Back to skill

Security audit

Deep Read

Security checks for vulnerabilities and agentic risk

Overview

This skill is a transparent book-analysis helper, but its dependency list should be tightened before installation.

Before installing, consider removing unused dependencies and pinning any required packages to reviewed versions. Only provide book files or notes you intend to have analyzed, especially if they contain private or copyrighted material. Expect the current skill to behave as a Chinese-language placeholder unless its model integration is completed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unnecessary Third-Party Dependencies

Content
View full analysis
=0.27.0 pandas markdown obsidian-api ``` ### Technical Analysis The dependency manifest does not pin any package to an exact, reviewed version. The `openai` requirement permits every version from `0.27.0` onward, including potentially incompatible future major releases, while the other three requirements have no version constraints at all. The implementation does not use `pandas`, `markdown`, or `obsidian-api`. It imports `openai` in `deep_read_generator.py`, but does not invoke it. Consequently, installation introduces a substantially larger third-party supply-chain footprint than the implemented placeholder behavior requires. Because package versions remain mutable, separate installations can resolve to different artifacts. If an allowed package version or one of its transitive dependencies is compromised, dependency installation may execute attacker-controlled installation logic or introduce malicious runtime code. No malicious package or active compromise was found in the audited project; the risk arises from uncontrolled future dependency resolution and unnecessary package installation. ### Attack Path 1. A user or deployment system installs the dependencies from `requirements.txt`. 2. The package resolver selects the latest versions satisfying the broad or absent constraints. 3. A selected direct or transitive dependency has been compromised, maliciously updated, or otherwise contains unsafe installation behavior. 4. The package manager downloads and installs that mutable artifact. 5. Installation hooks or subsequently imported package code execute with the permissions of the installation or runtime process. 6. The malicious dependency can access data and resources available to that process. ### Impact ...[truncated 581 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language instructions and field descriptions are presented exclusively in Chinese, which can amount to a language-policy constraint if the skill implicitly requires that locale without user opt-in. The file does not indicate that the tool is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file uses Chinese for the display name, description, parameters, outputs, and tags, but does not indicate that the skill is region-specific or provide any user opt-in for language preference. This can violate a language/locale policy when users are expected to be able to choose their preferred language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language description and parameter documentation are written in Chinese and indicate the skill implements deep reading analysis in that language, but there is no user choice or opt-in for language/locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill's behavior as producing analysis in that language, but it does not mention any user-selectable language option or justify a Chinese-only scope. This creates a natural-language locale policy concern because the skill appears to impose a specific language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown file describes inputs including a book file and user notes, which may contain personal or copyrighted material, but it provides no user-facing warning about data handling or privacy implications. Under the markdown-specific SQP-2 criteria, descriptions should warn when behavior could affect user data or privacy.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The 'openai>=0.27.0' specifier sets only a lower bound, so dependency resolution may install any later version, including versions with incompatible behavior or undiscovered security issues. This is less strict than exact pinning and still leaves the build non-reproducible.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
openai>=0.27.0
pandas
markdown
obsidian-api

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency 'pandas' is not pinned to a specific version, so installs may resolve to different releases over time. This weakens build reproducibility and can unexpectedly introduce vulnerable or breaking versions through normal dependency resolution or supply-chain compromise.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
openai>=0.27.0
pandas
markdown
obsidian-api

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The manifest does not pin the 'pandas' version, and there is at least one known advisory affecting some releases. Because the installed version is unknowable from this file, the project may resolve to an affected version and expose itself to dependency-level risk.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency 'markdown' is unpinned, which means different environments may install different versions, including newly released vulnerable versions. This creates avoidable supply-chain and reproducibility risk for the skill.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
openai>=0.27.0
pandas
markdown
obsidian-api

Unverifiable Dependency: markdown has 2 known advisory(ies) (CVE-2025-69534 (Python-Markdown has an Uncaught Exception); CVE-2025-69534 (Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like se)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The unpinned 'markdown' dependency has known advisories in some versions, but the manifest does not identify which release will actually be installed. That uncertainty makes it impossible to verify safety and may allow deployment with a vulnerable version.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency 'obsidian-api' is specified without a version constraint, allowing arbitrary future versions to be installed. That increases exposure to accidental breaking changes or malicious/vulnerable upstream releases.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
openai>=0.27.0
pandas
markdown
obsidian-api

Static analysis

No suspicious patterns detected.