Back to skill

Security audit

Knowledge Engine

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a coherent personal knowledge manager, but it under-discloses privacy-relevant behavior in its visualization and persistent data handling.

Review this skill before installing. It stores personal knowledge, beliefs, contexts, and search usage in local plaintext files and SQLite; use --dry-run before prune and avoid putting highly sensitive material into the visualization until the remote D3 dependency is vendored or pinned and the HTML rendering is hardened. Prefer pinned installer versions or reviewed commits instead of mutable latest/head commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/visualize.py:58
Finding

Stored Script Injection in Generated Knowledge Graph HTML

Content
View full analysis
Remediation
View remediation
``` 3. Serialize the data with HTML-safe escaping, at minimum replacing `<`, `>`, `&`, U+2028, and U+2029 with Unicode escapes. For example: ```python data_json = json.dumps(data, ensure_ascii=False) data_json = ( data_json.replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` 4. Parse the inert data explicitly: ```javascript const DATA = JSON.parse( document.getElementById('graph-data').textContent ); ``` 5. Replace the tag `innerHTML` assignment with DOM construction using `textContent`: ```javascript const tagsElement = document.getElementById('ttTags'); tagsElement.replaceChildren(); for (const tag of d.tags) { const span = document.createElement('span'); span.className = 'tt-tag'; span.textContent = tag; tagsElement.appendChild(span); } ``` 6. Add a restrictive Content Security Policy that disallows inline scripts and limits outbound connections. 7. Add regression tests using values containing ``, HTML event handlers, quotes, backslashes, and Unicode line separators. 8. Replace the bundled sample data with a clearly defined, consistently handled data placeholder. ]]>

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/viz-template.html:184
Finding

Remote Unpinned JavaScript Executes with Access to Private Knowledge Data

Content
View full analysis
``` ### Technical Analysis The generated visualization loads and executes JavaScript from `https://d3js.org` whenever the user opens the graph with network connectivity. The dependency is not locally vendored, and the script element has no Subresource Integrity hash. The effective code executed by the visualization can therefore change after the Skill package has been reviewed. The remote script runs in the same document as the user's personal concepts, contexts, tags, and graph relationships. It can access that information through JavaScript globals or the document after initialization. This behavior directly contradicts the security declaration in `SKILL.md` that all operations are local and that no network requests are made. Loading D3 remotely is not necessary for the declared functionality because a reviewed copy can be bundled with the Skill. ### Attack Path 1. The user stores private concepts and beliefs in the Knowledge Engine. 2. The user generates and opens `knowledge-graph.html`. 3. The browser requests `https://d3js.org/d3.v7.min.js`. 4. A compromised CDN, publisher account, DNS/network path, or upstream release returns malicious JavaScript. 5. The browser executes that code in the knowledge-graph document. 6. The code waits for graph initialization or reads the page's data and D ...[truncated 719 chars]
Remediation
View remediation
``` 3. Record the expected cryptographic hash of the vendored file and verify it during release preparation. 4. If a remote dependency must be retained, pin an immutable version and add Subresource Integrity and `crossorigin` attributes. Vendoring is still preferable for a local-only Skill. 5. Add a Content Security Policy similar to: ```html ``` 6. Test the visualization while offline to ensure no network access is required. 7. Update the documentation so security claims accurately reflect actual behavior. ]]>

T08 · Insecure Dependencies

Warning
Location
README.md:71
Finding

Recommended Installation Executes a Mutable Unpinned npm Package

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prune command permanently deletes concepts, links, usage logs, and JSON files, which is materially more destructive than the skill description suggests. In a personal knowledge engine, silent or easy access to irreversible deletion can cause substantial data loss and undermine trust in the tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The prune path performs irreversible deletion of records and files without confirmation, increasing the likelihood of accidental or induced destructive actions. In a knowledge repository, that can permanently erase user data and associated metadata with no built-in recovery path.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/concept_synthesis.py (reported line 71)May include surrounding context.

python
}
            rules.append(rule)
    
    return rules


def generative_synthesis(conn, days=7):

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README prominently presents commands that search, add, link, decay, synthesize, and visualize knowledge while only later disclosing that data is persisted under memory/ and knowledge.db. In an agent-skill context, undocumented local writes are security-relevant because users or agents may invoke commands assuming read-only behavior, leading to unintended modification of persistent local state.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents command execution and local data storage/manipulation but does not declare an explicit tool scope such as allowed tools or permissions. That ambiguity can cause an agent runtime to grant broader-than-necessary file/environment access, increasing the risk of unintended reads/writes to local data when the skill is invoked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written as a Chinese-only user-facing invocation and behavior description, and the rest of the skill guidance is predominantly Chinese. There is no indication that users may interact in other languages or that the skill is intentionally limited to a Chinese-specific compliance or regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents the schema and examples primarily in Chinese, which effectively forces a specific language on users. The policy allows locale constraints only when users are given a choice or when the restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains user-facing natural-language instructions exclusively in Chinese, including the schema description, field explanations, and special-tag guidance. Under the policy criteria, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Search queries and context are persistently logged in usage_log without a visible consent or disclosure mechanism. In a personal knowledge tool, queries may contain sensitive thoughts, research topics, or private identifiers, so silent retention increases privacy risk and expands the impact of local compromise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code silently mutates concept confidence and status based on usage and age, which goes beyond a user expectation of merely viewing belief state. In a knowledge-management skill, hidden state mutation can corrupt or bias stored knowledge, especially because inactivity is treated as evidence for downgrading or deprecation.

Content

No source excerpt is available for this finding.

Tainted flow: 'card_path' from os.environ.get (line 371, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/concept_manager.py (reported line 372)May include surrounding context.

python
card["context"] = (existing_row["context"] or "") + merge_context
                card["updated_at"] = now
                card_path = os.path.join(CONCEPTS_DIR, f"{best_match[0]}.json")
                with open(card_path, "w", encoding="utf-8") as f:
                    json.dump(card, f, ensure_ascii=False, indent=2)
                
                conn.commit()

Tainted flow: 'card_path' from os.environ.get (line 538, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/concept_manager.py (reported line 416)May include surrounding context.

python
"updated_at": now
    }
    card_path = os.path.join(CONCEPTS_DIR, f"{concept_id}.json")
    with open(card_path, "w", encoding="utf-8") as f:
        json.dump(card, f, ensure_ascii=False, indent=2)

    conn.commit()

Tainted flow: 'card_path' from os.environ.get (line 538, credential/environment) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/concept_manager.py (reported line 539)May include surrounding context.

python
"updated_at": now
    }
    card_path = os.path.join(CONCEPTS_DIR, f"{concept_id}.json")
    with open(card_path, "w", encoding="utf-8") as f:
        json.dump(card, f, ensure_ascii=False, indent=2)

    conn.commit()

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Belief records are serialized to plaintext JSON files on disk in addition to the database, without an obvious warning to the user. Because beliefs and reasoning can be highly sensitive, duplicating them to filesystem storage broadens exposure and may surprise users who expect in-app storage only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and user-facing operational descriptions are entirely in Chinese, establishing a fixed language for the skill's behavior without offering the user a language or locale choice. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The argparse description and help string are user-facing text that constrain the interface to Chinese only. There is no visible language selection or justification for a Chinese-only locale, which conflicts with the policy against forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, usage examples, and command-line help text are written in Chinese and present the interface as Chinese-only. This creates a natural-language locale constraint without documenting user choice, opt-in, or a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents usage and output information only in Chinese, and later user-facing status/error messages are also Chinese-only. This imposes a specific language on users without opt-in or any documented reason that the skill is region- or locale-specific, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file explicitly sets the document language to zh-CN and presents the primary UI text in Chinese, which imposes a specific language/locale on users. Under the policy, locale constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill documentation is presented entirely in Chinese, including headings, usage guidance, and operational descriptions, with no indication that users may choose another language or that the skill is intentionally region-specific. This can amount to a language/locale policy issue because it implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This SVG contains user-facing labels entirely in Chinese, including the title and feature descriptions. Because SQP-3 applies to all file types and flags language-policy issues when a skill forces a specific language without user opt-in, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This SVG embeds multiple Chinese-only text labels, beginning at L025 and continuing throughout the graphic, with no indication that the skill is intended only for Chinese-speaking users or that alternative locales are supported. The policy explicitly flags language or locale constraints when they are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module description, comments, help text, and CLI output are written in Chinese, which imposes a specific language/locale on users. There is no indication of user opt-in, alternate locale support, or justification that this is a region-specific tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The manifest scope is personal knowledge management: search, add, track beliefs, distill, and visualize. Adding an 'eval' command suggests an evaluation-suite capability that is not justified by or explained in that scope, even though no handler is implemented in this file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.