T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/generate_source_pdf.py:188- Finding
Source Directory Boundary Bypass Through Symbolic Links
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears purpose-built for Chinese software copyright paperwork, but it can copy broad source content into shareable PDFs and store personal contact details without enough safeguards.
Install only if you are comfortable with the agent reading the selected source tree and generating PDFs that may be submitted externally. Use it on trusted repositories, inspect the included files and final PDFs before sharing, keep software_info.json out of version control, and avoid entering or storing personal contact details unless required for your filing. Treat generated security, API, login, backup, and admin-function sections as draft text that must be verified or removed.
scripts/generate_source_pdf.py:188Source Directory Boundary Bypass Through Symbolic Links
scripts/generate_doc_pdf.py:1270Unescaped ReportLab Paragraph Markup in Imported Documents
代码内容明确是 generate_doc_pdf.py,其核心行为是生成“文档鉴别材料PDF(用户手册)”或把已有文本转换为PDF。虽然这与声明中的一个子能力相符,但声明将技能描述为“软著申请所需的全部材料生成器”,并特别列出软件基本信息表单和程序鉴别材料PDF(源代码高亮)两项能力,而在本代码片段中均未体现。因此,若将该代码块视为对技能实际行为的代表,则其实际能力明显窄于声明的整体用途,构成描述与行为不一致。未发现与此目的无关的可疑外部访问或越权行为;不匹配主要在于功能范围被夸大。
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The skill instructs the agent to explore a user's code repository and read source files, but it does not declare any explicit tool scope or allowed-tools constraints. In practice, this creates an authorization-boundary problem: the skill can induce file access behavior without a machine-readable limitation on which files or directories may be read, increasing the chance of overbroad repository inspection or accidental access to unrelated local files.
The skill collects detailed personal contact information including real name, address, postal code, and phone number, then instructs saving it to software_info.json, but provides no privacy notice, retention limits, masking guidance, or handling constraints. This creates unnecessary exposure of personally identifiable information in plaintext files that may be retained, shared, committed to repositories, or processed by other tools without the user's informed consent.
This markdown file contains user-facing instructions only in Chinese, which can constitute a language/locale policy violation when no opt-in or alternative language is provided. The policy specifically calls for flagging cases where a skill forces a specific language without user choice or documented justification.
The generator emits detailed claims about authentication, RBAC, encryption, audit logging, backup, API security, and other concrete product capabilities without verifying that the target software actually implements them. In this skill’s context, the output is intended for software copyright registration materials, so inaccurate security and capability assertions can become authoritative-looking compliance evidence and mislead reviewers, customers, or internal stakeholders.
The README title and description present the skill entirely in Chinese and position it specifically as a China software copyright application material generator, with no indication that users may choose another language or locale. Under the policy criteria, forcing a specific language without user opt-in is a natural-language locale policy concern.
The module docstring describes the tool as a Chinese document generator with automatic Chinese font discovery, which imposes a specific language/locale behavior. The file does not indicate that users can opt into another language or that the Chinese-only constraint is required by a clearly documented regional compliance scope.
This code file contains natural-language strings that assume Chinese as the required user language, including the module docstring and CLI help/messages. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the constraint is explicitly justified.
This code performs a file write by creating the output PDF at the chosen path, but there is no check for an existing file and no confirmation prompt before replacement. Although the script logs the target path, it does not disclose overwrite behavior or protect existing user data at that location.
No suspicious patterns detected.