T09 · Insecure Skill Coding Practices
- Location
mcp_tool_maker.py:24- Finding
Generated Python Code Injection Through an Unsanitized Module Name
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an MCP code generator, but it can create unsafe wrappers that expose broad local code as tools and can be manipulated through generated Python source.
Install only for controlled local experiments. Review generated code before adding it to an MCP server, use only trusted source files with simple valid module names, avoid writing output over existing server files, and do not expose generated tools until each function has been explicitly approved.
mcp_tool_maker.py:24Generated Python Code Injection Through an Unsanitized Module Name
mcp_tool_maker.py:15Unrestricted Exposure of Public and Nested Functions as MCP Tools
The skill contains extensive mojibake/mixed-script text, which obscures its real behavior and makes human review unreliable. Obfuscated or malformed text can hide risky instructions, capabilities, or trigger conditions, increasing the chance that unsafe functionality is approved or invoked without proper scrutiny.
The skill appears capable of generating code and writing output files, but it declares no explicit tool scope or permissions. In practice this can enable silent file modification or code generation side effects beyond what a reviewer or runtime policy expects, especially because the description explicitly mentions writing generated content into files and integrating into server code.
The trigger phrases are broad phrases like requests to generate tools or scan functions, which can overlap with ordinary user requests. This raises the risk of unintended activation, causing the skill to run code-generation or file-writing workflows when the user did not explicitly request this specific skill.
The secondary trigger section uses ambiguous keywords and loose activation language, including generic terms associated with help or the skill topic. In context, this broadens the skill's activation surface and can cause accidental routing to a skill that may generate or write files, compounding the risk created by undeclared write capability.
The module docstring is entirely in Chinese and presents the skill's purpose and usage in a single language with no opt-in or alternative locale. Under the policy, a skill should not impose a language or locale unless it is explicitly optional or clearly justified as region-specific.
compile() creates code objects from strings. When combined with exec()/eval(), it enables obfuscated code execution.
with open(filepath, encoding="utf-8") as f:
source = f.read()
tree = compile(source, filepath, 'exec', ast.PyCF_ONLY_AST)
functions = []
for node in ast.walk(tree):
The generated code forcibly prepends a fixed local directory to sys.path, altering Python module resolution at runtime. This can cause imports to load unintended local modules, widen trust boundaries, and make the generated tool depend on a sensitive machine-specific path, increasing the risk of unsafe or surprising code execution.
The skill hard-codes a list of specific local project files and exposes their presence and sizes through the list command. For a generic MCP tool generator, this unnecessarily reveals local environment structure and encourages access to unrelated files, which can aid reconnaissance and accidental overreach.
No suspicious patterns detected.