Back to skill

Security audit

AI食品营养管理助手

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent nutrition tracker, but it persists sensitive diet/profile data with unclear consent and generates reports that can execute untrusted HTML or mutable third-party JavaScript.

Review this before installing if you are comfortable storing diet history and body-profile details locally. Use it only with trusted meal text and diary/cache data, avoid opening generated reports from untrusted inputs, and prefer adding explicit save confirmation, deletion guidance, HTML escaping, and a pinned or bundled chart library.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/html_report.py:31
Finding

Stored HTML and JavaScript Injection in Daily Nutrition Reports

Content
View full analysis
{meal.get('meal', f'第{i+1}餐')} {meal.get('time', '')}
{items_str}
``` ### Technical Analysis The report generator directly interpolates `meal`, `time`, `foodName`, and `amount_g` values into an HTML document without HTML escaping or contextual output encoding. Food names can originate from user-provided meal descriptions. In particular, `NutritionCalc.parse_food_items()` preserves the original name for an unknown food, and `NutritionCalc.save_meal()` persists the resulting value in a diary JSON file. Values returned by TianAPI or loaded from cache and diary files are also treated as trusted. For example, an attacker-controlled food or meal name containing the following markup would be rendered as executable HTML rather than text: ```html ``` This is a stored injection because the malicious value can be saved in the diary and executed later when the generated report is opened. The affected generated document does not define a Content Security Policy that would prevent inline event-handler execution. ### Attack Path 1. An attacker supplies a crafted food or meal name containing HTML with an inline JavaScript event handler. 2. `parse_food_items()` retains the attacker-controlled value when it cannot safely map it to a built-in food. 3. `sa ...[truncated 1216 chars]
Remediation
View remediation
``` The policy should be adapted for the report's legitimate resources and should avoid permitting inline scripts or event handlers. 6. Add regression tests using payloads containing `

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/html_report.py:198
Finding

Mutable Third-Party JavaScript Is Loaded at Report Viewing Time

Content
View full analysis
``` ### Technical Analysis Weekly reports load executable JavaScript from jsDelivr whenever a report is opened. The dependency URL specifies only the major Chart.js version, `@4`, rather than an exact immutable version. As a result, the effective JavaScript payload can change after the Skill has been reviewed. The script is not protected by a Subresource Integrity hash. The browser therefore has no locally defined cryptographic expectation for the downloaded file. This creates a remote payload execution and supply-chain risk. Compromise of the CDN, package publication process, package owner account, or dependency distribution path could cause attacker-controlled JavaScript to execute in generated reports without any modification to the reviewed Skill package. ### Attack Path 1. The user requests a weekly nutrition report. 2. `generate_weekly_report()` creates an HTML document referencing the remote Chart.js URL. 3. The user opens or previews the report while network access is available. 4. The browser requests the current JavaScript resolved by `chart.js@4` from jsDelivr. 5. If the upstream package or distribution channel has been compromised, the CDN returns malicious JavaScript. 6. The browser executes that JavaScript in the report page context. ### Impact Assessment A compromised dependency would execute with the privileges of JavaScript in the weekly report page. It could: - Read report contents, including nutrition trends and target information. - Modify displayed results or recommendations. - Exfiltrate report data through network requests. - Display deceptive content or capture information entered into dynamically created page elements. - Access same-origin browser r ...[truncated 312 chars]
Remediation
View remediation
``` The version and hash must be taken from and verified against the selected release artifact. 3. Add a restrictive Content Security Policy that permits scripts only from the selected local path or exact required source. 4. Consider generating the graph without runtime JavaScript, such as an SVG or static image, if report interactivity is not required. 5. Record the dependency version and integrity hash in project metadata so upgrades are explicit and reviewable. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (18)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes very broad everyday phrases such as '吃什么', '今天吃了', and '卡路里', which can cause the skill to activate during ordinary conversation not clearly intended as consent to use the skill. In this skill, unintended invocation is more dangerous because activation can lead to collection of health-related data and subsequent file writes or report generation workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The description states the skill is based on Chinese dietary guidelines and line L103 says the data and standards prioritize Chinese cuisine. This establishes a locale-specific policy without offering users an alternative or clearly framing the skill as region-specific, which can be a language/locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks for age, sex, height, weight, goals, activity level, and optionally an API key, but does not provide a clear privacy notice about storage, retention, or how this sensitive health-related data will be used. Because these attributes are personal and health-adjacent, lack of transparency increases the risk of over-collection, unexpected persistence, and user harm from unauthorized disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that after analyzing a meal it will automatically call save_meal() to persist the record, but the user-facing flow does not clearly guarantee informed consent before the write occurs. In a nutrition tracker, automatic persistence of meal history can create a sensitive longitudinal dataset about health, habits, and lifestyle without a clear opt-in boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This file’s top-level natural-language documentation is entirely Chinese, and the rest of the inline comments and docstrings follow the same pattern, with no indication that the skill is China-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module description and generated HTML content are consistently hard-coded in Chinese, including the document language tag and all user-facing strings. This creates a language/locale policy issue because the skill forces a specific language experience without any visible user opt-in or configurable locale handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language strings and documentation in this file consistently force a specific language/locale. Under the policy, a skill should not impose a language without user opt-in unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code saves profile information to user_data/profile.json, which is personal health-related data. The file includes only internal docstrings and no visible prompt, disclosure, or user-facing log indicating that sensitive data will be persisted locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The save_meal function writes meal names, timestamps, nutrition data, item details, and free-form notes to date-based JSON files under user_data/diary. Because this is personal dietary data, the lack of any user-facing disclosure or confirmation is a missing warning for a safety- and privacy-relevant operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The report generation flow writes HTML files into the working directory without clearly warning the user that filesystem changes will occur. While lower severity than hidden health-data collection, undisclosed file creation can still surprise users, leave sensitive reports on disk, and increase the exposure surface if the workspace is shared or synced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The JSON values for food name and category are written only in Chinese (e.g. "水煮蛋", "蛋类"), which imposes a specific language/locale in natural-language content. There is no indication in this file that the locale is optional, user-selected, or justified as region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This file is a JSON manifest/data file, so vague-trigger review applies. The content consists only of nutrition fields and provides no activation conditions, trigger phrases, exclusions, or scope, leaving invocation behavior unspecified and therefore ambiguous if this file is used as skill metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The JSON stores natural-language content entirely in Chinese (for example, the food name and category) with no indication that the user can choose locale or that the file is intentionally region-specific. Under the policy check, fixed language content without opt-in can be a locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The JSON content uses Chinese values for fields like foodName and category, which imposes a specific language/locale in the skill data. There is no indication of user opt-in, alternate locale support, or documentation justifying a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file stores user-facing natural-language values such as "苹果" and "水果" entirely in Chinese, which may reflect a fixed language choice. Because no surrounding context in this file indicates user opt-in or a documented locale-specific scope, this appears to force a specific language/locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This JSON file contains natural-language values exclusively in Chinese (for example, "米饭" and "谷类"). For a rule that applies to all file types, this can indicate a locale-specific constraint without any accompanying opt-in or justification in the file itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The JSON content uses Chinese-only values such as "水煮蛋" and "蛋类" with no indication that the skill is region-specific or that users can choose another language. This can violate language/locale policy when a skill implicitly assumes a single language without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON contains user-facing natural-language values such as meal names, food names, and categories exclusively in Chinese. Under the language/locale policy, forcing a specific language without user opt-in or documented regional justification can be a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.