted environments.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill declares file read/write behavior in its workflow and outputs but does not explicitly scope or constrain those capabilities via a permissions or allowed-tools section. This creates an authorization ambiguity where an agent runtime may grant broader filesystem access than users expect, increasing the risk of unintended reads or overwrites during content generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill hardcodes a content-policy preference for domestic/official sources without user opt-in, which can silently bias outputs and suppress alternative authoritative references. In educational content generation, this affects integrity and user autonomy, and may create compliance or fairness issues when the user's jurisdiction or learning goals differ.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README is entirely written as a China-specific workflow and requires prioritizing Chinese official documents, Chinese MOOCs, and Chinese academic sources, while prohibiting unverified foreign-language sources. This effectively enforces a specific language/locale and source regime without indicating user opt-in or that the skill is limited to a justified region-specific compliance use case.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

文件头注释明确声明这是“权威学习内容生成器配置文件”,而技能清单描述的是基于学习路径节点生成个性化学习内容,重点在层级感知和上下文感知。该文档化意图将技能定位为“权威内容生成器”,属于对技能目的的主动重定义,和声明用途存在明显偏移。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This YAML file uses Chinese for comments, field explanations, examples, and metadata throughout, effectively imposing a specific language on users and maintainers. The file does not indicate that the skill is China-specific or provide any opt-in or alternative locale, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

技能清单只声明生成30005000字学习内容及35道随堂自测题,并强调层级感知与上下文感知;该配置却完整定义了语音生成工具、分段规则、音频质量和发音人选择。音频合成不是从 manifest 描述中可直接推导出的实现细节,而是新增输出模态能力。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This section declares active URL validation, authority verification, and periodic update checking against external resources, which introduces network-reaching behavior beyond simple local content generation. In skill contexts, undocumented outbound fetch/validation logic can create SSRF-like access paths, privacy leakage, or trust-boundary expansion if implementations later consume attacker-influenced URLs or remote metadata.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Enabling plugins with auto_load=true materially increases attack surface because it allows code or logic extensions to be discovered and loaded from a directory without an explicit per-plugin approval flow shown here. In an agent skill ecosystem, automatic plugin loading can become an execution foothold for malicious or tampered local files, dependency confusion, or unintended capability expansion beyond the declared learning-content purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script markets itself as an authoritative generator while emitting largely hardcoded blockchain-specific content regardless of the requested knowledge node, and it labels some quiz material as mixed/inferred. In an educational pipeline, this can silently produce inaccurate or mismatched material that users may trust as verified authority, creating integrity and misinformation risk in downstream content delivery.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file embeds its primary description and all generated learning content in Chinese, and the generated template continues enforcing Chinese-language headings and prose throughout the script. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and there is no mechanism here for users to select another language or any documented region-specific justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill generates personalized learning content based on learning-path nodes, with hierarchical awareness (L1/L2/L3 depth differences) and contextual differentiation for the same concept. However, the text generation function emits a fixed blockchain-specific template regardless of the input node, and does not use node level, path context, or same-concept differentiation data to vary depth or content meaningfully.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes generating 30005000 words of learning content plus 35 in-class quiz questions per node. The code uses a static template of unspecified length rather than validating/enforcing the promised word range, and the quiz assembly logic always selects five questions rather than generating a variable 3~5 as described.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest explicitly advertises L1/L2/L3 hierarchical awareness with different depth levels, but the code only changes the recommended learning strategy strings for learner levels such as beginner/intermediate/advanced. It does not tailor the generated learning content or quiz depth using knowledge-node hierarchy levels, so the advertised capability is largely absent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata says it generates personalized learning content from learning-path nodes, but this file also performs live external retrieval from Wikipedia and arXiv. That hidden capability changes the data-flow and trust boundary: user/topic data is transmitted to third-party services and outputs become dependent on unpinned external content, which can affect privacy, reproducibility, and safety review scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The configuration fixes wikipedia_language to zh, and the skill content and outputs are written in Chinese throughout. This imposes a specific language/locale without any opt-in or documented region-specific constraint, matching the language policy violation criteria.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code sends the user-provided topic to external services for live retrieval without any user-facing notice, consent flow, or redaction. If topics contain personal, proprietary, regulated, or sensitive educational context, that information may be disclosed to third parties and logged outside the system's control.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated text claims the content has been 'real-time authoritatively verified' and 'ensures accuracy and timeliness', but the implementation only uses two sources and simple heuristic matching for confidence and objective validation. This overstates assurance and can mislead users into trusting inaccurate or weakly supported educational content, especially in high-stakes domains.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation instructs the skill to write intermediate artifacts and reports to /tmp and other output files without requiring user awareness, consent, or clear storage boundaries. In an agent environment, silent filesystem writes can leak sensitive input data, leave recoverable artifacts, overwrite existing files, or create persistence that other local processes or later sessions may access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

manifest 描述聚焦于学习内容和随堂测验的生成,没有声明将内容发布为 HTML 或 PDF。该配置不仅定义 Markdown,还加入 HTML 模板和 PDF 渲染引擎,体现的是文档发布/排版能力而非单纯内容生成。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

version_info 中的 skill_name 为“authoritative-content-generator”,而当前技能上下文名称是“learning-content-generator”。这不是单纯信息缺失,而是文档元数据对技能身份的直接矛盾表述,容易误导对技能意图和范围的理解。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The citations footer says the retrieval 'ensures timeliness and authority', but the code only pulls a small number of results from Wikipedia and arXiv with lightweight sorting. This is a misleading trust signal; users may over-rely on the references despite limited source coverage and no rigorous verification of correctness or relevance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.