T05 · Unauthorized Access and Privilege Escalation
- Location
server.py:29- Finding
Unauthenticated Network-Exposed Management and Destructive APIs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a plausible skill manager, but its dashboard exposes sensitive skill-management and deletion APIs without adequate access controls.
Install only if you trust the publisher and are prepared to run it locally with strict controls: bind the dashboard to 127.0.0.1, restrict CORS, avoid exposing the port, review deletion targets carefully, and prefer fixing the path validation and shell-deletion guidance before using cleanup or delete features.
server.py:29Unauthenticated Network-Exposed Management and Destructive APIs
server.py:50Missing Canonical Path Confinement for User-Controlled Skill Names
assets/index.html:308Stored DOM Cross-Site Scripting Through Inline Event Handlers
SKILL.md:106Destructive Shell Deletion Workflow Lacks Safe Argument and Path Handling
The declared description presents a broad, all-in-one lifecycle manager for skills, including listing, viewing, creating, deleting, searching, auditing, packaging, installing, and managing local/marketplace skills. The supplied code only implements the audit portion: directory scanning, simple frontmatter parsing, duplicate detection, orphan zip detection, issue classification, and report generation. While listing skills and health-check/audit/duplicate detection are consistent with the description, the primary behavior of this chunk is much narrower than the declared full manager. Additionally, the script advertises a --fix option and report text mentions auto-fix, but no fix logic exists in the code. Therefore the description materially overstates the implemented capabilities for this code chunk.
The description claims a broad 'full lifecycle' manager covering listing, viewing, creating, deleting, searching, auditing, packaging, and installing skills for both local and built-in marketplace skills. The supplied code only implements a subset: health/stats, list/search/filter/sort, detail view, raw SKILL.md retrieval, audit report, limited audit fix (deleting stray .zip files), and deletion restricted to agent-created skills. There is no implementation for creating skills, packaging skills, or installing skills. The code also does not actually manage a built-in marketplace directory; BUILTIN_SKILLS_DIR is defined but unused, and all operations target ~/.workbuddy/skills. Additionally, the server exposes undeclared behavior by serving these capabilities over HTTP and returning raw skill contents and file inventories. These are material gaps and extra capabilities relative to the declared description, so this is a mismatch.
The skill instructs use of a shell wildcard deletion command (rm ~/.workbuddy/skills/*.zip) for cleanup. This is dangerous because shell expansion can delete multiple files indiscriminately, and if path assumptions are wrong or symlinks/unexpected files are present, legitimate archives may be destroyed without granular validation.
触发:用户说"修复技能""清理技能""fix skills"。
审计后提供一键修复选项:
1. 删除遗留 .zip 文件:`rm ~/.workbuddy/skills/*.zip`
2. 删除 .backup 重复目录(需确认)
3. 补充缺失的 `agent_created: true`(需确认)
4. 补充缺失的 description
The skill description and all user-facing instructions in the README are presented only in Chinese, which imposes a specific language on users without any opt-in or alternative locale option. Under the stated policy, language constraints should either be optional or clearly justified as region-specific.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
4. 如果用户加了 `--full` 或"看完整内容",则展示 Markdown 全文
5. 如果是市场安装的,检查 `_skillhub_meta.json` 看是否有更新可用
### 3. 创建技能 (`--create <name>`)
触发:用户说"创建技能""新建skill""add skill"。
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
4. 如果用户加了 `--full` 或"看完整内容",则展示 Markdown 全文
5. 如果是市场安装的,检查 `_skillhub_meta.json` 看是否有更新可用
### 3. 创建技能 (`--create <name>`)
触发:用户说"创建技能""新建skill""add skill"。
The instruction "中文输出:与用户交互全程中文" forces a specific language for all user interactions. This is a natural-language locale policy issue because it does not offer the user a language choice or require opt-in.
The HTML document declares lang="zh-CN", and the visible UI text throughout the page is Chinese-only, indicating a fixed language experience. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.
The UI imports executable JavaScript from a third-party CDN at runtime, which gives that external source code execution inside the skill manager page. In a tool that can audit, export, and trigger destructive actions on local skills, a compromised CDN response or dependency tampering could manipulate displayed data, exfiltrate skill metadata, or invoke sensitive local API actions from the user's browser session.
This Python file contains user-facing natural-language text in Chinese in the module docstring and later CLI help strings, which effectively constrains the skill's interface to a specific language. The policy allows locale constraints only when they are opt-in or clearly justified; this file provides no such choice or justification.
The module docstring advertises a --fix mode in the usage string, and later help/output text also says known issues can be auto-fixed. However, the parsed --fix argument is never used anywhere in the script, which means the documented behavior actively contradicts the actual implementation.
The function docstrings and command-line help/messages throughout the script are written in Chinese, creating a consistent language restriction for operators of the tool. Because the file does not state that the tool is region-specific or provide an alternative language path, this is a natural-language policy concern.
The report tells users to use --fix to auto-fix known issues, which is an explicit behavioral claim. Since the script contains no code path that performs modifications based on args.fix, this runtime messaging is misleading and contradicts actual behavior.
The argument help text explicitly states that --fix performs automatic remediation, creating a clear expectation of side effects. In reality, the flag is only parsed and then ignored, so the implementation does not match the command's documented intent.
This Python file contains user-facing natural-language text exclusively in Chinese, including startup instructions and error messages. Because the file provides no indication that language is selectable or intentionally limited to a region-specific audience, it creates a locale-policy concern under the rule for forced language without user opt-in.
The server enables CORS for all origins, methods, and headers, which allows arbitrary websites to issue browser-based requests to this local skill-management API. Because the API includes sensitive read operations and destructive endpoints such as deletion and cleanup, a user merely visiting a malicious webpage could trigger unauthorized local actions if the service is reachable from the browser.
The skill detail endpoints return the full contents of SKILL.md plus a complete per-file inventory and sizes for any named skill. That exposes potentially sensitive local metadata and content to any caller of the API, which exceeds what is necessary for basic lifecycle management and materially increases information disclosure risk, especially when combined with the permissive CORS policy.
The manifest advertises audit and health-check capabilities, but this endpoint implements automatic remediation by deleting .zip files from the skills directory. Auditing normally implies inspection/reporting, while mutation of local files is a separate cleanup capability that is not clearly declared in the description.
No suspicious patterns detected.