Back to skill

Security audit

设计框架套件 - 框架生成器

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Telegram design automation, but it automatically transmits design content through unreviewed external scripts and services, so users should review it before installing.

Install only if you are comfortable sending design requirements and generated previews to Telegram and OpenRouter, and first verify the exact design-framework-sender implementation, its credentials handling, endpoints, attachment behavior, and lock cleanup. Avoid using this with confidential client or product plans until those boundaries are explicit.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:12
Finding

Predictable Global Temporary-Directory Lock Enables Local Denial of Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 12-16
Vulnerability Type: Predictable and unmanaged temporary lock
Risk Level: Medium

Vulnerable Code Snippet

markdown
The skill is triggered when a group message contains the configured mention and `/tmp/design-framework-lock` does not exist.

## Execution Process

1. **Atomic lock**: `mkdir /tmp/design-framework-lock` to prevent concurrent execution.

The snippet above is an English rendering of the documented behavior at the cited location. The security-relevant literal path and command are reproduced exactly.

Technical Analysis

The skill uses the fixed, system-wide path /tmp/design-framework-lock both as a trigger condition and as its concurrency lock. Although mkdir provides atomic creation, the documentation does not specify:

  • Validation of the directory's owner or permissions.
  • A private, owner-restricted runtime directory.
  • A process identifier or other mechanism for determining whether the lock is active.
  • Stale-lock detection and recovery.
  • Guaranteed cleanup through a shell trap or equivalent mechanism.

On a multi-user host, another local process may create this predictable path before the skill runs. Because the absence of that path is explicitly required for triggering, pre-creation can prevent legitimate jobs from starting. A worker crash can also leave the directory behind and cause a persistent denial of service until manual cleanup.

This issue does not provide additional operating-system privileges. Exploitation requires sufficient local filesystem access to create an entry under /tmp.

Attack Path

  1. An attacker or untrusted local process creates /tmp/design-framework-lock.
  2. A legitimate Telegram message containing the configured mention arrives.
  3. The skill checks whether the fixed lock path exists.
  4. Because the attacker-created directory already exists, the trigger condition fails ...[truncated 613 chars]
Remediation
View remediation

Remediation Suggestions

  • Store runtime locks in an owner-restricted directory such as $XDG_RUNTIME_DIR/design-framework-builder/, with permissions set to 0700.
  • Prefer an advisory lock using flock on a file opened by the trusted worker.
  • If a directory lock remains necessary, validate its ownership, type, and permissions before trusting it.
  • Record the worker PID and verify process liveness before treating an existing lock as active.
  • Install cleanup handlers before beginning work, for example with a shell trap covering normal exit and relevant signals.
  • Implement bounded stale-lock recovery and log rejected or recovered locks.
  • Do not use lock existence alone as an authorization or trust decision.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Security-Critical External Scripts and Installation Dependency Are Not Included or Pinned

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24-30 and 36-38
Vulnerability Type: Unverifiable external execution and data-transmission dependency
Risk Level: Medium

Vulnerable Code Snippet

markdown
## Dependent Scripts

All scripts are located in the `design-framework-sender/` directory:

- `generate_prompt.sh`: calls the OpenRouter API to generate an image-generation prompt
- `send_text.sh`: sends text messages to Telegram
- `config.py`: performs centralized configuration loading

## Installation Instructions

Refer to the installation documentation of the `design-framework-sender` skill.

The snippet above is an English rendering of the complete dependency and installation sections. Script names and service names are preserved exactly.

Technical Analysis

The documented workflow delegates security-sensitive behavior to a separate design-framework-sender skill, but that dependency and its scripts are absent from the audited package. _meta.json also declares an empty requirements array and does not provide a version, digest, repository, or other immutable identifier for the external skill.

The missing components reportedly:

  • Execute shell operations.
  • Send content to Telegram.
  • Submit data to the OpenRouter API.
  • Read shared configuration, which may include API credentials.

Consequently, this package does not provide enough information to verify shell argument quoting, endpoint validation, credential storage, attachment handling, transmitted fields, retention behavior, or the provenance and integrity of the installed dependency. The issue is a supply-chain and auditability weakness; the reviewed files do not prove that the omitted dependency is malicious.

Attack Path

  1. An operator installs design-framework-builder.
  2. The operator follows the instruction to obtain the separate design-framework-sender skill.
  3. Because no exact version, trusted r ...[truncated 1259 chars]
Remediation
View remediation

Remediation Suggestions

  • Include the required scripts in the reviewed package, or declare the external skill through a machine-readable dependency manifest.
  • Pin the dependency to an immutable version and cryptographic digest.
  • Document an authoritative repository and require signature or checksum verification before installation.
  • Review and publish the exact OpenRouter and Telegram endpoints, request fields, authentication method, and data-retention behavior.
  • Pass untrusted message data through structured interfaces rather than shell command construction.
  • If shell execution is unavoidable, quote every argument, reject control characters, avoid eval, and use fixed executable paths.
  • Store API credentials in a dedicated secret manager or protected environment variables; never place them in source files or command-line arguments.
  • Require explicit authorization before transmitting attachments or sensitive design content to external services.
  • Add the dependency, required permissions, and network destinations to _meta.json or an equivalent manifest so installations are reproducible and auditable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly describes sending generated framework content to a group chat and calling an external API to generate prompts, and it may also extract attached reference images for downstream use. Because the description omits any user-facing warning or consent boundary about transmitting potentially sensitive requirements, copy, or attachment-derived data to third parties and group recipients, users may disclose confidential information unintentionally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says the skill will generate a complete design framework upon receiving design requirements, but it does not define narrow trigger conditions, approval gates, or scope limits. In an automation context, broad activation language can cause the skill to run on loosely related inputs and initiate downstream actions unexpectedly, increasing the chance of unintended execution and data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description explicitly states that generated design frameworks are automatically sent to a group for preview, but it does not warn users that their input or generated content will be transmitted to an external chat channel. This creates a real data exfiltration and privacy risk, especially if design requirements contain confidential product, client, or internal planning information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The entire skill description is written as a Chinese-only workflow for generating and sending design outputs, with no indication that users can choose another language or that the locale restriction is intentional and justified. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill's behavior as Chinese-language oriented without indicating that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.