Back to skill

Security audit

aitubiao-chart

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its chart-generation purpose, but its persistent API-key file is loaded as shell code, creating a real local execution risk if the file or key value is malformed or tampered with.

Install only if you trust aitubiao with the data you send and are comfortable using a revocable API key that can query quota and create billable projects. Inspect or delete ~/.aitubiao/credentials when done, rotate the API key if exposed, and avoid pasting anything except a key copied directly from the legitimate aitubiao API-key page.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrases include broad natural-language terms like 'visualize data' and 'make a chart', which may match routine conversation and cause accidental invocation. Because this skill can request/store API keys, query account state, and create billable remote projects, unintended activation can lead to privacy exposure, user confusion, or unwanted charges.

Static analysis

No suspicious patterns detected.