Back to skill

Security audit

knowledge-health-checker

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Markdown knowledge-base auditor, but its bundled fix generator can create executable scripts that delete or rewrite files and has unsafe input-handling flaws.

Install only if you are comfortable reviewing generated scripts before running them. Use the scanner/report modes on trusted local Markdown folders, do not treat auto_fix.py as a safe dry-run, and avoid feeding it untrusted results JSON or knowledge bases until the repair-script generation, path validation, and HTML escaping issues are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auto_fix.py:82
Finding

Shell Command Injection in Generated Repair Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auto_fix.py:181
Finding

Python Code Injection in Generated Repair Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auto_fix.py:46
Finding

Documented Dry-Run Is Not Implemented and Generated Script Contains Active Deletions

Content
View full analysis
1: json_file = sys.argv[1] results = json.loads(Path(json_file).read_text(encoding='utf-8')) generate_fix_script(results) generate_python_fix_script(results) else: print("Usage: python auto_fix.py ") ``` However, `SKILL.md` advertises: ```bash python3 scripts/auto_fix.py results.json --dry-run ``` ### Technical Analysis Any second argument, including `--dry-run`, is ignored. The program always generates an executable shell script containing active `rm` commands for files classified as sufficiently short or containing placeholders. The deletion operands are relative paths. Although the code computes `file_path` by combining the knowledge-base root and the result path, that computed value is not used in the generated `rm` command. The script also does not change its working directory to the knowledge-base root. Consequently, deletion is resolved relative to the directory from w ...[truncated 1237 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/report_generator.py:299
Finding

Stored HTML Injection Through Unescaped Scan Path

Content
View full analysis
{results['scan_path']} ``` The same file defines an escaping helper: ```python def escape_html(text: str) -> str: return html.escape(str(text)) ``` The helper is used for issue entries but is not applied to `results["scan_path"]`. ### Technical Analysis The report generator inserts `results["scan_path"]` directly into an HTML document. Because the value is not HTML-escaped, markup characters are interpreted by the browser rather than displayed as text. The report data is loaded from a caller-selected JSON file. Therefore, an attacker can inject an HTML element or script-capable payload into the `scan_path` field without needing a filesystem that supports the same characters. When the generated report is opened, the payload is processed in the local report’s browser context. Exact script capabilities depend on browser restrictions for local files and the payload used, but arbitrary markup injection is confirmed by the missing output encoding. ### Attack Path 1. An attacker supplies or modifies a scan-result JSON file. 2. The `scan_path` field contains malicious HTML or script-capable markup. 3. The victim runs `scripts/report_generator.py` against the file. 4. The unescaped value is written into the generated HTML report. 5. The victim opens the report in a browser. 6. The browser interprets the attacker-controlled value as markup, potentially executing script or displaying deceptive content. ### Impact Assessment The vulnerability can alter the report’s content, create convincing local phishing interfaces, redirect users, or execute browser-side code subject to local-file security restrictions. The issue does not directly grant operating-system privileges. Its effective scope is the browser context a ...[truncated 53 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code substantially matches the core declared purpose of auditing Markdown knowledge-base health: it scans Markdown files, detects empty/placeholder content, checks broken wiki links, evaluates content density, builds a graph, identifies isolated notes, and computes health scores. However, the description overstates several capabilities that are not implemented. There is no stale-file detection, no remediation/fix-plan generation, and no richer graph-fragmentation analysis beyond isolated nodes and central nodes. Reporting is limited to JSON output rather than actionable repair plans. Also, the claimed broad platform support is only implicit through generic Markdown scanning, not through platform-specific handling. Because these omitted capabilities are explicitly advertised and material, this is a description-behavior mismatch, though the primary purpose is broadly aligned.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs use of shell commands and bundled scripts that can read and write files, but it declares no tool scope or allowed-tools boundaries. That creates an authorization gap where an agent may execute broader filesystem or shell actions than the skill's stated safe workflow implies, increasing the chance of unintended mutation or misuse.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 335)May include surrounding context.

md
Avoid:

- equating more notes with better knowledge
- deleting or rewriting files without confirmation
- checking external URLs by default on large vaults
- treating all orphan notes as bad; some are intentionally private/draft
- creating huge reports with no prioritized next action

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 348)May include surrounding context.

md
Avoid:

- equating more notes with better knowledge
- deleting or rewriting files without confirmation
- checking external URLs by default on large vaults
- treating all orphan notes as bad; some are intentionally private/draft
- creating huge reports with no prioritized next action

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents the skill evaluation entirely in Chinese, and there is no indication that users can choose their preferred language or that the skill is intentionally limited to a Chinese-speaking context. The policy explicitly flags language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language docstrings and user-facing output entirely in Chinese, including the tool description and runtime messages. Under the policy for language/locale, forcing a specific language without opt-in is a violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file generates executable shell and Python repair scripts that can delete or modify knowledge-base files based on scan results. In an auditing skill, crossing from analysis into action increases risk because untrusted or mistaken scan output can be converted into destructive operations, leading to data loss or unsafe changes if a user runs the generated script.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated shell script includes destructive commands such as rm and in-place sed edits, which gives a knowledge-base checker the ability to perform irreversible filesystem changes. Although file paths are shell-quoted, the danger is capability-based: if scan results are wrong, manipulated, or overly broad, the emitted script can delete files or mass-rewrite content when executed by the user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language descriptions and runtime status messages in Chinese, which imposes a specific language on users without any opt-in or fallback. The policy only allows fixed language behavior when the skill offers language choice or the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script prints user-facing status output such as scan progress and completion messages exclusively in Chinese. Because there is no option to select another language or clear documentation that the tool is region/language-specific, this is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and all user-facing report content are written in Chinese, and the generated HTML explicitly declares lang="zh-CN". For a general-purpose report generator, this imposes a specific language/locale without user opt-in or any documented justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file defines an HTML-escaping helper but fails to apply it to several values interpolated directly into the main HTML template, including results['scan_path'] and multiple score/stat fields. If the JSON input is attacker-controlled or derived from untrusted markdown metadata/paths, opening the generated report in a browser can trigger stored XSS in the local report context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language prompt values are written entirely in Chinese across multiple test cases, which indicates the skill/test corpus expects a specific language by default. There is no visible opt-in, fallback, or justification that this skill is intentionally region-specific, so this creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document is entirely written in Chinese, including the title and all section content, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all user-facing content in Chinese only, with no indication that the skill is region-specific or that users can opt into another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文件的标题、说明和操作指引全部以中文呈现,没有提供用户可选择的语言版本,也没有解释这是仅面向中文用户或特定区域的技能。根据规则,强制单一语言而无用户 opt-in 属于自然语言层面的语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated script docstring says it is a '知识库自动修复脚本' and fix_empty_files() is documented as deleting empty shell files, yet the actual deletion call is commented out and only prints what would be deleted. This is an active mismatch between the script's stated intent and what it really does.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.