Back to skill

Security audit

用自然语言描述需求 → 自动生成需求文档 → 打开编辑器

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent, but it automatically writes a project file and opens an editor through an unsafe command pattern that could run unintended commands.

Review before installing. The skill's basic workflow is understandable, but it should remove shell=True, validate or constrain project_path, avoid overwriting requests.txt without confirmation, and ask before launching an external editor.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
agent.py:48
Finding

Shell-Enabled Editor Invocation May Permit Command Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This duplicate finding flags the same underlying issue: shell-based process creation with a user-influenced argument. Because the skill automatically opens the generated file after writing it, exploitation could chain from path manipulation directly into arbitrary command execution in the host environment.

Content

Scanner excerpt · agent.py (reported line 56)May include surrounding context.

python
try:
        # 尝试直接调用
        subprocess.Popen([editor_path, file_path], shell=True)
        print(f"✅ 已用 {editor_name} 打开")
    except Exception as e:
        # fallback 到系统默认

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

This duplicate finding flags the same underlying issue: shell-based process creation with a user-influenced argument. Because the skill automatically opens the generated file after writing it, exploitation could chain from path manipulation directly into arbitrary command execution in the host environment.

Content

Scanner excerpt · agent.py (reported line 56)May include surrounding context.

python
try:
        # 尝试直接调用
        subprocess.Popen([editor_path, file_path], shell=True)
        print(f"✅ 已用 {editor_name} 打开")
    except Exception as e:
        # fallback 到系统默认

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructions, triggers, and examples are entirely presented in Chinese, including the directive to describe requirements in natural language, without indicating that other languages are supported or that Chinese is an opt-in choice. This can constitute a language/locale policy issue because the skill appears to impose a specific language without user choice or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are broad enough to match many ordinary coding requests, which can cause the skill to activate unexpectedly instead of only when the user explicitly wants this workflow. In this skill, unexpected activation is more dangerous because the documented behavior includes writing a file into the current project directory and opening an editor automatically, creating side effects without clear user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill performs side-effecting actions by writing requests.txt to the current project directory and automatically opening an editor, but it does not clearly warn the user before those actions occur. This is dangerous because users may invoke the skill expecting only text generation, while the skill modifies the workspace and launches applications, which can disrupt workflows or affect sensitive repositories.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language description and docstrings present the skill as Chinese-only, which can amount to a language policy violation when no user opt-in or locale justification is provided. There is no indication that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code performs a file write operation by creating or overwriting requests.txt in the specified project path. Although the module docstring mentions generating the file, the write happens without an in-flow confirmation prompt or explicit warning at the point of action, which can affect user data in the workspace.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
96% confidence
Finding

The code launches a subprocess with shell=True while incorporating a file path derived from user-controlled project_path. On Windows in particular, shell invocation can reinterpret special characters and cause command injection or unexpected command execution, making this more dangerous than a normal editor launch.

Content

Scanner excerpt · agent.py (reported line 56)May include surrounding context.

python
try:
        # 尝试直接调用
        subprocess.Popen([editor_path, file_path], shell=True)
        print(f"✅ 已用 {editor_name} 打开")
    except Exception as e:
        # fallback 到系统默认

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · agent.py (reported line 63)May include surrounding context.

python
try:
            os.startfile(file_path)  # Windows
        except:
            subprocess.Popen(["xdg-open", file_path])  # Linux


def run(task: str, project_path: str = ".") -> str:

Static analysis

No suspicious patterns detected.