Back to skill

Security audit

元案 yotta-lesson

Security checks for vulnerabilities and agentic risk

Overview

The lesson tool itself is local and coherent, but its installers can persistently copy the skill into many agent environments without confirmation, so it should be reviewed before installing.

Use a narrow install path such as --agent codex or an explicit --dir, and avoid -g unless you really want this skill installed across many agent environments. Check whether a yotta-lesson directory already exists before installing, and prefer a pinned package version or reviewed tagged source instead of unpinned npx. The inspected lesson engine itself appears local-only and does not show upload, credential access, or remote execution behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A second, stronger mismatch is reported: the package may not implement any actual lesson-generation or checking logic at all, and instead functions primarily as a cross-agent installer/distributor that creates directories, recursively copies files, and removes .git metadata. This is especially risky because it suggests deceptive packaging: the skill context lowers user suspicion while enabling propagation across agent environments and hiding provenance details.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A second, stronger mismatch is reported: the package may not implement any actual lesson-generation or checking logic at all, and instead functions primarily as a cross-agent installer/distributor that creates directories, recursively copies files, and removes .git metadata. This is especially risky because it suggests deceptive packaging: the skill context lowers user suspicion while enabling propagation across agent environments and hiding provenance details.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · install.sh (reported line 66)May include surrounding context.

sh
install_to() {
  mkdir -p "$1/$SKILL_NAME"
  cp -r "$SOURCE_DIR/." "$1/$SKILL_NAME/"
  rm -rf "$1/$SKILL_NAME/.git"
  echo "installed -> $1/$SKILL_NAME"
}

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to execute npx -y @yottameta/yotta-lesson without pinning a specific package version. This causes users to fetch and run whatever version is current on the registry at execution time, creating a supply-chain risk if a future release is compromised, maliciously republished, or unexpectedly changed.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This command again tells users to run an unpinned npx package, which means the executed code is not stable or auditable over time. Even though the skill describes itself as local-only and deterministic, the installation path still depends on live registry content and can expose users to registry compromise or malicious package updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to execute npx -y @yottameta/yotta-lesson without pinning an exact package version. This creates a supply-chain risk: users may install whatever version is current at execution time, including a compromised or unexpectedly breaking release, and the -y flag reduces friction for accidental execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

This second npx -y @yottameta/yotta-lesson invocation has the same issue: it fetches and runs an unpinned package version from the registry. If the upstream package, maintainer account, or dependency chain is compromised, users following the README could execute attacker-controlled code locally.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill declares no explicit tool scope or permissions despite documented capability indicators for environment-variable access and file reading. Even if these capabilities are only used locally, the absence of a clear permission boundary weakens reviewability and can let a seemingly harmless educational skill access local data paths or context unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · bin/install.js (reported line 25)May include surrounding context.

js
const AGENT_DIRS = {
  claude:    { label: 'Claude Code',      dirs: ['.claude/skills'] },
  cursor:    { label: 'Cursor',           dirs: ['.cursor/skills', '.agents/skills'] },
  codex:     { label: 'Codex',            dirs: ['.codex/skills'] }, // 特判:$CODEX_HOME/skills
  gemini:    { label: 'Gemini CLI',       dirs: ['.gemini/skills', '.agents/skills'] },
  goose:     { label: 'Goose',            dirs: ['.config/goose/skills', '.agents/skills'] },
  amp:       { label: 'Amp',              dirs: ['.config/agents/skills', '.agents/skills'] },

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer creates target directories and copies files into them without checking for an existing installation, prompting for confirmation, or performing a safe merge strategy. This can silently overwrite an existing skill's contents or replace trusted local files in a user-specified directory, causing integrity loss and unexpected behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Global install mode writes into multiple user-level skill directories automatically once -g is supplied, with no summary, confirmation, or dry-run preview. This broadens filesystem impact and increases the chance of unintended modification across several agent environments, especially where skill loading is automatic.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · install.sh (reported line 124)May include surrounding context.

sh
echo "完成。"; return
  fi
  local installed=0 d
  for d in .claude/skills .cursor/skills .codex/skills .config/goose/skills .config/agents/skills .opencode/skills .codeium/windsurf/skills .workbuddy/skills .kiro/skills .traecli/skills .gemini/skills .trae-cn/skills .qwen/skills .comate/skills .codebuddy/skills .kimi/skills .agents/skills; do
    if [ -d "$d" ]; then install_to "$d"; installed=1; fi
  done
  if [ "$installed" = "0" ]; then

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and built-in disclaimer are written entirely in Chinese and the tool's rendered output strings throughout the file are fixed in Chinese. This indicates a hard-coded language/locale choice without any user opt-in or documented justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file uses Chinese throughout, including the title and all release notes, and does not indicate that the skill is region-specific or that alternative language documentation is available here. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The header explicitly labels the skill language as English while only providing Chinese as an alternate linked document. This can be read as a default language constraint in the skill documentation without stating that users may choose their preferred language at runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

文件首行以“语言: 中文 · English”呈现,并将当前文档固定为中文版本,但未说明技能是否会在运行时默认强制中文输出,或是否允许用户自行选择语言/locale。按规则,若技能在自然语言层面强制特定语言而无用户 opt-in,可构成语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's comments and console output are written in Chinese, including usage/help text shown to users. This forces a specific language experience without user opt-in, which is a natural-language locale policy concern unless the tool is explicitly documented as Chinese-only or region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, including headings, field descriptions, and usage guidance. Under the policy rule for natural-language constraints, forcing a specific language without user opt-in can be a locale-policy violation when no rationale or alternative is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all instructions and schema descriptions in Chinese only, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-language audience. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.