Back to skill

Security audit

Agent开发决策辅助系统

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated reporting purpose, but it needs review because generated HTML can include unescaped user or web-sourced content that may execute in a browser.

Review before installing. Use it only if you are comfortable with web searches and local HTML report creation, constrain report output paths, and avoid opening reports built from untrusted web or pasted content until the generator escapes or sanitizes all report fields.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/report_generator.py:342
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis
Agent 开发可行性决策报告 - {name} {css}

🤖 {name}

{direction}
``` Representative unescaped detail-field interpolation: ```python tech_detail = safe_get(tech, "detail", "暂无详细数据") html += f"""

🧠 一、技术选型分析

{make_score_bar(tech_score)}

{tech_detail}

""" ``` The generated content is then persisted as an executable HTML document: ```python html = generate_report(data) Path(args.output).write_text(html, encoding="utf-8") ``` Similar direct interpolation affects product names, directions, competitor information, market data, technical details, risk descriptions, table cells, and other report fields throughout lines 398-655. ### Technical Analysis The `safe_get()` helper only retrieves values from dictionaries: ```python def safe_get(d, key, default=""): """Safely get dict value.""" if isinstance(d, dict): return d.get(key, default) return default ``` It does not perform HTML escaping, attribute encoding, content validation, or sanitization. Consequently, user-controlled or externally sourced strings are inserted directly into HTML text, title, table, and other markup contexts. An attacker can supply a value containing HTML that closes the surrounding element and introduces executable markup. For exa ...[truncated 2180 chars]
Remediation
View remediation
str: return escape(str(value), quote=True) ``` Use it for every externally supplied value: ```python safe_name = html_text(name) safe_direction = html_text(direction) safe_tech_detail = html_text(tech_detail) html = f""" Agent Development Feasibility Report - {safe_name}

{safe_name}

{safe_direction}

{safe_tech_detail}

""" ``` 2. **Prefer an auto-escaping template engine.** Move the large HTML template to Jinja2 or an equivalent engine configured with automatic HTML escaping: ```python from jinja2 import Environment, FileSystemLoader, select_autoescape env = Environment( loader=FileSystemLoader("templates"), autoescape=select_autoescape(["html", "xml"]), ) template = env.get_template("report.html") html = template.render(data=data, score_result=score_result) ``` Do not mark externally sourced values as safe unless they have passed a strict allowlist sanitizer. 3. **Treat WebSearch and WebFetch content as untrusted.** Never insert retrieved page content into the report as raw HTML. Convert it to plain text and escape it. If limited formatting is required, sanitize it with a maintained allowlist-based sanitizer that rejects scripts, event-handler attributes, dangerous URLs, embedded objects, frames, and active SVG content. 4. **Validate field types and ranges.** Require strings for descriptive fields and numeric values for scores. Reject nested objects or unexpected types rather than relying on implicit string conversion. Constrain scores to the documented range of 0-100. 5. **Preserve safe JavaScript serialization.** Continue using `json.dumps()` for JavaScript data rather than str ...[truncated 1055 chars]
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description and usage examples are entirely in Chinese, including the suggested invocation phrases, and there is no indication that users may interact in other languages or that the skill is intentionally limited to a Chinese-speaking audience. This creates a natural-language locale constraint without explicit opt-in or justification, which fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requests powerful tools including Write, Edit, and Bash, but does not define any explicit tool scope such as allowed-tools or permissions boundaries. That creates a least-privilege violation: if the skill is auto-invoked or misused, it can write files and execute commands beyond what is necessary to generate an analysis report, increasing the risk of unintended filesystem modification or command execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description embeds broad trigger phrases like 'Agent开发', 'AI助手开发', and 'Agent选型' that can match many ordinary conversations about agents. This can cause accidental activation in unrelated contexts, unexpectedly granting the skill access to web search, file write, and shell-capable behavior, which raises the attack surface and chance of unsafe side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage examples show that natural-language requests like '帮我评估做AI法律咨询Agent可行吗' are treated as activation triggers without any explicit invocation boundary. In combination with the skill's broad tool access, this ambiguity increases the likelihood that benign advisory conversations will unexpectedly launch web collection and report-generation actions, including file creation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python skill embeds a fixed lang="zh-CN" HTML locale and the surrounding report content is consistently rendered in Chinese, with no option for the user to select another language. The policy explicitly forbids forcing a specific language or locale without user opt-in unless the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.