T09 · Insecure Skill Coding Practices
- Location
scripts/download.py:62- Finding
HTTPS Certificate and Hostname Verification Disabled
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a legitimate exam-paper retrieval purpose, but its downloader and archive workflow expose users to unsafe downloads, arbitrary file writes, and weak verification.
Review this skill carefully before installing. Use it only in a sandbox or dedicated download directory, avoid social-media and cloud-drive links unless independently trusted, do not open or upload downloaded archives until manually checked, and require fixes for TLS verification, URL/domain allowlisting, output-path confinement, download size limits, and safe archive extraction.
scripts/download.py:62HTTPS Certificate and Hostname Verification Disabled
scripts/search.sh:99User-Controlled Search Values Are Interpolated into Python Source Code
scripts/verify.py:13Authenticity Verification Ignores Expected Year and Region
SKILL.md:56Untrusted Archives Are Extracted without Path or Resource Safety Checks
scripts/download.py:48Arbitrary URL Fetching, Unrestricted File Writes, and Unbounded Response Reads
声明的核心能力是“搜索并下载全国各地中考真题试卷”。但提供的代码只是一个辅助搜索规划脚本:接收地区、科目、年份后,为 zhongkao.com、trjlseng.com、shijuan1.com、zxzyw.cn、51test.net 等来源构造 query、URL pattern、download pattern,并以 JSON 输出。脚本中没有 curl/wget 等网络访问,也没有实际解析网页或保存文件;日志还明确写明“下一步:使用web_search工具按query字段搜索... 然后使用download.sh下载文件”。因此,代码实际行为与声明存在实质性不符,尤其是“下载”与“实际搜索执行”两项能力未在该代码中实现。
声明的核心能力是“搜索并下载中考真题试卷”,但提供的代码并没有任何网络访问、检索、抓取、下载、地区/年份资源发现等逻辑。它只接收一个本地文件路径并验证文件格式、大小和部分内容特征,属于下载后的校验工具,而不是搜索下载工具。虽然这可能与试卷下载场景相关,但其主要目的与声明明显不一致,且缺少声明中的核心能力,因此应判定为描述与实际行为不匹配。
The code explicitly disables TLS certificate validation and hostname checking for all HTTPS downloads, which allows a man-in-the-middle attacker to intercept or modify downloaded files without detection. In this skill’s context, the script fetches exam papers from arbitrary URLs, so a network attacker or malicious hotspot could replace files with malicious or misleading content while the tool still reports success.
The skill describes use of local scripts, file reading, and network-assisted workflows but does not declare any explicit tool scope or permissions boundary. This can lead to overbroad execution in environments where the runtime grants more capability than users expect, reducing auditability and increasing the chance of unintended file or network access.
The trigger phrases include broad, common educational terms such as exam prep, subject names, and regional exam references, which can cause the skill to activate in ordinary study conversations. Unintended invocation matters here because the skill then steers users toward external search and downloads from third-party sites, increasing accidental network activity and exposure to untrusted content.
The skill instructs automatic retrieval from third-party websites and writing downloaded files locally, including archives such as RAR and ZIP, without upfront user-facing notice about network access, local file creation, or the trust risks of external content. In this context, that is dangerous because users may unknowingly fetch malicious or misleading files from low-trust sources such as social media or ad-heavy exam repositories.
This markdown file contains user-facing operational guidance exclusively in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-language audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
The skill explicitly recommends searching social-media posts and cloud-drive links for exam materials, but provides no warning about copyright restrictions, expired or hijacked links, malware in third-party archives, or phishing risks from unofficial download sources. In this context, the skill is guiding users toward unvetted off-platform distribution channels, which increases the chance of unsafe or unauthorized downloads even if the underlying topic is educational.
The file's description, usage messages, and argument prompts are written entirely in Chinese, including all user-facing guidance. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.
The module description and declared output behavior specify Chinese-only interaction and JSON results in Chinese, and the script also defaults to a Chinese subject value. This enforces a specific language/locale without offering user opt-in or documenting a justified region-specific restriction, which matches the policy-violation category.
The primary description and operational content are written entirely in Chinese and target Chinese exam materials, but the file does not explicitly state that interaction is limited to Chinese or offer the user a language choice. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy concern unless the locale constraint is clearly documented and justified.
The module description and CLI usage/error strings are written only in Chinese, which imposes a specific language on users without opt-in. Under the stated policy, forcing a language or locale without offering a choice can be a natural-language policy violation.
No suspicious patterns detected.