Back to skill

Security audit

Skill 管理器

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible skill manager, but its dashboard exposes sensitive skill-management and deletion APIs without adequate access controls.

Install only if you trust the publisher and are prepared to run it locally with strict controls: bind the dashboard to 127.0.0.1, restrict CORS, avoid exposing the port, review deletion targets carefully, and prefer fixing the path validation and shell-deletion guidance before using cleanup or delete features.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
server.py:29
Finding

Unauthenticated Network-Exposed Management and Destructive APIs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
server.py:50
Finding

Missing Canonical Path Confinement for User-Controlled Skill Names

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/index.html:308
Finding

Stored DOM Cross-Site Scripting Through Inline Event Handlers

Content
View full analysis
` ${esc(s.name)}${s.description ? `
${esc(s.description.substring(0,80))}` : ''} v${s.version} ${getSourceBadge(s.source_type)} ${getLevelBadge(s.level)}${s.issue_count ? ` (${s.issue_count})` : ''} ${getResourceIcons(s.resources)} 查看 `).join(''); ``` ```javascript const actions = document.getElementById('drawer-actions'); actions.innerHTML = detail.agent_created ? `🗑️ 删除` : `非自建技能,请在 WorkBuddy 技能管理面板操作`; actions.innerHTML += `📥 导出`; ``` ```javascript function esc(s) { return String(s||'').replace(/&/g,'&').replace(//g,'>').replace(/"/g,'"'); } ``` ### Technical Analysis Skill directory names originate from the local filesystem and are returned by the backend. The frontend inserts those values into inline JavaScript event-handler attributes using `innerHTML`. The `esc()` helper escapes several HTML metacharacters but does not escape apostrophes. More importantly, HTML escaping is not sufficient for a value embedded inside a JavaScript string within an HTML attribute. An attacker-controlled apostrophe can terminate the JavaScrip ...[truncated 1421 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:106
Finding

Destructive Shell Deletion Workflow Lacks Safe Argument and Path Handling

Content
View full analysis
`) 触发:用户说"删除XX技能""移除XX"。 执行步骤: 1. ⚠️ **必须确认**:先展示技能详情(名称、描述、来源),然后用 `AskUserQuestion` 二次确认 2. 仅删除 `agent_created: true` 的技能(自建技能),拒绝删除内置系统技能 3. 市场技能:提示用户市场安装的 skill 可通过 WorkBuddy UI 的【技能管理】面板卸载 4. 自建技能:用 Bash 执行 `rm -rf` 删除整个目录 5. 确认删除成功 ``` ### Technical Analysis The Skill instructs the Agent to delete an entire directory using `rm -rf`, but it does not require a fixed trusted root, canonical path confinement, strict Skill-name validation, safe argument separation, shell quoting, or the `--` end-of-options marker. Skill names can be influenced by user requests and filesystem entries. If an Agent interpolates such a name or path into a shell command, shell metacharacters, command substitutions, whitespace, glob characters, or option-like values can alter the command's meaning. Even without command injection, a traversal or incorrectly resolved path can cause recursive deletion outside the intended Skill directory. The user-confirmation requirement reduces accidental invocation but does not neutralize malicious command syntax hidden in a displayed name or path. ### Attack Path 1. An attacker supplies or creates a Skill name containing shell metacharacters, command-substitution syntax, an option-like prefix, or path-navigation components. 2. The user asks the Skill Manager to delete that Skill. 3. The Agent follows the documented workflow and builds an `rm -rf` command using the untrusted name or derived path. 4. The shell interprets the injected syntax or resolves the path outside the intended root. 5. Arbitrary commands may execute, or unrelated files and directories may be recursively deleted with the Agent process's privileges. The exact exploit string depends on how the host Agent interp ...[truncated 523 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad, all-in-one lifecycle manager for skills, including listing, viewing, creating, deleting, searching, auditing, packaging, installing, and managing local/marketplace skills. The supplied code only implements the audit portion: directory scanning, simple frontmatter parsing, duplicate detection, orphan zip detection, issue classification, and report generation. While listing skills and health-check/audit/duplicate detection are consistent with the description, the primary behavior of this chunk is much narrower than the declared full manager. Additionally, the script advertises a --fix option and report text mentions auto-fix, but no fix logic exists in the code. Therefore the description materially overstates the implemented capabilities for this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description claims a broad 'full lifecycle' manager covering listing, viewing, creating, deleting, searching, auditing, packaging, and installing skills for both local and built-in marketplace skills. The supplied code only implements a subset: health/stats, list/search/filter/sort, detail view, raw SKILL.md retrieval, audit report, limited audit fix (deleting stray .zip files), and deletion restricted to agent-created skills. There is no implementation for creating skills, packaging skills, or installing skills. The code also does not actually manage a built-in marketplace directory; BUILTIN_SKILLS_DIR is defined but unused, and all operations target ~/.workbuddy/skills. Additionally, the server exposes undeclared behavior by serving these capabilities over HTTP and returning raw skill contents and file inventories. These are material gaps and extra capabilities relative to the declared description, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

The skill instructs use of a shell wildcard deletion command (rm ~/.workbuddy/skills/*.zip) for cleanup. This is dangerous because shell expansion can delete multiple files indiscriminately, and if path assumptions are wrong or symlinks/unexpected files are present, legitimate archives may be destroyed without granular validation.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
触发:用户说"修复技能""清理技能""fix skills"。

审计后提供一键修复选项:
1. 删除遗留 .zip 文件:`rm ~/.workbuddy/skills/*.zip`
2. 删除 .backup 重复目录(需确认)
3. 补充缺失的 `agent_created: true`(需确认)
4. 补充缺失的 description

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description and all user-facing instructions in the README are presented only in Chinese, which imposes a specific language on users without any opt-in or alternative locale option. Under the stated policy, language constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
4. 如果用户加了 `--full` 或"看完整内容",则展示 Markdown 全文
5. 如果是市场安装的,检查 `_skillhub_meta.json` 看是否有更新可用

### 3. 创建技能 (`--create <name>`)

触发:用户说"创建技能""新建skill""add skill"。

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
4. 如果用户加了 `--full` 或"看完整内容",则展示 Markdown 全文
5. 如果是市场安装的,检查 `_skillhub_meta.json` 看是否有更新可用

### 3. 创建技能 (`--create <name>`)

触发:用户说"创建技能""新建skill""add skill"。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction "中文输出:与用户交互全程中文" forces a specific language for all user interactions. This is a natural-language locale policy issue because it does not offer the user a language choice or require opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The HTML document declares lang="zh-CN", and the visible UI text throughout the page is Chinese-only, indicating a fixed language experience. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The UI imports executable JavaScript from a third-party CDN at runtime, which gives that external source code execution inside the skill manager page. In a tool that can audit, export, and trigger destructive actions on local skills, a compromised CDN response or dependency tampering could manipulate displayed data, exfiltrate skill metadata, or invoke sensitive local API actions from the user's browser session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing natural-language text in Chinese in the module docstring and later CLI help strings, which effectively constrains the skill's interface to a specific language. The policy allows locale constraints only when they are opt-in or clearly justified; this file provides no such choice or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module docstring advertises a --fix mode in the usage string, and later help/output text also says known issues can be auto-fixed. However, the parsed --fix argument is never used anywhere in the script, which means the documented behavior actively contradicts the actual implementation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function docstrings and command-line help/messages throughout the script are written in Chinese, creating a consistent language restriction for operators of the tool. Because the file does not state that the tool is region-specific or provide an alternative language path, this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The report tells users to use --fix to auto-fix known issues, which is an explicit behavioral claim. Since the script contains no code path that performs modifications based on args.fix, this runtime messaging is misleading and contradicts actual behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The argument help text explicitly states that --fix performs automatic remediation, creating a clear expectation of side effects. In reality, the flag is only parsed and then ignored, so the implementation does not match the command's documented intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing natural-language text exclusively in Chinese, including startup instructions and error messages. Because the file provides no indication that language is selectable or intentionally limited to a region-specific audience, it creates a locale-policy concern under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The server enables CORS for all origins, methods, and headers, which allows arbitrary websites to issue browser-based requests to this local skill-management API. Because the API includes sensitive read operations and destructive endpoints such as deletion and cleanup, a user merely visiting a malicious webpage could trigger unauthorized local actions if the service is reachable from the browser.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill detail endpoints return the full contents of SKILL.md plus a complete per-file inventory and sizes for any named skill. That exposes potentially sensitive local metadata and content to any caller of the API, which exceeds what is necessary for basic lifecycle management and materially increases information disclosure risk, especially when combined with the permissive CORS policy.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest advertises audit and health-check capabilities, but this endpoint implements automatic remediation by deleting .zip files from the skills directory. Auditing normally implies inspection/reporting, while mutation of local files is a separate cleanup capability that is not clearly declared in the description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.