Back to skill

Security audit

閱讀習慣追蹤

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed local reading tracker that stores and edits only its own reading-goal data, with some usability and quality caveats.

Install only if you are comfortable with a Traditional Chinese CLI tool that stores reading goals, sessions, and booklists in ~/.bookshelf-plus/habit_tracker. Review delete commands before using them, and add the suggested cron job only if you want recurring reading alerts.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

整體上,程式確實與閱讀習慣分析、進度追蹤、週/月報告、落後預警高度相關,主目的大致符合描述;它也處理書單狀態與目標進度分析,與宣稱的『目標導向、深度數據分析』相當接近。不過,這段程式碼本身並不實作『目標設定』,只會讀取既有 goals.json 後分析;若技能描述聲稱該技能直接提供設定能力,則此碼不足以支撐。此外,所謂『視覺化統計』在這裡僅是終端文字格式、ASCII 進度條與簡易柱狀圖,與一般對圖形化視覺化的期待有些落差。最後,程式另外提供了 description 未明示的 stats 子命令(指定時間統計)。因此判定為輕度到中度不一致,而非完全失配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

描述宣稱的是完整的閱讀習慣追蹤與分析系統,但此程式碼僅涵蓋書單管理子功能。它操作本地 JSON 檔,管理書籍的新增、查詢、狀態變更、評分與刪除,沒有看到任何目標管理、閱讀進度數據、週月報表、預警機制或視覺化統計邏輯。因此程式的主要用途與宣稱用途存在實質落差。雖然描述中提到書單是功能之一,但目前提供的程式碼只實作了其中一小部分,且缺少宣稱中的核心能力。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code partially matches the declared goal-setting and progress-tracking aspects: it supports yearly/monthly/per-book goals, stores targets for books/pages/hours, and computes simple completion percentages from a local sessions file. However, the declared description presents a broader reading habit tracking system with weekly/monthly analysis reports, lag warnings, visualization, planning management, and deep analytics. Those capabilities are not present in this code chunk. The code is narrowly a goal management CLI, not the fuller analytics/reporting/alerting system described. There are no suspicious undeclared external accesses; it only reads/writes local JSON files under the user's home directory.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

描述主打的是完整的『目標導向閱讀習慣追蹤系統』,核心能力應包含目標管理、週月分析、進度落後提醒與視覺化統計。但這段程式碼的主要功能只是記錄與查詢閱讀 session,附帶基本統計(總頁數、總時長、完成本數)以及書單狀態更新。雖然『進度追蹤』的一小部分可由歷史紀錄與摘要勉強涵蓋,但描述中的主要功能大多未出現,因此屬於明顯的描述與實作不符。程式也沒有顯示任何不相關或額外高風險的未宣告能力;問題在於宣稱能力遠多於實際實作。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

宣告描述的是一個完整的閱讀習慣追蹤與目標管理系統,但提供的程式碼片段實際上只是 visualizer.py,主要用途是讀取本地 sessions 資料並在終端輸出 ASCII/ANSI 圖表。它確實覆蓋了描述中的『視覺化統計』與部分『進度追蹤』呈現,但缺少描述中最核心的功能:目標設定、書單/頁數/時長目標管理、每週/每月分析報告生成、以及落後預警。另有一個實作問題:CLI 的 calendar 指令會呼叫 args.year 和 args.month,但這兩個參數並未定義;不過這屬於缺陷,不是額外能力。整體而言,程式行為僅是所宣稱系統的一個視覺化子模組,無法充分代表完整描述,因此屬於明顯不符。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill advertises and instructs use of scripts that read and write user data under ~/.bookshelf-plus/habit_tracker/, but the manifest does not declare any explicit tool scope or permissions. This creates a transparency and governance gap: an agent or platform may invoke file-capable behavior without clear least-privilege boundaries, increasing the chance of unexpected file access or unsafe future expansion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language description, trigger phrases, and scheduled message are all written only in Traditional Chinese, and the cron example hard-codes the timezone to Asia/Taipei. The file does not indicate that language and locale are optional or region-specific, which can violate a policy requiring user language or locale choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Broad trigger phrases like '閱讀目標', '追蹤進度', or '讀了多少' can cause the skill to activate in unrelated conversations, leading to unintended file reads/writes or autonomous workflow execution. In agent systems, overbroad invocation acts like an authorization boundary weakness because the skill may run without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module description and all user-facing help/report strings are written in Traditional Chinese, indicating the skill is effectively locked to a specific language. There is no visible user opt-in, language selection mechanism, or justification that this skill is intended only for a specific locale.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

At L121 the comment says the code is predicting whether the goal can be completed, but the implementation computes projected using needed, which is itself derived from the exact remaining work required to hit the target. That makes projected effectively equal to the target whenever done < target, so on_track becomes almost always true and does not reflect an actual pace-based prediction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-facing strings throughout the file, including the module description and command outputs, are written exclusively in Chinese, with no indication that users can opt into another language. This can violate language/locale policy when a skill imposes a specific language without user choice or explicit justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The remove_book function deletes matching entries from the persisted book list and immediately writes the modified data back to disk. Although it returns a success message afterward, there is no prior confirmation prompt or explicit warning before this irreversible data change occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code deletes a session by rewriting the stored sessions file after removing the matching entry, which is a destructive operation affecting user data. Although the function prints a success message after deletion, there is no confirmation prompt or pre-action warning before the irreversible change occurs in this code file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings that effectively force a specific language/locale for users, including the module docstring and later CLI help/output text. The policy allows locale constraints only when users can opt in or when the restriction is clearly justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language descriptions in Chinese, and later CLI help/output is also presented only in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The docstring and all CLI help and output strings are written in Traditional Chinese, indicating the skill is effectively constrained to a specific language. There is no visible opt-in, locale selection, or justification showing that this language restriction is intentional for a region-specific tool.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The CLI help and command structure imply that the "calendar" subcommand supports selecting a monthly calendar view, but the parser never defines year or month arguments before calendar_view(args.year, args.month) is called. This is an intent-code mismatch in the command interface documentation: the command claims a usable calendar feature, while the code path is inconsistent with that advertised behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.