Back to skill

Security audit

Web Collection

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent for browser-based web collection, but it needs review because it handles authenticated data and credentials with under-scoped endpoint, storage, and install controls.

Install only if you trust the publisher and the Feishu/GitHub sources. Before running, verify the connector and browser extension source, avoid saving cloud tokens in preferences if possible, keep cloud and bridge URLs at the documented defaults, and do not pass an untrusted `--bridge-cmd` or endpoint override.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run.sh:199
Finding

Bearer and Local Administrator Credentials Can Be Sent to Arbitrary Endpoint Overrides

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export_preference.sh:191
Finding

Cloud Bearer Tokens Are Persisted in Plaintext Without Enforced Owner-Only Permissions

Content
View full analysis
{ try { return JSON.parse(fs.readFileSync(filePath, "utf8")); } catch { return null; } }; let value = rawValue; if (rawValue === "true") value = true; else if (rawValue === "false") value = false; else if (/^[0-9]+$/.test(rawValue)) value = Number(rawValue); const data = read(prefPath) ?? read(legacyPath) ?? {}; data[key] = value; data.updatedAt = new Date().toISOString(); data.updatedBy = "user"; const tempPath = `${prefPath}.tmp-${process.pid}`; fs.writeFileSync(tempPath, JSON.stringify(data, null, 2) + "\n", "utf8"); fs.renameSync(tempPath, prefPath); ' "$pref_path" "$legacy_path" "$key" "$value" } ``` The public interface explicitly supports persisting the token: ```text Supported keys: defaultConnectionMode local | cloud defaultExportMode csv | bitable defaultPlatform douyin | tiktok | xiaohongshu | amazon | bilibili defaultMaxItems integer defaultFetchDetail true | false defaultDetailSpeed slow | medium | fast defaultDeduplicationEnabled true | false defaultDeduplicationStrategy keepOld | keepNew defaultBridgeUrl string defaultCloudBaseUrl string defaultCloudDeviceId string defaultCloudToken string ``` ### Technical Analysis `defaultCloudToken` is stored as an ordinary JSON string ...[truncated 1922 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:112
Finding

Mutable and Unverified Sources Are Used for Extension, Connector, and Skill Installation

Content
View full analysis
/install-skill-from-github.py \ --url https://github.com/yiming1001/skills-yiming/tree/main/web-collection ``` ### Technical Analysis The installation instructions do not specify: - An immutable connector or extension version. - A Git commit hash or signed release tag. - SHA-256 checksums. - Code-signing certificate details. - A signature-verification procedure. - A trusted publisher identity that users must verify. The Feishu guide can change after this Skill has been audited. Likewise, the GitHub `main` branch can resolve to different content over time. A compromise of the document, download hosting, repository account, or branch can therefore replace ...[truncated 1693 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself mainly as a collection/onboarding helper, but the instructions also include modifying local preference state, applying defaults, and handling cloud credential-related fields. When a skill mutates local state and credential configuration beyond what its description clearly discloses, users and reviewers may underestimate its ability to alter persistent settings or affect future runs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill presents itself mainly as a collection/onboarding helper, but the instructions also include modifying local preference state, applying defaults, and handling cloud credential-related fields. When a skill mutates local state and credential configuration beyond what its description clearly discloses, users and reviewers may underestimate its ability to alter persistent settings or affect future runs.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
For collection execution, keep using this `SKILL.md` and the bundled scripts as the agent contract. For complex or ambiguous execution requests, read [reference

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
For collection execution, keep using this `SKILL.md` and the bundled scripts as the agent contract. For complex or ambiguous execution requests, read [reference

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

md
- When authorization is needed, run the normal collection entry point or `scripts/ensure_connector_auth.sh`; it will generate a website login confirmation link.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 578)May include surrounding context.

md
- When authorization is needed, run the normal collection entry point or `scripts/ensure_connector_auth.sh`; it will generate a website login confirmation link.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 583)May include surrounding context.

md
- When authorization is needed, run the normal collection entry point or `scripts/ensure_connector_auth.sh`; it will generate a website login confirmation link.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 262)May include surrounding context.

md
- `run.sh` first tries environment variables, stored preferences, App state, and connector state.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

md
- `run.sh` first tries environment variables, stored preferences, App state, and connector state.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 399)May include surrounding context.

md
- `run.sh` first tries environment variables, stored preferences, App state, and connector state.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 581)May include surrounding context.

md
- `run.sh` first tries environment variables, stored preferences, App state, and connector state.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 366)May include surrounding context.

md
values, ask for the complete set in one message and then persist them through `scripts/export_preference.sh set-key`. Do not introduce a card callback server,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 592)May include surrounding context.

md
values, ask for the complete set in one message and then persist them through `scripts/export_preference.sh set-key`. Do not introduce a card callback server,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 570)May include surrounding context.

md
- local mode dispatches only through `scripts/collect_and_export_loop.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 585)May include surrounding context.

md
- local mode dispatches only through `scripts/collect_and_export_loop.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 589)May include surrounding context.

md
- `scripts/reexport_task.sh`

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a web-collection skill for connector-based data collection and onboarding/troubleshooting, but this script also accepts a caller-supplied command and later executes it to start a bridge. Spawning an arbitrary local process via a free-form command is a powerful capability that is not inherently required for performing collection requests against the connector API.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

When --ensure-bridge is enabled, the script executes nohup bash -lc "$BRIDGE_CMD" ... &, which is a direct shell execution sink. If --bridge-cmd is influenced by untrusted input, this becomes arbitrary command execution with the privileges of the script runner and persists as a background process.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script captures output from an authorization helper and executes it with eval, meaning any compromised helper, tampered file, or unexpected output can run arbitrary shell code in the caller's context. This goes beyond configuration parsing and turns auth-response handling into a local code-execution primitive.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script accepts a bridge startup command from an environment variable or CLI argument and passes it into downstream execution, enabling arbitrary shell command execution if that value is attacker-controlled. In a data-collection skill, this is unnecessarily broad capability and creates a clear command-injection/RCE path on the local host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file states that the skill performs data collection across multiple websites and handles exports, but it does not disclose any user warning about effects on privacy, collected account data, or downstream handling of exported data. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill specifies executable capabilities such as shell, network, and environment access but does not declare an explicit tool scope or permission boundary. That increases the risk of overbroad execution, because the agent can invoke scripts, read environment state, and make outbound requests without an in-file allowlist constraining what is intended.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
- `assets/bitable-step-00-personal-center.png`
  - Use when telling the user to open the browser extension, enter `个人中心`, and log in.
- `assets/bitable-step-01-template-copy.png`
  - Use when telling the user to open the direct bitable template link and create a copy.
- `assets/bitable-step-02-auth-code.png`
  - Use when telling the user to open `多维表格插件` -> `自定义插件` and copy the authorization code.
- `assets/bitable-step-03-config-save.png`

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill mandates a specific Chinese next-step prompt for users, and similar required Chinese quick-reply templates appear later in the file. This is a natural-language locale policy issue because the skill does not offer the user any language choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These sections prescribe exact Chinese-language prompts for authorization, quick replies, and custom configuration collection. Because the file does not provide an alternative language path or user opt-in, it enforces a specific locale in a way that violates the stated natural-language policy criterion.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/preflight_check.sh:254