Back to skill

Security audit

Four Dimensional Deep Reading

Security checks for vulnerabilities and agentic risk

Overview

This is a real deep-reading helper, but it needs review because it can automatically search the web, save/export reports, and run spawned agents on untrusted content without strong safeguards.

Install only if you are comfortable with automatic web lookups, workspace report/cache persistence, and multi-agent analysis. Avoid using it on private, unpublished, or sensitive documents unless you first disable external lookup and autosave behavior; use Notion export only when you intentionally want the report content sent to Notion.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/parallel_analysis.py:746
Finding

Untrusted Book Content Is Embedded Directly into Subagent Instructions

Content
View full analysis
List[Dict]: """ Generate tasks for all 4 personas to be executed in parallel. Args: book_content: The book content to analyze book_name: Name of the book language: Output language (en/zh/ja/ko/fr/de/es/pt/ru) Returns a list of task configurations for sessions_spawn. """ random_identity = get_random_identity(language) tasks = [] for persona_id in PERSONAS.keys(): persona_name = get_persona_name(persona_id, language) instruction = get_persona_instruction(persona_id, language) if persona_id == "random_variable_x": if language == "en": instruction = instruction.replace( "## 🎲 Random Identity: [Role Name]", f"## 🎲 Random Identity: {random_identity['name']}" ) elif language == "zh": instruction = instruction.replace( "## 🎲 随机身份:[角色名称]", f"## 🎲 随机身份:{random_identity['name']}" ) elif language == "ja": instruction = instruction.replace( "## 🎲 ランダムアイデンティティ:[役割名]", f"## 🎲 ランダムアイデンティティ:{random_identity['name']}" ) elif language == "ko": instruction = instruction.replace( "## 🎲 무작위 정체성: [역할 이름]", f"## 🎲 무작위 정체성: {random_identity['name']}" ) if language in ["en", "zh", "ja", "ko"]: instruction += f"\n\nSelected identity: {random_iden ...[truncated 3319 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:5
Finding

Third-Party Dependencies Are Not Reproducibly Pinned

Content
View full analysis
=0.10.0 # EPUB parsing ebooklib>=0.18 beautifulsoup4>=4.12.0 lxml>=4.9.0 # ==================== # Export Utilities (v1.8.0+) # ==================== # Anki export: No additional dependencies needed # Obsidian export: No additional dependencies needed # Notion export (optional, for Notion integration) notion-client>=2.0.0 ``` The installation workflow is also documented in `SKILL.md:2648-2660`: ```bash pip install pdfplumber ebooklib beautifulsoup4 lxml pip install -r requirements.txt ``` ### Technical Analysis Every dependency uses an open-ended lower bound. A future installation can therefore resolve to package versions that did not exist and were not reviewed when the Skill was audited. The direct `pip install` command is even less constrained because it does not specify any version. The package names appear to be conventional PyPI package names; the audit found no custom package index, direct untrusted URL, obvious typosquatting, or known malicious package embedded in the project. The issue is the absence of reproducible version and artifact controls, not evidence that the currently named packages are malicious. Python packages can execute build-backend or setup-related code during installation, and imported packages execute module initialization code at runtime. Consequently, compromise of a future release or an unsafe dependency-resolution environment could affect the account installing or running the Skill. ### Attack Path 1. A user follows the documented command or installs `requirements.txt`. 2. The package resolver selects the latest release satisfying each `>=` constraint. 3. ...[truncated 1075 chars]
Remediation
View remediation
ebooklib== beautifulsoup4== lxml== notion-client== ``` 2. Generate a lock file that includes all transitive dependencies. 3. Record and enforce package hashes, for example with: ```bash pip install --require-hashes -r requirements.lock ``` 4. Install from an explicitly trusted package index and disable unintended extra indexes where operationally possible. 5. Keep optional dependency groups separate: - Base installation with no parsing integrations. - PDF/EPUB parsing extras. - Notion export extra only when requested. 6. Run installation and parsing in a non-root, isolated virtual environment or container with minimal filesystem and network permissions. 7. Add automated dependency vulnerability scanning and review dependency updates before changing the lock file. 8. Document the tested Python version and platform because packages such as `lxml` may use platform-specific binary wheels. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (42)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 2194)May include surrounding context.

md
- **Japanese (ja)**: Complete role names and descriptions
- **Korean (ko)**: Complete role names and descriptions

For other languages (FR/DE/ES/PT/RU), the system falls back to English with output instruction in target language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 2195)May include surrounding context.

md
- **Japanese (ja)**: Complete role names and descriptions
- **Korean (ko)**: Complete role names and descriptions

For other languages (FR/DE/ES/PT/RU), the system falls back to English with output instruction in target language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 2196)May include surrounding context.

md
- **Japanese (ja)**: Complete role names and descriptions
- **Korean (ko)**: Complete role names and descriptions

For other languages (FR/DE/ES/PT/RU), the system falls back to English with output instruction in target language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 2197)May include surrounding context.

md
- **Japanese (ja)**: Complete role names and descriptions
- **Korean (ko)**: Complete role names and descriptions

For other languages (FR/DE/ES/PT/RU), the system falls back to English with output instruction in target language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 2198)May include surrounding context.

md
- **Japanese (ja)**: Complete role names and descriptions
- **Korean (ko)**: Complete role names and descriptions

For other languages (FR/DE/ES/PT/RU), the system falls back to English with output instruction in target language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 2212)May include surrounding context.

md
- **Japanese (ja)**: Complete role names and descriptions
- **Korean (ko)**: Complete role names and descriptions

For other languages (FR/DE/ES/PT/RU), the system falls back to English with output instruction in target language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · reference/identity_modules.md (reported line 221)May include surrounding context.

md
- **Japanese (ja)**: Complete role names and descriptions
- **Korean (ko)**: Complete role names and descriptions

For other languages (FR/DE/ES/PT/RU), the system falls back to English with output instruction in target language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/parallel_analysis.py (reported line 732)May include surrounding context.

python
- **Japanese (ja)**: Complete role names and descriptions
- **Korean (ko)**: Complete role names and descriptions

For other languages (FR/DE/ES/PT/RU), the system falls back to English with output instruction in target language.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/parallel_analysis.py (reported line 659)May include surrounding context.

python
}
}

# Additional language output instructions (for languages without complete templates)
ADDITIONAL_LANG_INSTRUCTIONS = {
    "fr": "Important: Output all analysis in French (Français).",
    "de": "Important: Output all analysis in German (Deutsch).",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/parallel_analysis.py (reported line 726)May include surrounding context.

python
if language in PERSONA_INSTRUCTIONS:
        instructions = PERSONA_INSTRUCTIONS[language]
        if persona_id in instructions:
            return instructions[persona_id]
    
    # Fallback to English template
    instructions = PERSONA_INSTRUCTIONS.get(FALLBACK_LANG, {})

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Export triggers like '导出到笔记', '一键导出', or '全部导出' are generic phrases that can collide with unrelated user intents. Because export writes files and may synchronize content to external systems such as Notion, accidental trigger matching can cause unintended data disclosure or persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes automatic searches across third-party sites for reviews and metadata without clearly warning that user-supplied titles, links, and possibly uploaded content-derived details may be transmitted externally. This creates a privacy and confidentiality risk, especially if users provide sensitive, proprietary, or unpublished materials expecting local-only analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Speed-mode keywords include very generic phrases like 'summarize' and 'brief overview,' which commonly appear in normal conversation. That increases the risk of accidental skill execution, especially since even the reduced mode still initiates analysis behavior and auto-save workflows described elsewhere in the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill defaults to automatically saving reports and downloaded link content to local workspace storage without a clear consent warning. For sensitive books, private documents, or user-uploaded files, silent persistence increases risk of later disclosure through workspace sharing, backups, retention, or access by other tools/processes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger conditions and examples are broad enough to match ordinary requests like 'analyze this file' or 'summarize this book,' which can cause unintended activation of the skill. In context, that matters because this skill automatically performs external retrieval, parallel subagent execution, and report persistence, so accidental invocation can lead to unnecessary data exposure and side effects.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The changelog at L3037 says '移除subprocess,仅保留纯Python' (removed subprocess, pure Python only), and earlier dependency sections also state no system binaries are required. However, the same file later documents PDF parsing via pdftotext and MOBI conversion via calibre, both external binaries, which directly contradicts the stated implementation intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The configuration maps 'en' and 'default' to English-language sources such as Goodreads, English Wikipedia, and Google Books, while no mechanism is provided for users to opt into or override that locale choice. This is a natural-language policy concern because the skill operationalizes a specific language preference implicitly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The language detection logic falls back to 'en' for any text that is not detected as Chinese, Japanese, or Korean. Combined with the source selection configuration, this imposes an English locale by default rather than letting the user choose a preferred language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document states that for FR/DE/ES/PT/RU, the system falls back to English while only instructing output in the target language. This creates a language-policy issue because users of those locales are forced into English processing behavior without an explicit choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The onboarding API returns English whenever the requested language code is unsupported. This forces a specific language choice rather than offering a user-controlled fallback or explicit notice, which can violate language/locale policy expectations for user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Public APIs in this file set language: str = "zh" by default, and the module docstrings and CLI messages are also Chinese-centric. This can amount to a language-policy violation because the skill imposes a specific language/locale by default rather than asking the user or clearly making it an opt-in choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The Obsidian export API exposes a language parameter but defaults it to zh, which biases output toward a single locale without user opt-in. The same pattern appears across this module, indicating a systematic locale constraint rather than a one-off implementation detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This function sets language: str = "zh" by default, continuing the module-wide pattern of forcing a specific language setting. Because no user choice is required before applying that locale, it may violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Notion export function transmits the full report content and derived flashcards to an external third-party service, but neither the function contract nor the CLI flow provides an explicit warning, confirmation, or data-classification check before exfiltration. In a reading/analysis skill, reports may contain copyrighted material, private notes, or sensitive text, so silent remote export increases privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/export_utils.py (reported line 350)May include surrounding context.

python
"error": "请安装notion-client: pip install notion-client"
        }
    
    client = Client(auth=notion_api_key)
    parser = AnalysisReportParser(report_content, book_title, language)
    
    # 创建页面

Static analysis

No suspicious patterns detected.