Back to skill

Security audit

Plan I

Security checks for vulnerabilities and agentic risk

Overview

This skill creates local planning documents as advertised, with no network, credential, persistence, or hidden behavior, though its filename handling should be tightened.

Install only if you want a Chinese-language planning initializer that creates Markdown files in your workspace. Avoid using slashes, dots, shell metacharacters, or unusual characters in plan names until the script enforces a strict safe-name pattern.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/pl-init.sh:38
Finding

Unvalidated Plan Name Permits Filesystem Path Manipulation

Content
View full analysis
"$file_path" <
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/pl-init.sh:46
Finding

Predictable Check-Then-Write Sequence Allows a Symbolic-Link Race

Content
View full analysis
"$file_path" < "$file_path"` opens it. The destination is comparatively predictable because its variable components are the current date, a timestamp with one-second precision, and the supplied plan name. Shell redirection follows symbolic links and truncates the resolved target before writing the template. ### Attack Path 1. A local attacker obtains write access to the applicable `plans/YYYYMMDD` directory or otherwise controls a relevant path component. 2. The attacker learns or influences the plan name and predicts the timestamp used in the destination filename. 3. The attacker waits for the script's existence check to complete or repeatedly attempts to place the anticipated filename. 4. Before output redirection opens the path, the attacker creates or swaps in a symbolic link pointing to ano ...[truncated 954 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

该 markdown 文件将技能描述为“启动一个新的规划流程,创建新的规划文件”以及“启动一个新的规划”,并仅要求用户请求“包含变更名称或对想要构建内容的描述”。这些表述较宽泛,容易与日常的泛化“做个规划/想构建什么”类请求重叠,文档中也没有提供明确触发短语、适用范围限制或不应触发的负例。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

文档要求“提炼出简洁的中文规划主题”,属于对输出语言的硬性限定。文件中未见用户可选择语言/locale 的机制,也未说明该技能为何必须仅使用中文,因此构成语言/locale 政策风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

技能要求调用本地 shell 脚本并立即向新建文件写入用户衍生内容,但文档没有要求对规划名称做严格校验、转义或向用户提示文件系统副作用。若脚本参数处理不安全,用户提供的名称可能触发命令注入、路径穿越或意外文件创建;即使脚本本身安全,缺少显式风险提示也会增加误操作和静默写盘风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script description, help text, and user-visible messages are written in Chinese only, including usage guidance and success/error output. This imposes a specific language on users without any opt-in, fallback, or documented justification for a locale-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.