Back to skill

Security audit

Ai Project Scaffold

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but some scripts can write or delete files outside the intended project when given unsafe paths.

Install only if you are comfortable with local scripts that create, copy, rewrite, archive, and delete project files. Use trusted project names, avoid path separators or .. components, review resolved paths before running, prefer dry-run for checkpoint cleanup, and keep backups before using clean or --fix.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/init_ai_project.py:540
Finding

Unvalidated Path Components Permit Filesystem Writes Outside the Intended Project

Content
View full analysis
Remediation
View remediation
str: if not SAFE_NAME.fullmatch(value): raise ValueError(f"Invalid {field}") return value ``` 2. Reject absolute paths and explicit `.` or `..` components for every logical name. 3. Resolve and verify every destination before writing: ```python def contained_path(root: str, *parts: str) -> str: root = os.path.realpath(root) candidate = os.path.realpath(os.path.join(root, *parts)) if os.path.commonpath([root, candidate]) != root: raise ValueError("Destination escapes the project root") return candidate ``` 4. Validate `--output` separately as the authorized parent directory, then require all generated paths to remain beneath it. 5. Before overwriting configuration files, use exclusive creation or require an explicit `--overwrite` option. Display the resolved destination and request confirmation when replacing existing files. 6. Check parent directories for symbolic links or securely open files relative to a trusted directory descriptor where the platform supports it. 7. Add tests for absolute paths, nested separators, parent traversal, symbolic links, empty names, and platform-specific path syntax. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/checkpoint_mgmt.py:106
Finding

Checkpoint Cleanup Can Delete Files from an Arbitrary Selected Directory

Content
View full analysis
list: """Scan all checkpoints in the project.""" checkpoints = [] for root, dirs, files in os.walk(base): if 'checkpoints' in root: for f in files: if f.startswith('.') or f == '.gitkeep': continue fpath = os.path.join(root, f) size = os.path.getsize(fpath) mtime = os.path.getmtime(fpath) rel = os.path.relpath(fpath, base) checkpoints.append({ "path": fpath, "rel_path": rel, "size": size, "mtime": mtime, "run_dir": os.path.dirname(os.path.dirname(fpath)), }) return sorted(checkpoints, key=lambda x: x["size"], reverse=True) ``` ```python def cmd_clean( base: str, project_name: str, keep: int = 3, dry_run: bool = False ): ckpts = find_all_checkpoints(base) run_groups = {} for c in ckpts: run_key = c.get("run_dir", "unknown") if run_key not in run_groups: run_groups[run_key] = [] run_groups[run_key].append(c) for run_dir, items in sorted(run_groups.items()): items_sorted = sorted( items, key=lambda x: x["mtime"], reverse=True ) to_delete = items_sorted[keep:] if not dry_run: for d in to_delete: try: os.remove(d["path"]) except OSError as e: print( f"Delete failed: " f"{os.path.basename(d['rel_path'])} - {e}" ...[truncated 2961 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/doc_lint.py:441
Finding

Documentation Fix Mode Can Rewrite Files Outside the Intended Project Boundary

Content
View full analysis
\n" if not content.startswith("
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个面向 AI 项目初始化与治理的综合性目录结构/流程管理能力,主目标应是搭建标准化工程结构并支持全链路管理。实际代码仅处理已存在项目目录下的 checkpoint 文件,提供 list/clean/archive/stats 四类操作,并会删除或复制文件。虽然“checkpoint 管理”在声明中被提及,因此这部分不算完全越界,但该代码块的主要行为只是声明中的一个子功能,而且缺失声明中的大部分核心能力,尤其是“创建标准化目录结构”这一主目的。因此描述与代码实际行为存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个面向 AI 模型项目的目录结构/项目脚手架与流程管理工具,核心应是创建和组织项目结构,并支持实验链路相关管理能力。实际代码仅是 scripts/doc_lint.py,一个文档 lint/审计工具,主要约束文档命名、位置、长度、模板填写情况和重复内容。它不会创建目录,不会管理实验、checkpoint、来源追踪或多方案并行。虽然声明中提到“严格文档规范防止 AI 生成冗余文档”,这一点与代码部分吻合,但只是整体声明中的很小一部分,不能覆盖其主要用途偏差。此外,代码还支持 --fix 模式修改文件头,这属于实际存在但未在声明中体现的写入能力。因此描述与代码行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明的核心用途是“创建标准化目录结构”并内置多项项目管理能力,但代码仅通过 os.listdir/os.walk 对现有目录进行扫描和报告输出。它会读取 metadata.yaml、统计文件与子目录、展示数据/分词/模型层概况,并生成全局追踪链文本视图;可选地列出文件详情。这与“创建目录结构”这一主要目的明显不符。描述中提到的来源追踪和质量记录有部分对应(如数据源 metadata、QC 脚本/报告统计、全局追踪链),但这些只是被动扫描展示,不是完整实现其余宣称能力。因此应判定为描述与实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
<project_name>/
├── README.md                          # 项目总览(≤300字)
├── _project_config.yaml               # 项目元信息
├── .gitignore                         # 自动生成,忽略 checkpoints/logs/数据/.env
├── scripts/                           # 管理脚本(自动复制)
│   ├── check_project.py               # 健康检查
│   ├── trace.py                       # 追踪链生成

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_ai_project.py (reported line 114)May include surrounding context.

python
<project_name>/
├── README.md                          # 项目总览(≤300字)
├── _project_config.yaml               # 项目元信息
├── .gitignore                         # 自动生成,忽略 checkpoints/logs/数据/.env
├── scripts/                           # 管理脚本(自动复制)
│   ├── check_project.py               # 健康检查
│   ├── trace.py                       # 追踪链生成

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/check_project.py (reported line 115)May include surrounding context.

python
("checkpoints", "**/checkpoints/"),
            ("*.pth", "*.pth"),
            ("*.safetensors", "*.safetensors"),
            (".env", ".env"),
            ("logs", "*.log"),
        ]
        for name, pattern in checks:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_ai_project.py (reported line 118)May include surrounding context.

python
.env.*
*.key
*.pem
secrets.yaml
credentials.json

# ── IDE ──

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_ai_project.py (reported line 119)May include surrounding context.

python
*.key
*.pem
secrets.yaml
credentials.json

# ── IDE ──
.vscode/

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the entire skill guidance are written exclusively in Chinese, and the file contains no statement that the assistant should adapt to the user's preferred language. Under the language/locale policy, a skill should not impose a specific language without opt-in or an explicit justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and later user-facing CLI text are written exclusively in Chinese, indicating the skill is designed to operate in a fixed language. The policy allows locale constraints only when the user is given a choice or the restriction is clearly justified, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains its top-level docstring, CLI descriptions, and operational output in Chinese only, which imposes a specific language on users. The policy for this audit flags language/locale constraints when they are forced without opt-in or a clearly documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language content entirely in Chinese in the module docstring and CLI help/output strings, which imposes a specific language on users. The policy allows locale constraints only when users are given a choice or the restriction is clearly justified as region-specific, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The argparse description, help text, and error/status messages are user-facing natural-language strings that require Chinese comprehension. Because there is no language selection, fallback, or documented regional justification, this is a language/locale policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file presents its primary description, usage text, and later user-facing output entirely in Chinese, indicating the skill is designed to operate in a single language. Under the language/locale policy, forcing a specific language without offering user choice or documenting a justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and all CLI help text are written in Chinese, and the script's user-facing messages throughout the file are likewise fixed to Chinese. For a general-purpose project initialization tool, this imposes a specific language on users without any opt-in, fallback, or justification that the tool is intended only for a Chinese-speaking environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and CLI-facing text are written exclusively in Chinese, and the script provides no option for users to select another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.