Back to skill

Security audit

中考真题检索

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate exam-paper retrieval purpose, but its downloader and archive workflow expose users to unsafe downloads, arbitrary file writes, and weak verification.

Review this skill carefully before installing. Use it only in a sandbox or dedicated download directory, avoid social-media and cloud-drive links unless independently trusted, do not open or upload downloaded archives until manually checked, and require fixes for TLS verification, URL/domain allowlisting, output-path confinement, download size limits, and safe archive extraction.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/download.py:62
Finding

HTTPS Certificate and Hostname Verification Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search.sh:99
Finding

User-Controlled Search Values Are Interpolated into Python Source Code

Content
View full analysis
<科目> <年份>}" SUBJECT="${2:?用法: search.sh <省份城市> <科目> <年份>}" YEAR="${3:?用法: search.sh <省份城市> <科目> <年份>}" ``` Representative construction of a result containing user input: ```bash echo '{"source":"zhongkao","status":"needs_web_search","query":"'"${CITY} 中考${SUBJECT} 真题 下载版 ${YEAR}"'","url_pattern":"m.zhongkao.com/e/{date}/{id}.shtml","download_pattern":"files.eduuu.com/ohr/{year}/{month}/{day}/{filename}.zip|.rar"}' ``` The generated strings are then inserted directly into Python program text: ```bash python3 -c " import json, sys results = [ json.loads('''$R1'''), json.loads('''$R2'''), json.loads('''$R3'''), json.loads('''$R4'''), json.loads('''$R5'''), ] print(json.dumps(results, ensure_ascii=False, indent=2)) " ``` ### Technical Analysis The script treats user-controlled values as both JSON text and executable Python source. The values are first concatenated into strings such as `R1` through `R5`. Those strings are subsequently interpolated into a `python3 -c` command inside triple-quoted Python string literals. Shell quoting does not make the resulting Python source safe. A crafted argument containing quote or triple-quote sequences can terminate the intended Python literal and inject additional Python statements. The vulnerability occurs before `json.loads` can validate the data because Python must first parse and execute the dynamically assembled program. The same construction also permits malformed JSON and denial-of-service conditions with less sophisticated input. ### Attack Path 1. An attacker supplies or influences the `REGION`, `SUBJECT`, or `YEAR` argument passed ...[truncated 1021 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verify.py:13
Finding

Authenticity Verification Ignores Expected Year and Region

Content
View full analysis
3 else "" subject = sys.argv[4] if len(sys.argv) > 4 else "英语" result = verify_file(file_path, year, region, subject) ``` However, `year` and `region` are never used in the verification logic. PDF validation is also limited to a header check: ```python def verify_pdf(file_path): """验证PDF文件""" result = {"type": "pdf", "valid": False, "issues": []} try: with open(file_path, 'rb') as f: header = f.read(10) if header[:4] == b'%PDF': result["valid"] = True else: result["issues"].append('非有效PDF文件') ``` Scanned DOCX files bypass keyword verification: ```python result["is_scan"] = total_media_size > 1000000 and len(text) < 500 if not result["is_scan"] and len(text) > 50: # Keyword checks are performed here ... elif result["is_scan"]: result["found_keywords"] = ["(扫描嵌入版,无法提取文本关键词)"] result["has_content"] = len(text) > 200 or result["is_scan"] ``` ### Technical Analysis The verifier is documented as checking authenticity and completeness, but its expected year and region parameters do not influence the result. Consequently, a structurally valid document for a different year or location can pass. PDF validation only checks whether the file begins with `%PDF`; it does not parse the PDF structure, inspect content, detect active elements, or confir ...[truncated 1344 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:56
Finding

Untrusted Archives Are Extracted without Path or Resource Safety Checks

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/download.py:48
Finding

Arbitrary URL Fetching, Unrestricted File Writes, and Unbounded Response Reads

Content
View full analysis
3 and sys.argv[3] == "--referer" and len(sys.argv) > 4: referer = sys.argv[4] result = download_file(url, output_path, referer) ``` ### Technical Analysis The downloader accepts an arbitrary URL without restricting its scheme, hostname, resolved address, port, or redirect destination. In an environment with access to private services, a manipulated invocation could request loopback, private-network, link-local, or cloud-metadata endpoints. The output path is converted to an absolute path and its parent directories are created, but no check confines it to an approved output directory. Opening the path with `wb` truncates an existing writable file. Finally, `response.read()` loads the entire response into memory before writing it. ...[truncated 1501 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明的核心能力是“搜索并下载全国各地中考真题试卷”。但提供的代码只是一个辅助搜索规划脚本:接收地区、科目、年份后,为 zhongkao.com、trjlseng.com、shijuan1.com、zxzyw.cn、51test.net 等来源构造 query、URL pattern、download pattern,并以 JSON 输出。脚本中没有 curl/wget 等网络访问,也没有实际解析网页或保存文件;日志还明确写明“下一步:使用web_search工具按query字段搜索... 然后使用download.sh下载文件”。因此,代码实际行为与声明存在实质性不符,尤其是“下载”与“实际搜索执行”两项能力未在该代码中实现。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明的核心能力是“搜索并下载中考真题试卷”,但提供的代码并没有任何网络访问、检索、抓取、下载、地区/年份资源发现等逻辑。它只接收一个本地文件路径并验证文件格式、大小和部分内容特征,属于下载后的校验工具,而不是搜索下载工具。虽然这可能与试卷下载场景相关,但其主要目的与声明明显不一致,且缺少声明中的核心能力,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code explicitly disables TLS certificate validation and hostname checking for all HTTPS downloads, which allows a man-in-the-middle attacker to intercept or modify downloaded files without detection. In this skill’s context, the script fetches exam papers from arbitrary URLs, so a network attacker or malicious hotspot could replace files with malicious or misleading content while the tool still reports success.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill describes use of local scripts, file reading, and network-assisted workflows but does not declare any explicit tool scope or permissions boundary. This can lead to overbroad execution in environments where the runtime grants more capability than users expect, reducing auditability and increasing the chance of unintended file or network access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases include broad, common educational terms such as exam prep, subject names, and regional exam references, which can cause the skill to activate in ordinary study conversations. Unintended invocation matters here because the skill then steers users toward external search and downloads from third-party sites, increasing accidental network activity and exposure to untrusted content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs automatic retrieval from third-party websites and writing downloaded files locally, including archives such as RAR and ZIP, without upfront user-facing notice about network access, local file creation, or the trust risks of external content. In this context, that is dangerous because users may unknowingly fetch malicious or misleading files from low-trust sources such as social media or ad-heavy exam repositories.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file contains user-facing operational guidance exclusively in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-language audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly recommends searching social-media posts and cloud-drive links for exam materials, but provides no warning about copyright restrictions, expired or hijacked links, malware in third-party archives, or phishing risks from unofficial download sources. In this context, the skill is guiding users toward unvetted off-platform distribution channels, which increases the chance of unsafe or unauthorized downloads even if the underlying topic is educational.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's description, usage messages, and argument prompts are written entirely in Chinese, including all user-facing guidance. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and declared output behavior specify Chinese-only interaction and JSON results in Chinese, and the script also defaults to a Chinese subject value. This enforces a specific language/locale without offering user opt-in or documenting a justified region-specific restriction, which matches the policy-violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The primary description and operational content are written entirely in Chinese and target Chinese exam materials, but the file does not explicitly state that interaction is limited to Chinese or offer the user a language choice. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy concern unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The module description and CLI usage/error strings are written only in Chinese, which imposes a specific language on users without opt-in. Under the stated policy, forcing a language or locale without offering a choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.