Back to skill

Security audit

运维智能巡检系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is an operations inspection tool, but its advertised scope controls do not work and it may run broader host and service checks than the user requested.

Review before installing. Run it only from an unprivileged account, avoid relying on --layers for containment until fixed, and treat exported reports as sensitive operational data. Do not schedule or run it with sudo unless you have reviewed exactly which checks will execute and where reports will be stored.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
intelligent_inspection.py:1498
Finding

Requested inspection scope is ignored

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:128
Finding

Dependency installation instructions use unpinned global packages

Content
View full analysis
Remediation
View remediation
requests== ``` 2. Publish a lock file containing cryptographic hashes and install with hash verification: ```bash python3 -m pip install --require-hashes -r requirements.lock ``` 3. Require an isolated virtual environment: ```bash python3 -m venv .venv .venv/bin/python -m pip install --require-hashes -r requirements.lock ``` 4. Document the expected trusted package index and warn users against untrusted mirrors or dependency overrides. 5. Avoid installing dependencies with root or administrator privileges. 6. Separate mandatory and optional dependencies so `requests` is installed only when Elasticsearch inspection is required. 7. Add automated dependency auditing and periodically review pinned versions for published vulnerabilities. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and the entire skill documentation are written as a Chinese-only interface contract, and the output format section defines report fields only in Chinese. There is no indication that users may choose another language or locale, which can violate a language/locale policy requiring opt-in or choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README encourages exporting inspection reports and setting up scheduled report generation, but does not warn that such reports can contain sensitive operational details such as hostnames, OS versions, service presence, health status, and potentially internal topology clues. In an ops-inspection context, routinely generating and storing these reports increases the chance of unintended disclosure through weak file permissions, backups, shared directories, or log collection pipelines.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README includes a cleanup command that permanently deletes report files older than 30 days, but provides no warning about irrecoverable data loss or the need to verify the working directory and filename pattern first. In operational environments, users may copy-paste this command into the wrong path or adapt it unsafely, causing accidental deletion of audit artifacts or other matching files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advises running the inspection script with sudo/root privileges without clearly limiting when this is necessary or warning about the risks of executing a complex inspection tool with elevated rights. In this skill context, the tool appears to probe many subsystems and services, so running it as root expands the blast radius of any bug, unsafe shell invocation, or future extension added to the script.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
96% confidence
Finding

This is a concrete instance of the root-execution guidance: the README explicitly tells users to run the script with sudo. Even though this is documentation rather than executable code, it normalizes elevated execution for a tool that inspects multiple services and may evolve over time, increasing the risk of system-wide impact if the script contains unsafe operations or is modified maliciously later.

Content

Scanner excerpt · README_INSPECTION.md (reported line 209)May include surrounding context.

权限不足

部分巡检需要root权限:

bash
sudo python3 intelligent_inspection.py

网络连接失败

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This Python skill’s top-level natural-language description is entirely in Chinese and presents the system as a fixed Chinese-language experience, with no indication that users may choose another language or locale. The policy for SQP-3 requires flagging language or locale constraints when they are forced without user opt-in or justification.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · intelligent_inspection.py (reported line 79)May include surrounding context.

python
def check_service_running(self, service_name: str) -> bool:
        """检查服务是否运行"""
        try:
            result = subprocess.run(
                ['systemctl', 'is-active', service_name],
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · intelligent_inspection.py (reported line 332)May include surrounding context.

python
def _check_inode(self):
        """Inode检查"""
        try:
            result = subprocess.run(
                ['df', '-i'],
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · intelligent_inspection.py (reported line 626)May include surrounding context.

python
try:
            # 检查Redis是否运行
            result = subprocess.run(
                ['redis-cli', 'ping'],
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · intelligent_inspection.py (reported line 646)May include surrounding context.

python
return
            
            # 获取Redis信息
            info_result = subprocess.run(
                ['redis-cli', 'info'],
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · intelligent_inspection.py (reported line 677)May include surrounding context.

python
mem_fragmentation_ratio = float(metrics.get('mem_fragmentation_ratio', 1.0))
                
                # 慢查询
                slowlog_result = subprocess.run(
                    ['redis-cli', 'slowlog', 'len'],
                    capture_output=True,
                    text=True,

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · intelligent_inspection.py (reported line 916)May include surrounding context.

python
try:
            if REQUESTS_AVAILABLE:
                response = requests.get('http://localhost:9200/_cluster/health', timeout=5)
                if response.status_code == 200:
                    health = response.json()
                    status = health.get('status', 'unknown')

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · intelligent_inspection.py (reported line 972)May include surrounding context.

python
return
        
        try:
            result = subprocess.run(
                ['rabbitmqctl', 'status'],
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · intelligent_inspection.py (reported line 1025)May include surrounding context.

python
return
        
        try:
            result = subprocess.run(
                ['nginx', '-t'],
                capture_output=True,
                text=True,

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The K8S inspection is labeled as simulated, but it still performs real host capability discovery by checking for kubectl. That mismatch can mislead users about the script's behavior, causing unintended environment probing and privacy-sensitive host enumeration in contexts where only mock behavior was expected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The log inspection fabricates results instead of analyzing any logs, which can create false assurance or false alarms in operational workflows. In a security-sensitive or SRE setting, presenting invented telemetry as inspection output undermines trust and can directly lead to missed incidents or wasted response effort.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The business inspection produces fabricated business metrics while presenting them as actual checks, which is dangerous because operators may base decisions on nonexistent data. In monitoring software, invented success rates and latency values can conceal real outages or trigger unnecessary escalation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest presents a very broad operational inspection scope across host resources, middleware, Kubernetes, logs, business metrics, and planned security checks, but it does not define activation boundaries, target-scoping rules, or safety exclusions. In an agent setting, this can lead to over-collection of sensitive system and service data, unintended probing of production environments, or execution in contexts where the user did not intend such extensive inspection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest advertises JSON export capability but does not disclose where files are written, whether existing files may be overwritten, or whether exported reports contain sensitive operational data. This creates a risk of accidental data exposure, unsafe file placement, or destructive overwrite behavior when users enable export in automated or privileged environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.