Back to skill

Security audit

知网高级检索

Security checks for vulnerabilities and agentic risk

Overview

This skill automates a disclosed CNKI paper-search and export workflow, with expected browser use and local result-file creation.

Install this only if you want an agent to operate CNKI in a browser and create exported result files locally. Before running it, confirm the keyword groups, expected export count, and save location, especially if the fallback Excel generation is used.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger conditions are broad enough to activate on many ordinary research-related requests, which can cause the skill to run browser automation and downloading behavior without sufficiently specific user intent. In context, this increases the risk of overcollection, unintended site interaction, and unexpected local side effects from a casual query.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill performs downloads and local move/copy operations, including writing to ~/Downloads with generated filenames, without a clear upfront warning and explicit consent for filesystem modification. This is dangerous because it normalizes local file side effects and could surprise users or overwrite/duplicate files in ways they did not anticipate.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs behavior beyond its declared scope by falling back to local Python/Excel generation when CNKI export is unavailable. That expands the tool from browser automation into local file creation and processing without an explicit manifest declaration or separate user consent, increasing the chance of unexpected file writes and unsafe execution paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The instructions state that execution must use the "openclaw" profile and must not use "chrome," presenting a fixed tooling/profile requirement without offering user opt-in or explaining a locale/policy-style organizational necessity. This is a natural-language constraint that removes user choice in a way that may conflict with policy expectations around opt-in for forced preferences.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Lines L052-L055 instruct the agent not to stop merely because CAPTCHA-related DOM text appears and to continue trying the form unless interaction is actually blocked. Later documentation says '验证码出现时必须请用户手动完成' and at L114 says to prompt the user if CAPTCHA appears, creating conflicting operational guidance about the same condition.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.