Back to skill

Security audit

Templatebased Writing

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent document-template purpose, but it routes sensitive documents, API keys, and payment proof through an unsafe and under-disclosed external workflow.

Review carefully before installing. Do not upload private, regulated, school, resume, or business documents until the service uses HTTPS, explains retention/deletion, and asks for explicit upload consent. Do not provide API keys or payment proof to the current plaintext backend. Prefer a pinned install command whose slug matches the reviewed artifact.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/check_payment.py:20
Finding

API Credentials Transmitted over Plaintext HTTP

Content
View full analysis
dict: url = f"{API_BASE}/key/balance" req = Request(url) if api_key: req.add_header("Authorization", f"Bearer {api_key}") req.add_header("X-API-Key", api_key) ``` ### Technical Analysis The payment-status script transmits the API key to a bare IP address over unencrypted HTTP. The same credential is included in both the `Authorization` and `X-API-Key` headers, unnecessarily duplicating sensitive information. HTTP provides neither transport confidentiality nor authenticated server identity. A network intermediary can therefore read the API key, modify the balance response, redirect the request, or impersonate the backend. Using a bare IP also prevents the script from benefiting from the HTTPS domain advertised in `readme.md`. The network operation is related to payment-status checking, but exposing credentials over plaintext transport exceeds the minimum security requirements for that functionality. ### Attack Path 1. A user or Agent supplies an API key through `--apikey` or `TEMPLATE_API_KEY`. 2. The script creates a request to `http://124.221.10.61/api/v1/key/balance`. 3. The credential is sent in two HTTP headers without TLS. 4. An attacker on the local network, proxy path, ISP path, or another intermediary captures the request. 5. The attacker extracts and reuses the API key against backend operations available to that identity. 6. An active attacker may also forge the balance response to manipulate payment or access-control decisions. ### Impact Assessment An attacker can obtain the backend credential and exercise whatever document, account, quota, or premium-access privileges are associated with it. The precise backend aut ...[truncated 344 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/upload_template.py:38
Finding

Private User Documents Uploaded over Unencrypted HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/pricing.md:67
Finding

Payment Proofs and Transaction Data Directed to a Plaintext Backend

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
references/templates.md:5
Finding

Broad Document Requests Hijacked into a Mandatory Commercial Workflow

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
readme.md:34
Finding

Unpinned Executable Package Used for Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (28)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document describes uploading user-provided templates and processing document contents through a backend API, yet it contains no indication that users are warned their files may leave the local environment and be stored or analyzed remotely. In this context, uploaded templates may contain resumes, academic papers, or other sensitive personal/business data, creating a real privacy and compliance risk if transmission occurs without explicit disclosure and consent.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
# 定价规则(统一版)

## 一句话

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · readme.md (reported line 1)May include surrounding context.

md
# 定价规则(统一版)

## 一句话

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/pricing.md (reported line 1)May include surrounding context.

md
# 定价规则(统一版)

## 一句话

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script sends authentication material to an HTTP endpoint (http://124.221.10.61/api/v1) and includes the API key in both Authorization and X-API-Key headers. Because HTTP is unencrypted, any network observer or on-path attacker can intercept the key, replay it, or tamper with the server response, directly compromising the associated account or service usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file is sent as multipart/form-data to an HTTP endpoint, so both the full document contents and any Authorization bearer token are exposed in cleartext to passive monitoring and active man-in-the-middle attacks. Because this script is specifically designed to upload user-supplied templates, the skill context increases the danger: templates may contain proprietary or personal data, and tampered responses could mislead downstream processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file states that the skill can directly handle code, server, payment, and document-generation workflows, but it does not warn users that their document content may be sent to a backend API or that files and payment actions may be performed. Under the markdown-file criteria, descriptions that omit warnings about behaviors affecting user data, privacy, or system integrity should be flagged.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The handoff describes payment flows, order creation, paid-state updates, and persistent account-status changes without any corresponding notice that charges may occur or that user state will be durably modified after payment. In a skill that directly brokers paid document generation, this omission can lead to unexpected charges, poor consent, and disputes over billing or entitlement state.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description uses broad marketing language like '跟AI说句话' and claims broad coverage across papers, PPTs, reports, resumes, and job materials. This can cause the skill to trigger in loosely related everyday contexts and collect or generate sensitive academic or employment content without clear user intent boundaries.

Content

No source excerpt is available for this finding.

External Model or Provider Selection

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill explicitly routes user-provided academic, employment, and document content to an external model/provider while also declaring read, write, exec, and web_fetch capabilities. Sending potentially sensitive documents to a third-party model without clear disclosure, retention limits, or provider trust boundaries creates a real confidentiality and data-governance risk.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
- write
  - exec
  - web_fetch
model: deepseek/deepseek-v4-flash
---

# 核心操作流程

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to upload their own .docx templates and later provide document content, but it does not warn that templates may contain personal data, institutional metadata, revision history, comments, or embedded objects. In a document-authoring workflow, this omission increases the chance users will expose sensitive files without informed consent or minimization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions require that English user requests be automatically translated into Chinese keywords and explicitly state searches must use Chinese category names. This imposes a language handling policy without user opt-in or an offered language choice, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is described as activating from extremely broad natural-language prompts such as '跟龙虾说句话,它就帮你搞定一切', without any narrow trigger phrase or scope boundary. This increases the chance of accidental invocation and unintended document-generation behavior in unrelated conversations, especially when the agent is embedded in a general-purpose assistant.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example prompts are common, everyday requests such as '帮我写毕业论文', '来份简历', and '做个答辩PPT', which are too generic to safely distinguish intentional skill use from ordinary chat. In an agent environment, these phrases could cause the skill to trigger unexpectedly and process sensitive user content or generate files without sufficiently explicit consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to execute npx clawhub install template-library-ai without pinning a specific version, which allows whatever version is current at install time to run. This creates a supply-chain risk: a compromised or maliciously updated package could execute code on the user's machine during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document instructs users to upload local files and send document contents to a remote backend at a hardcoded external IP address, but it does not prominently warn that potentially sensitive documents will leave the local environment. In a document/template workflow, this omission is meaningful because users may submit academic, corporate, or personal files containing confidential information without informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document predominantly describes a document/template generation skill: uploading templates, filling placeholders, previewing templates, and creating local .docx files. In that context, exposing create_api_key(name) and key_balance() introduces account-management and billing capabilities that are separate from the core template/document operations described in the rest of the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation includes credential-related and billing-related operations such as API key creation, balance checks, and payment/testing flows without warning about secret sensitivity or financial consequences. In an agent skill context, this increases the chance that an agent may create keys or trigger billable actions without adequately informing the user or handling the resulting credentials safely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Most of the file specifies template discovery, upload, preview, filling, and document generation behavior. pay_for_download(template_id) and especially test_pay_order(order_id) add commerce and payment-simulation functionality that is not necessary to perform document generation itself and is not justified by any stated purpose section for the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is entirely written in Chinese and prescribes exact Chinese user-facing payment prompts such as the required收费话术. This imposes a specific language/locale on the interaction without any opt-in, alternative language path, or justification that the skill is limited to a Chinese-only regulatory or regional context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger conditions are very broad and cover common requests such as writing documents, files, or finding templates. This can cause the skill to activate in contexts where the user did not intend document analysis or upsell flows, increasing the chance of inappropriate prompting for uploads, payment, or personal information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill encourages users to upload their own .docx or .pptx templates for analysis without warning that such files may contain sensitive personal, academic, or business information. This creates a privacy and data-exposure risk, especially because templates and documents often include metadata, comments, hidden text, or confidential formatting artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill collects sensitive personal data such as name, student ID, contact details, and employment history without any privacy notice, minimization guidance, or handling limitations. Users may disclose unnecessary personal information without understanding retention, exposure, or downstream use risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language strings in the docstring and CLI help are entirely in Chinese, which effectively forces a specific language for users. The file does not offer an opt-in language choice or explain that the skill is intentionally region- or locale-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language instructions and output entirely in Chinese, including the module docstring and usage guidance. Under the policy rule, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified, which it is not here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.