Back to skill

Security audit

Zhihu Content Pack

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Zhihu content-workflow skill with local quality gates and citation checking, and I found no hidden credential use, destructive behavior, or automatic posting.

Install only if you want a Chinese-language Zhihu publishing workflow that may read local Zhihu CLI results, create local deliverable files and reports, and fetch user-provided citation URLs for verification. Review the package metadata/version mismatch and the strict branding/Chinese-style rules before relying on it in a broader multilingual or attribution-sensitive workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · 安全审计报告.md (reported line 27)May include surrounding context.

md
- 说明:仅在显式 `--selftest` 时创建临时样本目录,写本地、无网络、可用环境变量重定向。

## 📋 详细检查结果
- **命令执行与权限检查**: 0 命中(`curl|bash`/`eval`/`os.system`/`sudo`/`rm -rf /` 全部 0;delivery_guard.py 中 `subprocess` 仅存在于注释行 635)
- **文件操作与敏感路径检查**: 0 命中(无 `.ssh`/`.aws`/`.env`/credentials 读取;无系统路径写操作)
- **网络请求检查**: 仅 anchor_verify.py 的锚点核验 GET(声明功能);无 Base64 可疑载荷;无硬编码第三方域名
- **远程脚本深度分析**: 不适用——包内无自动下载+执行链路

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · 安全审计报告.md (reported line 27)May include surrounding context.

md
- 说明:仅在显式 `--selftest` 时创建临时样本目录,写本地、无网络、可用环境变量重定向。

## 📋 详细检查结果
- **命令执行与权限检查**: 0 命中(`curl|bash`/`eval`/`os.system`/`sudo`/`rm -rf /` 全部 0;delivery_guard.py 中 `subprocess` 仅存在于注释行 635)
- **文件操作与敏感路径检查**: 0 命中(无 `.ssh`/`.aws`/`.env`/credentials 读取;无系统路径写操作)
- **网络请求检查**: 仅 anchor_verify.py 的锚点核验 GET(声明功能);无 Base64 可疑载荷;无硬编码第三方域名
- **远程脚本深度分析**: 不适用——包内无自动下载+执行链路

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file explicitly instructs publishers to use only the brand name and forbids inclusion of personal real names, employer names, or internal paths. In an agent skill context, this can pressure the agent to suppress provenance, authorship, or organizational attribution in outward-facing outputs, reducing transparency and making it harder for users to assess trust, accountability, or conflicts of interest.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger scope is extremely broad: ordinary phrases like '发知乎', '写知乎文章', and '知乎回答' can cause the skill to activate across many loosely related requests. In an agent system, over-broad activation can hijack user intent, force unintended workflows, and trigger unnecessary tool use or policy-heavy behavior on tasks that only incidentally mention Zhihu.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill hard-enforces Chinese-language quotation conventions in visible output without checking user preference or task language, which can silently override user instructions and alter requested deliverables. In multi-skill or automated pipelines, this can corrupt output format, break style requirements, or cause unauthorized transformation of quoted text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, CLI description/help text, status output, and user-facing messages are consistently hard-coded in Chinese, with no option to select another language. This creates a language/locale policy concern because the skill effectively forces a specific language for interaction without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The package name is set to the Chinese string "未命名包" in the manifest, which is a natural-language artifact visible to users or operators. Because the file provides no indication that this skill is region-specific or that language is user-selectable, it may violate the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring says '零依赖:仅标准库' and lists only standard-library modules, implying the tool has no non-stdlib dependencies. However, the implementation later attempts to import pypdf to parse PDFs, so the documentation's dependency claim is not accurate as written.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request header hard-codes Accept-Language: zh-CN,zh;q=0.9,en;q=0.8, which imposes a specific locale preference on every outbound request. This is a natural-language policy concern because the tool does not offer the operator any language choice or document this as a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script writes a JSON report to the path supplied by --json using Path(args.json).write_text(...), which can overwrite or create files. While file output is expected for a reporting tool, this write operation has no preceding confirmation prompt, inline warning comment/docstring near the operation, or user-facing disclosure beyond the terse argument help text.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
tools/anchor_verify.py:117