T09 · Insecure Skill Coding Practices
- Location
intelligent_inspection.py:1498- Finding
Requested inspection scope is ignored
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an operations inspection tool, but its advertised scope controls do not work and it may run broader host and service checks than the user requested.
Review before installing. Run it only from an unprivileged account, avoid relying on --layers for containment until fixed, and treat exported reports as sensitive operational data. Do not schedule or run it with sudo unless you have reviewed exactly which checks will execute and where reports will be stored.
intelligent_inspection.py:1498Requested inspection scope is ignored
SKILL.md:128Dependency installation instructions use unpinned global packages
The title and the entire skill documentation are written as a Chinese-only interface contract, and the output format section defines report fields only in Chinese. There is no indication that users may choose another language or locale, which can violate a language/locale policy requiring opt-in or choice.
The README encourages exporting inspection reports and setting up scheduled report generation, but does not warn that such reports can contain sensitive operational details such as hostnames, OS versions, service presence, health status, and potentially internal topology clues. In an ops-inspection context, routinely generating and storing these reports increases the chance of unintended disclosure through weak file permissions, backups, shared directories, or log collection pipelines.
The README includes a cleanup command that permanently deletes report files older than 30 days, but provides no warning about irrecoverable data loss or the need to verify the working directory and filename pattern first. In operational environments, users may copy-paste this command into the wrong path or adapt it unsafely, causing accidental deletion of audit artifacts or other matching files.
The README advises running the inspection script with sudo/root privileges without clearly limiting when this is necessary or warning about the risks of executing a complex inspection tool with elevated rights. In this skill context, the tool appears to probe many subsystems and services, so running it as root expands the blast radius of any bug, unsafe shell invocation, or future extension added to the script.
This is a concrete instance of the root-execution guidance: the README explicitly tells users to run the script with sudo. Even though this is documentation rather than executable code, it normalizes elevated execution for a tool that inspects multiple services and may evolve over time, increasing the risk of system-wide impact if the script contains unsafe operations or is modified maliciously later.
部分巡检需要root权限:
sudo python3 intelligent_inspection.py
This Python skill’s top-level natural-language description is entirely in Chinese and presents the system as a fixed Chinese-language experience, with no indication that users may choose another language or locale. The policy for SQP-3 requires flagging language or locale constraints when they are forced without user opt-in or justification.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def check_service_running(self, service_name: str) -> bool:
"""检查服务是否运行"""
try:
result = subprocess.run(
['systemctl', 'is-active', service_name],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
def _check_inode(self):
"""Inode检查"""
try:
result = subprocess.run(
['df', '-i'],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
# 检查Redis是否运行
result = subprocess.run(
['redis-cli', 'ping'],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
return
# 获取Redis信息
info_result = subprocess.run(
['redis-cli', 'info'],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
mem_fragmentation_ratio = float(metrics.get('mem_fragmentation_ratio', 1.0))
# 慢查询
slowlog_result = subprocess.run(
['redis-cli', 'slowlog', 'len'],
capture_output=True,
text=True,
Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.
try:
if REQUESTS_AVAILABLE:
response = requests.get('http://localhost:9200/_cluster/health', timeout=5)
if response.status_code == 200:
health = response.json()
status = health.get('status', 'unknown')
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
return
try:
result = subprocess.run(
['rabbitmqctl', 'status'],
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
return
try:
result = subprocess.run(
['nginx', '-t'],
capture_output=True,
text=True,
The K8S inspection is labeled as simulated, but it still performs real host capability discovery by checking for kubectl. That mismatch can mislead users about the script's behavior, causing unintended environment probing and privacy-sensitive host enumeration in contexts where only mock behavior was expected.
The log inspection fabricates results instead of analyzing any logs, which can create false assurance or false alarms in operational workflows. In a security-sensitive or SRE setting, presenting invented telemetry as inspection output undermines trust and can directly lead to missed incidents or wasted response effort.
The business inspection produces fabricated business metrics while presenting them as actual checks, which is dangerous because operators may base decisions on nonexistent data. In monitoring software, invented success rates and latency values can conceal real outages or trigger unnecessary escalation.
The manifest presents a very broad operational inspection scope across host resources, middleware, Kubernetes, logs, business metrics, and planned security checks, but it does not define activation boundaries, target-scoping rules, or safety exclusions. In an agent setting, this can lead to over-collection of sensitive system and service data, unintended probing of production environments, or execution in contexts where the user did not intend such extensive inspection.
The manifest advertises JSON export capability but does not disclose where files are written, whether existing files may be overwritten, or whether exported reports contain sensitive operational data. This creates a risk of accidental data exposure, unsafe file placement, or destructive overwrite behavior when users enable export in automated or privileged environments.
No suspicious patterns detected.