Back to skill

Security audit

1

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Tencent Cloud CLI helper, but users should deliberately approve installation, login, and any cloud-changing commands.

Install tccli only from sources you trust, preferably with a pinned or reviewed version. Do not let the agent start OAuth login or run create, modify, or delete cloud commands unless you intended that exact action and account/profile. Never paste SecretId or SecretKey into the chat or ask the agent to print stored credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/install.md:8
Finding

Unpinned Third-Party CLI Installation Enables Supply-Chain Code Execution

Content
View full analysis
Remediation
View remediation
" ``` 2. Use a lock file or requirements file containing cryptographic hashes, and install with hash verification: ```sh python3 -m pip install --require-hashes -r requirements.txt ``` 3. Pin all transitive dependencies or use a reproducible dependency-locking process so dependency resolution cannot silently change after review. 4. If source installation must remain available, clone or fetch a reviewed release and check out an immutable commit hash. Verify the release signature or published checksum before installation. 5. Replace the deprecated `python setup.py install` workflow with a modern, reviewed build artifact and installer. Do not execute code directly from a mutable default branch. 6. Pin the Homebrew formula or document a verified release and integrity-checking procedure rather than relying on the current state of a mutable external tap. 7. Recommend installation in a dedicated virtual environment under a non-administrative account. Explicitly warn users not to use `sudo` or administrator privileges unless a separately justified deployment requirement exists. 8. Document the expected publisher, repository, version, checksum, and verification steps so users can validate that the downloaded artifact is authentic before execution. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's instructional content is presented entirely in Chinese and uses directive language such as '统一使用', without offering the user a language choice or documenting a justified locale restriction. The policy for SQP-3 applies to all file types and flags language/locale constraints imposed without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to run tccli auth login, which launches a browser-based OAuth flow, opens a local callback port, and blocks until completion, but the documentation does not require explicit user confirmation immediately before doing so. In an agent setting, initiating interactive authentication or opening local listeners without a clear warning can surprise the user, alter host state, and create unnecessary exposure if done automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document forces a specific language for all user-facing instructions, which can violate language/locale policy when no opt-in or alternative is provided. There is no indication that this skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all installation instructions in Chinese and does not indicate that the skill is intentionally region-specific or provide any user language choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill documentation is written only in Chinese and provides no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or China-specific audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.