Back to skill

Security audit

note-test1-limingzhi

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent IMA notes integration, but it can read or change private notes from broad prompts and documents plaintext credential files without permission hardening.

Review this before installing if your IMA notes contain sensitive material. Prefer environment variables or an OS secret store, or ensure ~/.config/ima and its credential files are owner-only. Use the skill only for explicit IMA note requests and confirm before reading note bodies or appending/creating notes from ambiguous prompts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:27
Finding

Credential Files Are Created Without Explicitly Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27–29
Vulnerability Type: Plaintext credential storage with environment-dependent file permissions
Risk Level: Medium

Vulnerable Code

bash
mkdir -p ~/.config/ima
echo "your_client_id" > ~/.config/ima/client_id
echo "your_api_key" > ~/.config/ima/api_key

Technical Analysis

The setup instructions write the IMA Client ID and App Key to plaintext files without setting a restrictive umask or explicitly assigning permissions to the directory and files. The resulting permissions therefore depend on the user's current environment.

In an environment with a permissive umask, other local accounts may be able to traverse the configuration directory and read the credential files. The App Key is a long-lived authentication secret used by the documented API helper to access the user's IMA notes.

No hardcoded production credential was found; the vulnerability concerns the insecure credential-storage procedure presented to users.

Attack Path

  1. A user follows the documented setup procedure.
  2. The shell creates ~/.config/ima, client_id, and api_key using the environment's default permissions.
  3. On a shared system with permissive permissions, another local account enumerates or directly reads these files.
  4. The attacker obtains both the Client ID and App Key.
  5. The attacker supplies the credentials in the documented ima-openapi-clientid and ima-openapi-apikey HTTP headers.
  6. The attacker invokes the IMA note API as the victim.

This attack requires local access and permissions sufficient to read the affected files; the documented commands do not independently bypass operating-system access controls.

Impact Assessment

Successful exploitation exposes the victim's IMA API credentials. Within the privileges granted to those credentials, an attacker may be able to:

  • Search private notes and note content.
  • Enumerate notebooks and their note metadata.
  • Read priva ...[truncated 300 chars]
Remediation
View remediation

Remediation Suggestions

Create the configuration directory and credential files with explicit owner-only permissions:

bash
install -d -m 700 ~/.config/ima
umask 077
printf '%s\n' "your_client_id" > ~/.config/ima/client_id
printf '%s\n' "your_api_key" > ~/.config/ima/api_key
chmod 600 ~/.config/ima/client_id ~/.config/ima/api_key

Additional hardening measures:

  1. Prefer an operating-system credential manager or secret store over plaintext files.

  2. Verify permissions before every API call and reject insecure files:

    bash
    [ "$(stat -c '%a' ~/.config/ima/api_key)" = "600" ] || {
      echo "Refusing to use an API key with insecure permissions"
      exit 1
    }
    
  3. Avoid printing credentials in logs, command traces, errors, or API responses.

  4. Document credential rotation and revocation procedures in case the files are exposed.

  5. Use narrowly scoped and revocable API credentials when the service supports them.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises very broad activation criteria, including generic phrases like saving, recalling, or accessing personal documents even when the user does not explicitly ask for notes. This can cause the agent to over-trigger a capability that reads and writes private note content, increasing the chance of unintended access, disclosure, or modification of sensitive user data.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same plaintext credential persistence behavior: API secrets are written directly to ~/.config/ima/client_id and ~/.config/ima/api_key. If those files are readable by unintended parties or included in sync/backup workflows, attackers could reuse the credentials to access or manipulate private notes.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

  1. 存储凭证:
bash
mkdir -p ~/.config/ima
echo "your_client_id" > ~/.config/ima/client_id
echo "your_api_key" > ~/.config/ima/api_key

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

This duplicate finding points to the same plaintext credential persistence behavior: API secrets are written directly to ~/.config/ima/client_id and ~/.config/ima/api_key. If those files are readable by unintended parties or included in sync/backup workflows, attackers could reuse the credentials to access or manipulate private notes.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

  1. 存储凭证:
bash
mkdir -p ~/.config/ima
echo "your_client_id" > ~/.config/ima/client_id
echo "your_api_key" > ~/.config/ima/api_key

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

bash
ima_api() {
  local endpoint="$1" body="$2"
  curl -s -X POST "https://ima.qq.com/openapi/note/v1/$endpoint" \
    -H "ima-openapi-clientid: $IMA_CLIENT_ID" \
    -H "ima-openapi-apikey: $IMA_API_KEY" \
    -H "Content-Type: application/json" \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level description instructs activation for very broad personal-document intents, including indirect phrases like '帮我记一下' and '我之前写过一个关于XX的东西', without firm boundaries or confirmation requirements. In a privacy-sensitive notes skill, this can lead to accidental invocation, causing the agent to store, search, or surface private user notes when the user may have meant a different memory, document, or application.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger guidance for the search endpoint uses generic phrases like “搜索” and “找笔记”, which can cause the skill to activate from ordinary conversational language without a clear note-management intent. Because this skill can search and retrieve private note metadata or content, overbroad invocation increases the risk of unintended access or disclosure in the wrong context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.