Back to skill

Security audit

AgentScout

Security checks for vulnerabilities and agentic risk

Overview

AgentScout has a coherent content-generation purpose, but it needs review because untrusted GitHub content can influence LLM output and browser-rendered images without enough safeguards.

Install only if you are comfortable sending GitHub repository content and generated prompts to the configured LLM/image providers. Use a low-scope GitHub token, avoid private or sensitive repositories, review generated commands before copying or publishing them, and run it in an isolated environment until prompt-injection handling, HTML escaping, URL restrictions, and dependency pinning are improved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
src/analyze/project_analyzer.py:14
Finding

Indirect Prompt Injection Through Untrusted GitHub Repository Content

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/visual/composer.py:13
Finding

Unescaped Attacker-Controlled Content Rendered in a Headless Browser

Content
View full analysis
Environment: """Get the Jinja2 template environment.""" return Environment( loader=FileSystemLoader(str(TEMPLATES_DIR)), autoescape=False, ) ``` Attacker-influenced values are passed directly into templates: ```python template = self.env.get_template(template_name) html = template.render( project_name=project_name, description=description, stars=stars, highlight=highlight, ) return html_to_image(html, output_path) ``` ```python template = self.env.get_template("architecture.html") html = template.render( architecture=architecture_text, project_name=project_name, ) return html_to_image(html, output_path) ``` ```python template = self.env.get_template("summary_card.html") html = template.render( summary=summary, project_name=project_name, repo_url=repo_url, ) return html_to_image(html, output_path) ``` The templates interpolate the values into HTML: ```html
{{ project_name }}
{{ architecture }}
``` ```html
{{ project_name }}
{{ description }}
{% if highlight %}
💡 {{ highlight }}
{% endif %}
⭐ {{ stars }} Stars
``` ```html
{{ step.title }}
{{ step.description }}
{% if step.code %}
{{ step.code }}
{% endif %} ``` ```html
{{ project_name }}
{{ summary }}
🔗 {{ repo_url } ...[truncated 2287 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils/image_client.py:42
Finding

Server-Side Request Forgery Through Image Provider Response URLs

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unhashed Third-Party Dependencies

Content
View full analysis
=2.1.0 openai>=1.0.0 playwright>=1.40.0 Pillow>=10.0.0 html2image>=2.0.0 Jinja2>=3.1.0 python-dotenv>=1.0.0 httpx>=0.25.0 rich>=13.0.0 ``` The documented installation command is: ```bash cd {baseDir} && pip install -r requirements.txt ``` ### Technical Analysis All dependencies use open-ended minimum-version constraints. No exact versions, lockfile, integrity hashes, or reviewed transitive dependency set are provided. A future installation can therefore resolve to versions that did not exist at audit time. Python packages execute installation and import-time code with the privileges of the user running `pip`. This project includes dependencies with significant capabilities, including browser execution, network communication, HTML rendering, and API access. A compromised future package release or transitive dependency can execute arbitrary code during installation or normal application startup. The package names reviewed here do not constitute confirmed typosquatting or known malicious packages. The confirmed weakness is the unsafe, non-reproducible dependency policy. ### Attack Path 1. A direct or transitive dependency publishes a compromised future release that still satisfies the minimum-version constraint. 2. A user follows the documented `pip install -r requirements.txt` command. 3. The resolver selects the compromised release because no exact version or hash prevents it. 4. Malicious package code executes during installation, import, or application use. 5. The package runs with the privileges and environment access of the user running AgentScout. ### Impact Assessment A compromised dependency could potentially: - Execute arbitrary code as the installing user. - Read the project `.env` file and API crede ...[truncated 378 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (71)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 115)May include surrounding context.

配置

bash
cp .env.example .env

编辑 .env 文件,填入你的 API Key:

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The reported ability to browse arbitrary URLs and save screenshot files is a significant undeclared capability. This is dangerous because arbitrary browsing can be abused for unintended network access, retrieval of sensitive internal resources in some environments, and silent local file creation.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 188)May include surrounding context.

text

And configure `.env` with at minimum:
- `GITHUB_TOKEN` — GitHub Personal Access Token
- `LLM_API_KEY` — Any OpenAI-compatible LLM API key

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

text

And configure `.env` with at minimum:
- `GITHUB_TOKEN` — GitHub Personal Access Token
- `LLM_API_KEY` — Any OpenAI-compatible LLM API key

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/config.py (reported line 1)May include surrounding context.

python
"""统一配置加载 - 从 .env 文件和环境变量读取所有配置"""

import os
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/pipeline.py (reported line 329)May include surrounding context.

python
"""统一配置加载 - 从 .env 文件和环境变量读取所有配置"""

import os
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/pipeline.py (reported line 333)May include surrounding context.

python
"""统一配置加载 - 从 .env 文件和环境变量读取所有配置"""

import os
from pathlib import Path

Credential Access

High
Category
Privilege Escalation
Confidence
64% confidence
Finding

Automatically loading secrets from a project-root .env file can increase the chance of accidental secret exposure or misuse, especially in agent/tooling contexts where local files may be packaged, copied, or executed in less controlled environments. The risk is contextual rather than overtly malicious, but this pattern can cause credentials to be implicitly consumed without clear operator intent.

Content

Scanner excerpt · src/config.py (reported line 10)May include surrounding context.

python
# 项目根目录
PROJECT_ROOT = Path(__file__).parent.parent
load_dotenv(PROJECT_ROOT / ".env")


@dataclass

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README explicitly says the tool fetches full READMEs, file trees, and key code, then uses an LLM to generate analysis. That creates a real data-transmission and privacy risk because repository content may be sent to third-party LLM or image providers without a prominent warning, consent step, or guidance about handling private/sensitive code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

The README configures an external LLM endpoint and elsewhere describes sending repository-derived content to LLM services. In this skill's context, that means project text/code may leave the local environment and be processed by third parties, creating confidentiality, compliance, and data-handling risks if users are not clearly warned.

Content

Scanner excerpt · README.md (reported line 126)May include surrounding context.

md
LLM_API_KEY=sk-xxxx

# 可选 - LLM 配置(默认 OpenAI)
LLM_BASE_URL=https://api.openai.com/v1
LLM_MODEL=gpt-4o

# 可选 - AI 配图(支持任意 OpenAI 兼容的图片 API)

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The image API endpoint indicates generated prompts and possibly project-derived text may be sent to an external image provider. Even if less sensitive than raw code analysis, this still constitutes third-party transmission that may expose repository names, descriptions, or generated content without clear warning or retention guidance.

Content

Scanner excerpt · README.md (reported line 131)May include surrounding context.

可选 - AI 配图(支持任意 OpenAI 兼容的图片 API)

IMAGE_API_KEY=sk-xxxx IMAGE_BASE_URL=https://api.siliconflow.cn/v1 IMAGE_MODEL=black-forest-labs/FLUX.1-schnell

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

This configuration table reinforces that a remote OpenAI-compatible endpoint is part of normal operation. Because the tool analyzes third-party repositories and generates derived content, defaulting to remote APIs without strong disclosure increases the chance users unknowingly transmit code/content outside their environment.

Content

Scanner excerpt · README.md (reported line 190)May include surrounding context.

md
|------|------|--------|------|
| `GITHUB_TOKEN` | 推荐 | - | GitHub Personal Access Token |
| `LLM_API_KEY` | ✅ | - | LLM API Key |
| `LLM_BASE_URL` | - | `https://api.openai.com/v1` | 任意 OpenAI 兼容端点 |
| `LLM_MODEL` | - | `gpt-4o` | 模型名称 |
| `IMAGE_API_KEY` | - | - | 图片生成 API Key(不填则跳过 AI 配图) |
| `IMAGE_BASE_URL` | - | `https://api.siliconflow.cn/v1` | 图片 API 端点 |

External Transmission

Medium
Category
Data Exfiltration
Confidence
76% confidence
Finding

The external image endpoint is another real outbound data flow documented as a standard configuration option. In the context of automated content generation, users may unintentionally send repository-derived themes, text, or screenshots to third-party services, which is a meaningful privacy/compliance concern.

Content

Scanner excerpt · README.md (reported line 193)May include surrounding context.

md
| `LLM_BASE_URL` | - | `https://api.openai.com/v1` | 任意 OpenAI 兼容端点 |
| `LLM_MODEL` | - | `gpt-4o` | 模型名称 |
| `IMAGE_API_KEY` | - | - | 图片生成 API Key(不填则跳过 AI 配图) |
| `IMAGE_BASE_URL` | - | `https://api.siliconflow.cn/v1` | 图片 API 端点 |
| `IMAGE_MODEL` | - | `FLUX.1-schnell` | 图片模型 |
| `SCORE_WEIGHT_*` | - | 见上表 | 四维评分权重 |
| `TOPK_SIZE` | - | `20` | 排行榜保留数量 |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares executable behavior that uses environment variables, network access, and file writes, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because users and orchestrators cannot easily tell what the skill is allowed to access, increasing the chance of over-privileged execution and unintended data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description frames the skill as automatically generating publish-ready Xiaohongshu content, which implies a specific platform and associated language/locale context by default. There is no indication that the user can choose a different language or locale, or that this constraint is region-specific and intentional.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill requires external credentials and implies use of outside services, but it does not clearly warn users that repository data and prompts may be sent to third-party APIs. This is dangerous in security-sensitive environments because code or metadata could leave the local trust boundary without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The system and prompt strings are entirely written in Chinese and direct the model to produce a tutorial in that language, but the file provides no user opt-in, language selection, or justification for a mandatory Chinese locale. This creates a natural-language policy issue because the skill enforces a specific language regardless of user preference.

Content

No source excerpt is available for this finding.

Ssd 1

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Untrusted README text, file tree content, and source files from arbitrary GitHub repositories are inserted directly into the LLM prompt with no isolation or sanitization. A malicious repository can embed prompt-injection instructions that cause the model to ignore the intended task, generate deceptive or harmful output, exfiltrate surrounding prompt context, or produce unsafe commands in the '5分钟跑起来' section; this skill context makes the issue more dangerous because it is explicitly generating publish-ready tutorials and executable setup steps from attacker-controlled content.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/config.py (reported line 34)May include surrounding context.

python
@dataclass
class LLMConfig:
    api_key: str = ""
    base_url: str = "https://api.openai.com/v1"
    model: str = "gpt-4o"
    temperature: float = 0.7
    max_tokens: int = 4096

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/config.py (reported line 83)May include surrounding context.

python
@dataclass
class LLMConfig:
    api_key: str = ""
    base_url: str = "https://api.openai.com/v1"
    model: str = "gpt-4o"
    temperature: float = 0.7
    max_tokens: int = 4096

Static analysis

No suspicious patterns detected.