Back to skill

Security audit

Auto Llm 1644

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small AI-report loader, but it has under-disclosed persistent knowledge-base writes and loads unaudited local Python code from a hard-coded path.

Install only if you intentionally want this skill to write Bilibili AI-report entries into a local knowledge base. Review and control the D:\\coze-local\\db learn module first, narrow the trigger, and avoid passing arbitrary user text unless the knowledge-base records can be reviewed and deleted.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
auto_llm_1644.py:5
Finding

Hard-Coded Import Path Enables Local Module Hijacking

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
auto_llm_1644.py:8
Finding

Unvalidated User Input Is Written to Persistent Knowledge Storage

Content
View full analysis
1 else "") ``` ### Technical Analysis The `param` argument is accepted from either an external caller or unrestricted command-line arguments and is passed directly to `KnowledgeBase.store_concept()`. The code applies no validation, size restriction, normalization, provenance marking, or approval step before persistence. An attacker can therefore submit text containing misleading facts, adversarial instructions, or content designed to influence later agent behavior. Because the record is stored under an automatic report title and trusted-looking source URL, later consumers may incorrectly treat attacker-supplied text as report content. The precise persistence duration and retrieval behavior depend on the external `learn.KnowledgeBase` implementation, which is absent from the project. The confirmed exposure is the direct passage of uncontrolled input into the storage API; downstream agent influence is conditional on stored concepts being retrieved and treated as trusted context. ### Attack Path 1. The attacker invokes the script with crafted command-line text or calls `run()` with a malicious `param` value. 2. The script concatenates command-line arguments wit ...[truncated 930 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger phrase "llm" is extremely broad and likely to appear in ordinary user conversation about AI topics, causing the skill to activate unintentionally. In this context, the skill is a generic content/reporting skill rather than a narrowly scoped command, so accidental invocation is more likely and can interfere with user intent or route requests to the wrong skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file's title, docstring, and printed/stored content are entirely in Chinese, and there is no indication that the skill offers a language choice or that the locale restriction is documented as intentional. This can violate language/locale policy when users are not given an opt-in or alternative language path.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents itself as a weekly report but performs a persistent write into a local knowledge base, which is a capability mismatch. This can mislead users and reviewers about side effects, causing silent data creation or contamination of shared memory without clear consent or necessity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code imports a local KnowledgeBase and unconditionally calls store_concept using user-controlled input via param, despite the skill appearing to be a content/reporting utility. Unjustified write access increases the risk of knowledge-base poisoning, unwanted persistence, and abuse of shared state, especially if other components later trust this stored content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The visible skill title, functionality, and trigger descriptions are entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-only audience. This can conflict with language/locale policy when no opt-in or justification is documented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.