T03 · Remote Payload Retrieval and Execution
- Location
deploy/deploy.sh:1- Finding
Mutable Remote Script Is Executed Directly with Administrative Privileges
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real quiz-making skill, but it exposes document content, API keys, public quiz data, and host deployment controls in ways that are under-scoped and unsafe by default.
Install only after review. Do not use confidential documents unless you accept cloud transmission to the configured services, require authentication before exposing the web app, remove the TLS bypass, avoid running it as root, replace curl-to-bash and runtime package installs with pinned setup steps, and protect the ARK API key with a proper secret mechanism.
deploy/deploy.sh:1Mutable Remote Script Is Executed Directly with Administrative Privileges
deploy/deploy.sh:25Web Application Is Installed as a Persistent Root Service
server.js:92Unauthenticated API Permits Quiz Enumeration, Result Disclosure, Creation, and Deletion
quiz-create.js:10TLS Certificate Verification Is Disabled When Transmitting Document Content
public/admin.html:112Stored Cross-Site Scripting Through Quiz and Participant Data
创建于 ${new Date(data.createdAt).toLocaleString('zh-CN')} · ${data.description || ''}
``` Participant records are also directly interpolated into the same HTML assignment: ```javascript return ` ${s.rank} ${s.name} ${s.className || '-'} ${s.score}分 ${new Date(s.submittedAt).toLocaleString('zh-CN')} `; ``` Question text is rendered in the same way: ```javascript : data.questionStats.map(q => `server.js:16Failed Uploads Are Not Deleted, Enabling Persistent Disk Exhaustion
start.sh:13Environment Configuration File Is Executed as Shell Code
qr-gen.py:1QR Utility Automatically Installs Unpinned Packages at Runtime
The skill description emphasizes local quiz generation from documents and QR return, but the workflow sends full document content to an external cloud API and does not clearly disclose that data leaves the local environment. This mismatch is dangerous because users may provide sensitive documents under the assumption of local-only processing, causing unanticipated data exposure to a third party.
The skill description emphasizes local quiz generation from documents and QR return, but the workflow sends full document content to an external cloud API and does not clearly disclose that data leaves the local environment. This mismatch is dangerous because users may provide sensitive documents under the assumption of local-only processing, causing unanticipated data exposure to a third party.
The skill description emphasizes local quiz generation from documents and QR return, but the workflow sends full document content to an external cloud API and does not clearly disclose that data leaves the local environment. This mismatch is dangerous because users may provide sensitive documents under the assumption of local-only processing, causing unanticipated data exposure to a third party.
The skill description emphasizes local quiz generation from documents and QR return, but the workflow sends full document content to an external cloud API and does not clearly disclose that data leaves the local environment. This mismatch is dangerous because users may provide sensitive documents under the assumption of local-only processing, causing unanticipated data exposure to a third party.
The skill description emphasizes local quiz generation from documents and QR return, but the workflow sends full document content to an external cloud API and does not clearly disclose that data leaves the local environment. This mismatch is dangerous because users may provide sensitive documents under the assumption of local-only processing, causing unanticipated data exposure to a third party.
The workflow sends the supplied document content to a cloud API to generate quizzes, but the skill does not provide a clear user-facing warning about data sharing, retention, or privacy consequences. This is especially dangerous because the input source is documents, which commonly contain confidential educational, business, or personal information.
The lockfile pins @xmldom/xmldom 0.8.13, which is flagged with multiple high-severity XML/DOM injection advisories. In a skill that processes uploaded documents such as DOCX, XML parsing is directly in scope, so malformed document content could potentially trigger parser flaws and compromise document handling or enable downstream injection behaviors.
adm-zip 0.5.17 is reported vulnerable to symlink-following during extraction and to excessive memory allocation on crafted ZIP input. Because this skill ingests user-supplied documents and DOCX files are ZIP-based, this dependency is especially risky: an attacker could supply a malicious archive to cause denial of service or arbitrary file overwrite depending on usage.
multer 2.1.1 is associated with multiple denial-of-service issues involving malformed multipart field structures and aborted uploads. This is highly relevant because the skill accepts uploaded files; a remote attacker could exploit upload handling to exhaust server resources or destabilize the service without authentication.
adm-zip 0.5.17 is flagged with high-severity advisories including symlink-following during extraction and crafted ZIP-induced excessive memory allocation. In this skill's context, document ingestion and archive handling make this more dangerous because an uploaded malicious archive could trigger file overwrite or denial-of-service conditions on the host processing service.
multer 2.1.1 is associated with multiple denial-of-service advisories involving aborted uploads and malformed field names. This skill explicitly appears to accept user-supplied documents for quiz generation, so a vulnerable upload parser materially increases exposure to remote service disruption by unauthenticated or low-effort attackers.
The DELETE endpoint allows any unauthenticated requester to remove a quiz and all related submissions and statistics. This is a direct integrity and availability issue because an attacker can permanently destroy quiz content and participant records without needing credentials.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
LOG_DIR="$SCRIPT_DIR/logs"
ENV_FILE="$SCRIPT_DIR/.env"
mkdir -p "$LOG_DIR"
echo "🚀 启动 Quiz Maker..."
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
echo "🚀 启动 Quiz Maker..."
echo "📁 工作目录: $SCRIPT_DIR"
# 加载环境变量(如果有 .env 文件)
if [ -f "$ENV_FILE" ]; then
echo "📋 加载环境变量: $ENV_FILE"
set -a
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
echo "🚀 启动 Quiz Maker..."
echo "📁 工作目录: $SCRIPT_DIR"
# 加载环境变量(如果有 .env 文件)
if [ -f "$ENV_FILE" ]; then
echo "📋 加载环境变量: $ENV_FILE"
set -a
The skill declares no explicit tool scope even though it instructs use of shell commands and environment/config modification. In an agent setting, missing scope boundaries increases the chance of unintended command execution or privilege creep because the runtime cannot clearly constrain what the skill is allowed to do.
Broad trigger phrases like '出题' or '生成题目' can match many ordinary educational requests and cause the skill to activate unexpectedly. In this skill, unintended invocation matters more because activation can lead to document extraction, cloud upload, local config changes, and credential prompting.
The skill instructs the agent to ask for an API key and persist it in a local .env file. Collecting and storing long-lived credentials expands the skill's sensitivity and creates risk of accidental disclosure, misuse by other local processes, or later exfiltration if the workspace is compromised.
The public description presents a simple document-to-quiz utility, but the instructions also modify a local configuration file and require a service restart. Hidden state changes are risky in agent workflows because they alter the host environment beyond the user's likely expectation and can affect future runs or other services.
The script makes privileged system-wide changes immediately, including installing packages, writing a systemd unit, enabling persistence, and restarting services, without any confirmation, dry-run mode, or prerequisite checks. This is dangerous because an operator can unintentionally modify a host, disrupt existing services, or deploy into the wrong environment with root-level impact.
The manifest describes a quiz-generation tool that creates tests from documents and returns a QR code for answering. This script performs host-level server provisioning by installing Nginx and Certbot, creating a systemd unit, and running the application as a persistent root service, which is infrastructure management rather than an obvious capability of a quiz authoring skill itself.
Enabling the service with systemd creates boot persistence for a process that is configured to run as root. Persistence itself can be legitimate in deployment, but in security terms it increases the blast radius of any compromise in the application because the service will automatically restart and survive reboots.
EOF
systemctl daemon-reload
systemctl enable quiz-maker
echo "Systemd 配置完成"
echo "=== 7/10 启动服务 ==="
The manifest says the skill generates quizzes from documents such as docx, pdf, txt, but this parser only supports .docx, .md, and .pptx and explicitly rejects other extensions. That is a direct behavior mismatch with the described input scope, especially for advertised formats like pdf and txt.
The PPTX fallback executes a shell pipeline via execSync and interpolates filePath directly into the command string. Even though the path is quoted, shell metacharacters such as embedded double quotes or command substitutions can still break out of the quoting context, enabling command injection if an attacker controls the file path; additionally, invoking external utilities increases attack surface and can block the process.
The code falls back to executing a shell command with execSync to extract strings from the file, but there is no confirmation prompt, user-visible logging, or warning comment/docstring indicating that external command execution may occur. Subprocess execution is a safety-relevant operation under this rule, and the top-level function description does not disclose this behavior.
Detected: suspicious.dangerous_exec, suspicious.insecure_tls_verification