Back to skill

Security audit

Parse Dedao

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its note-parsing purpose, but it can open arbitrary web pages in an unsandboxed browser and automatically save remote content to a fixed local folder.

Review before installing. Use this only with trusted Dedao links or after adding a strict dedao.cn allowlist, restoring Chromium sandboxing or running it in an isolated container, and making the output directory explicit and configurable. Be aware it can contact third-party image hosts and save page content/images locally.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/parse.js:40
Finding

Unrestricted URL Navigation Enables Server-Side Request Forgery

Content
View full analysis
{ const imgs = Array.from(document.querySelectorAll('img')); return imgs.map(img => img.dataset.src || img.dataset.lazySrc || img.src || '') .filter(src => src && src.startsWith('http') && !src.includes('track') && !src.includes('pixel')); }); for (const imgUrl of imgUrls) { try { const imgResponse = await page.goto(imgUrl, { timeout: 30000, waitUntil: 'domcontentloaded' }); if (imgResponse && imgResponse.ok()) { const buffer = await imgResponse.body(); // Skip images that are too small if (buffer.length < minImageSize) continue; let ext = '.jpg'; if (imgUrl.includes('.png')) ext = '.png'; else if (imgUrl.includes('.gif')) ext = '.gif'; else if (imgUrl.includes('.webp')) ext = '.webp'; result.images.push({ url: imgUrl, buffer, ext }); } } catch (imgErr) { // Failure of one image does not interrupt processing } } } ``` ### Technical Analysis `parsePage` accepts a caller-controlled URL and passes it directly to `page.goto` without validating its hostname, resolved IP address, port, or redirect destination. Although the skill documentation presents this as a parser for `dedao.cn` sharing links, the implementation does not enforce that restriction. The page can also control the image URLs placed in `imgUrls`. The only protocol-related check is `src.startsWith('http')`, which permits both HTTP and HTTPS requests to arbitrar ...[truncated 2293 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/parse.js:21
Finding

Chromium Sandbox Disabled While Rendering Untrusted Web Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

声明描述只提到解析得到分享链接、提取正文以及下载图片,这与代码的一部分行为一致。但实际代码还会把提取结果和图片整理成Markdown笔记,并写入本地固定目录。这属于额外的持久化与文件组织能力,且使用了明确的本地路径资源,超出了仅“提取正文和下载图片”的表述。因此描述未完整反映代码实际行为,存在能力层面的不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description says images are automatically saved locally, but it does not prominently warn about file-system writes or give users a chance to control where data is stored. Automatic persistence of remote content can create privacy, storage, and trust-boundary issues, especially when users may expect parsing only, not downloading to disk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as Dedao-specific, but the API example advertises a generic parsePage(url) function for arbitrary webpages. This broadens the effective scope from a narrowly described parser into a general web-fetching and content-extraction capability, which can increase exposure to untrusted URLs, unexpected network access, and misuse beyond the user's apparent expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code fetches a user-supplied URL and then downloads image URLs discovered on that page, which transmits network requests to third-party hosts and may expose system/network metadata. The file contains no confirmation, logging, or user-facing warning about this external network activity or the follow-on image downloads.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script writes extracted article content and downloaded images from a user-supplied URL into a fixed local directory on disk, creating persistent side effects beyond simple parsing. This can expose sensitive content, unexpectedly consume local storage, and violate least-privilege expectations for a skill whose stated role is content extraction rather than unmanaged local archival.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language description is entirely framed around Chinese-language use and says the skill should be used when the user sends a Dedao share link, without indicating any language preference or opt-in. Under the policy rule, language or locale constraints should either be optional or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The human-readable documentation in this file is written only in Chinese, including the function description, without offering a language choice or documenting a justified locale restriction. This can violate a language/locale policy when skills are expected to be language-neutral or user-selectable.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comment states step 2 is '总结关键信息(B)', implying the script actually generates a summary. In code, the summary is not produced; lines L63-L64 and L78-L80 explicitly use a placeholder indicating the AI summary is still pending.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code hard-codes toLocaleString('zh-CN'), which imposes a specific locale in generated user-facing content. This is a natural-language/locale policy concern because the skill does not offer opt-in, fallback behavior, or any documented reason for forcing Chinese formatting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.