T07 · Tool Hijacking and Spoofing
- Location
auto_llm_1644.py:5- Finding
Hard-Coded Import Path Enables Local Module Hijacking
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a small AI-report loader, but it has under-disclosed persistent knowledge-base writes and loads unaudited local Python code from a hard-coded path.
Install only if you intentionally want this skill to write Bilibili AI-report entries into a local knowledge base. Review and control the D:\\coze-local\\db learn module first, narrow the trigger, and avoid passing arbitrary user text unless the knowledge-base records can be reviewed and deleted.
auto_llm_1644.py:5Hard-Coded Import Path Enables Local Module Hijacking
auto_llm_1644.py:8Unvalidated User Input Is Written to Persistent Knowledge Storage
The trigger phrase "llm" is extremely broad and likely to appear in ordinary user conversation about AI topics, causing the skill to activate unintentionally. In this context, the skill is a generic content/reporting skill rather than a narrowly scoped command, so accidental invocation is more likely and can interfere with user intent or route requests to the wrong skill.
The file's title, docstring, and printed/stored content are entirely in Chinese, and there is no indication that the skill offers a language choice or that the locale restriction is documented as intentional. This can violate language/locale policy when users are not given an opt-in or alternative language path.
The skill presents itself as a weekly report but performs a persistent write into a local knowledge base, which is a capability mismatch. This can mislead users and reviewers about side effects, causing silent data creation or contamination of shared memory without clear consent or necessity.
The code imports a local KnowledgeBase and unconditionally calls store_concept using user-controlled input via param, despite the skill appearing to be a content/reporting utility. Unjustified write access increases the risk of knowledge-base poisoning, unwanted persistence, and abuse of shared state, especially if other components later trust this stored content.
The visible skill title, functionality, and trigger descriptions are entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-only audience. This can conflict with language/locale policy when no opt-in or justification is documented.
No suspicious patterns detected.