Back to skill

Security audit

Serp Markup Builder

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a coherent SEO markup helper, but it instructs agents to run an undeclared local Python preflight command against user-supplied URLs.

Review this skill before installing if your agent host can run shell commands. Prefer using the declared WebFetch path, or require URL validation and argument-array execution for the schema_lint.py preflight; also confirm the referenced connector is present and trusted. The SEO templates themselves are low risk, but locale examples and memory writes should be adjusted to your site and workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:63
Finding

Unquoted User-Controlled URL in Shell Command

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 63 and 92
Vulnerability Type: Command injection through unsafe shell argument interpolation
Risk Level: Medium

Vulnerable Code

Line 63:

text
Tier-1 (keyless, default): ask for current tags, target keywords, competitors, and page content; for `schema`, extract JSON-LD from server HTML with `WebFetch` or the bundled `python3 "${CLAUDE_PLUGIN_ROOT}/scripts/connectors/schema_lint.py" <url>` pre-flight.

Line 92:

text
Run the local pre-flight before the manual UI step: `python3 "${CLAUDE_PLUGIN_ROOT}/scripts/connectors/schema_lint.py" <url>` (extracts JSON-LD, checks required/recommended properties, flags these deprecations).

Technical Analysis

The documented command places the user-supplied page URL into an unquoted shell argument. If an agent substitutes <url> directly and executes the command through a shell, shell metacharacters in the URL—such as ;, &&, redirection operators, or command substitution syntax—could be interpreted as additional commands rather than as part of one URL argument.

The referenced schema_lint.py is outside the audited standalone package. Its implementation and integrity therefore could not be verified during this audit. This does not itself establish malicious behavior, but it increases reliance on an unaudited external component.

Exploitability depends on the host executing the generated command through a shell without argument-safe process invocation or URL validation.

Attack Path

  1. An attacker submits a crafted page URL containing shell control syntax.
  2. The agent replaces the <url> placeholder with the supplied value.
  3. The agent executes the documented pre-flight command using a shell.
  4. The shell parses the injected metacharacters as command syntax.
  5. The injected command runs with the permissions of the agent host process.

Impact Assessment

Successful exploitation could permit arbitrary command execution u ...[truncated 429 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer the declared WebFetch capability instead of constructing a shell command for URL retrieval.
  2. If the local script is necessary, invoke it through an argument-array process API, for example by passing ["python3", scriptPath, validatedUrl] without a shell.
  3. Validate the input as an absolute http or https URL and reject control characters, shell metacharacters, embedded newlines, and unsupported schemes.
  4. Do not interpolate raw user input into executable command strings.
  5. If a shell example must be retained, quote the URL argument and explicitly state that quoting is not a substitute for argument-safe execution and validation.
  6. Bundle schema_lint.py within the reviewed package or pin it to a verified source and integrity hash so its behavior can be audited.
  7. Add security tests using URLs containing spaces, semicolons, ampersands, substitutions, redirections, and newline characters to ensure they are passed only as inert data.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The display name and summary include Chinese text, but the file does not explain that this skill is intended specifically for Chinese-speaking users or offer an opt-in language choice. This can violate language/locale policy expectations by imposing a locale preference implicitly rather than making it user-selectable or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The Open Graph example fixes og:locale to en_US, which is a natural-language/locale policy concern because it presents a single locale as the default without user opt-in. The document is a reusable template rather than a region-specific tool, so this can encourage unnecessary forced locale settings.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example uses <html lang="en">, which imposes English as the language in a generic template. Because this file is not documented as English-only or region-specific, the fixed language value conflicts with the policy guidance against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.