Back to skill

Security audit

知网查重与报告验真

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly scoped CNKI paper-checking workflow that uploads user-selected papers and manages public order/report steps without hidden payment, admin, or persistence behavior.

Install only if you intend to use this specific CQCCJY/CNKI public workflow and are comfortable uploading the selected paper file to the documented external service. Users should personally complete payment, card settlement, CAPTCHA, and verification steps in the browser and should not provide passwords or unrelated credentials to the skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill clearly instructs use of file access and networked operations, including reading local files for upload workflows and invoking external endpoints, but it does not declare any explicit tool scope or allowed-tools policy. This creates an authorization gap: an agent runtime may grant broader file or network capabilities than intended, making it easier for prompt injection, misconfiguration, or future skill changes to trigger overbroad access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire workflow is written only in Chinese and provides no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The display name, short description, and default prompt are entirely in Chinese, with no indication that users may select another language or locale. Under the language/locale policy rule, this is a natural-language policy concern because the skill appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest contains natural-language labels only in Chinese (e.g. payment channel labels) but does not document that the skill is intended only for Chinese-speaking users or a China-specific deployment. Under the policy, forcing a specific language without opt-in or justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title and the full operational instructions are written exclusively in Chinese, which imposes a specific language on users without any stated opt-in or alternative locale. Under the policy rule for natural-language violations, this is a language/locale constraint that is not justified as an explicit region-specific requirement in the document itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The instruction states that time comparisons must use Shanghai time, which imposes a specific locale/timezone behavior. The document does not indicate user opt-in or explain that this is a region-specific requirement, so it may violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON manifest contains all user-facing product names and price labels exclusively in Chinese, such as "知网本科/专科检测" and "¥18.00 / 篇", with no indication that the skill offers alternative language or locale options. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is reportable unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-facing errors and operational text in this file are written exclusively in Chinese, and the skill also hard-codes a CNKI-specific channel and workflow. This creates a locale/language restriction without any visible user opt-in or documented language choice mechanism in the file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_cnki_client.py:13