Back to skill

Security audit

Auto Llm 4712

Security checks for vulnerabilities and agentic risk

Overview

This skill appears related to saving a Chinese LLM learning/report item, but it writes to persistent local knowledge storage through an unaudited external Python module path.

Review this before installing. It should only be used if you intend invocations to write entries into a local knowledge base and you trust the local D:\\coze-local\\db learn module. Narrow the trigger, disclose and confirm persistent writes, and avoid storing arbitrary caller text without validation or deletion controls.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
auto_llm_4712.py:5
Finding

External Module Search-Path Precedence Enables Arbitrary Code Execution

Content
View full analysis

Vulnerability Details

File Location: auto_llm_4712.py, lines 5-11
Vulnerability Type: Untrusted module loading through Python search-path manipulation
Risk Level: High

Vulnerable Code:

python
import sys
sys.path.insert(0, r"D:\\coze-local\\db")

def run(param=""):
    """AI 大模型周报 2026年5月 e(附链接)"""
    print(f"[auto_llm_4712] AI 大模型周报 2026年5月 e(附链接)")
    from learn import KnowledgeBase

Technical Analysis

The script inserts the hard-coded external directory D:\coze-local\db at index zero of sys.path. Python will consequently search this directory before standard package locations when resolving from learn import KnowledgeBase.

The learn module is not included in the audited project, so its implementation and integrity cannot be verified. If an attacker can create or modify learn.py, or a matching learn package, in the external directory, Python will execute attacker-controlled module-level code as soon as the import occurs. Attacker-controlled behavior may also execute when KnowledgeBase is instantiated or its methods are called.

This is an insecure module-loading pattern because the effective executable code is determined by mutable state outside the audited package.

Attack Path

  1. An attacker obtains write access to D:\coze-local\db, whether through permissive directory permissions, another compromised process, or an existing account with access.
  2. The attacker creates or replaces learn.py, or creates a learn package, containing malicious Python code and a compatible KnowledgeBase symbol.
  3. A user or Agent invokes auto_llm_4712.py.
  4. The script places the attacker-controlled directory first in sys.path.
  5. from learn import KnowledgeBase resolves to the attacker's module.
  6. Python executes the malicious module under the privileges of the process running the skill.

Impact Assessment

Successful exploitation permits arbitrary Python c ...[truncated 570 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the runtime sys.path.insert() modification.
  • Package learn as part of the skill or install it as a pinned, trusted dependency through the deployment system.
  • Import the dependency through an explicit package namespace rather than an ambiguous top-level module name.
  • Verify dependency integrity using locked versions and cryptographic hashes.
  • Ensure application directories and dependency locations are not writable by untrusted users.
  • Fail closed when the trusted dependency is unavailable instead of searching mutable external locations.
  • If external loading is unavoidable, resolve a canonical path, verify ownership and permissions, validate an expected cryptographic digest, and load only the verified file.

T02 · Agent Memory Poisoning

Warning
Location
auto_llm_4712.py:8
Finding

Unvalidated Caller Input Is Written to Persistent Knowledge Storage

Content
View full analysis

Vulnerability Details

File Location: auto_llm_4712.py, lines 8-16
Vulnerability Type: Persistent knowledge-base poisoning
Risk Level: Medium

Vulnerable Code:

python
def run(param=""):
    """AI 大模型周报 2026年5月 e(附链接)"""
    print(f"[auto_llm_4712] AI 大模型周报 2026年5月 e(附链接)")
    from learn import KnowledgeBase
    kb = KnowledgeBase()
    kb.store_concept("[Auto] AI 大模型周报 2026年5月 e(附链接)", "auto_llm_4712", param or "AI 大模型周报 2026年5月 e(附链接)",
                     "Source: https://www.bilibili.com/video/BV1d2Vh6EE1t",
                     ["auto"] + ['llm'])
    kb.close()

Technical Analysis

The param argument is passed directly to KnowledgeBase.store_concept() without validation, normalization, length limits, trust metadata, or user confirmation. When the script is run directly, param is assembled from arbitrary command-line arguments. This allows caller-controlled text to be stored in persistent knowledge state.

If downstream Agent workflows retrieve this value and treat it as trusted knowledge or instructions, an attacker could persist misleading information or instruction-like content that affects future sessions. The risk arises from crossing a trust boundary: untrusted invocation input is converted into long-lived application state without controls.

The implementation of KnowledgeBase is outside the audited project. Therefore, the exact storage duration, retrieval semantics, and any downstream interpretation cannot be confirmed from the available files. No direct database injection or code execution through param is established by the audited evidence.

Attack Path

  1. An attacker or untrusted caller invokes the skill with crafted param content, potentially containing false claims or instruction-like text.
  2. The run() function passes that content unchanged to store_concept().
  3. The external knowledge-base implementation persists the supplied content as an aut ...[truncated 867 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not persist caller-provided text unless persistence is explicitly required and authorized.
  • Require clear user confirmation before writing input into long-term knowledge storage.
  • Enforce a strict schema, permitted character policy, and conservative length limit.
  • Store provenance, caller identity, timestamp, and an explicit untrusted classification with every caller-supplied entry.
  • Keep user content in a data-only field that downstream prompt construction cannot interpret as system or developer instructions.
  • Escape or delimit stored content when incorporating it into later prompts.
  • Apply authorization controls to knowledge-base writes and restrict which workflows may create durable concepts.
  • Support review, expiration, rollback, and deletion of stored entries.
  • Audit downstream retrieval code to ensure retrieved knowledge never overrides higher-priority instructions.
  • Use try/finally or a context manager to ensure the knowledge-base connection is closed even when storage fails.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrase "llm" is extremely broad and likely to collide with normal user conversation about language models. This can cause the skill to activate unintentionally, hijack unrelated requests, and route users into behavior they did not explicitly request. In this context, the skill is just a content/news skill, which lowers direct security impact, but the broad trigger still creates avoidable invocation and prompt-routing risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is presented as a weekly report item, but its actual behavior writes content into a local knowledge base. This mismatch is dangerous because users or orchestrators may invoke it expecting a read-only/reporting action while it performs persistent state changes, which can enable hidden data ingestion, poisoning, or unauthorized accumulation of content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code modifies a local knowledge base by calling KnowledgeBase().store_concept() even though the skill description does not justify persistent storage. Unnecessary writes are risky because they create hidden side effects, can poison downstream retrieval or agent behavior, and may persist attacker-controlled input from the param argument into shared state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill content and trigger phrases are entirely presented in Chinese, with no indication that users may choose another language or locale. This can constitute a language-policy issue when the skill implicitly requires one language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file’s natural-language strings are entirely in Chinese, including the module description, function docstring, console output, and stored concept title. There is no indication that the skill is region-specific or that the user can opt into a preferred language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.