Back to skill

Security audit

web-data-extractor(网页数据采集器,支持 CSS/XPath 选择器、批量抓取、自动分页、数据导出(CSV/JSON)。 适用于市场调研、竞品分析、内容聚合。)

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a web-scraping/export purpose, but it requests undocumented command-execution authority that is broader than the documented workflow needs.

Review this skill before installing. Its scraping and export behavior is expected, but the manifest grants local command execution that is not explained by the documentation. Install only if you are comfortable with that extra authority, or prefer a version that removes exec and adds clearer confirmation for bulk fetching and file output locations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
config.json:21
Finding

Excessive and Undisclosed Command-Execution Capability

Content
View full analysis

Vulnerability Details

File Location: config.json, lines 21–26
Vulnerability Type: Excessive privilege and permission declaration mismatch
Risk Level: Medium

Complete Code Snippet:

json
"capabilities": [
  "web_fetch",
  "read",
  "write",
  "exec"
],

Technical Analysis

The configuration grants the Skill the exec capability, which can permit local command execution. This capability exceeds the requirements declared in SKILL.md, where only web_fetch, read, and write are listed, and it is not needed by the documented webpage retrieval and data-export workflows.

Granting arbitrary execution capability without a documented operational requirement violates the principle of least privilege. Although the reviewed package contains no executable implementation or demonstrated malicious command, retaining exec unnecessarily expands the authority available to the Skill and increases the consequences of malicious, compromised, or manipulated instructions.

Attack Path

  1. The runtime loads config.json and grants the declared capabilities.
  2. A user activates the Skill for a web-scraping or data-export task.
  3. Malicious or externally manipulated instructions cause the Skill to request an unrelated local command through exec.
  4. If the runtime authorizes the request based on this capability, the command executes with the privileges of the Agent process.
  5. The command may access or modify resources available to that process.

This is a capability-based attack path. The reviewed files do not contain an implementation that actively performs these exploitation steps.

Impact Assessment

Successful exploitation could allow execution of arbitrary local commands within the security context of the Agent runtime. Depending on runtime isolation and operating-system permissions, this may expose local files, permit modification of accessible data, launch additional processes, or ...[truncated 184 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the capabilities array because the documented functionality only requires webpage retrieval and file operations.
  2. Keep permission declarations consistent across config.json and SKILL.md.
  3. If command execution is genuinely required, document each legitimate use case and replace unrestricted execution with a narrowly scoped command allowlist.
  4. Validate command names and arguments against fixed schemas; do not pass webpage content, selectors, URLs, filenames, or other untrusted values to a shell.
  5. Execute any required subprocess in a sandbox with minimal filesystem access, restricted network access, resource limits, and a dedicated low-privilege identity.
  6. Require explicit user confirmation before executing commands that modify files, start processes, or access sensitive resources.
  7. Add automated checks that reject capability declarations not justified by the Skill's documented behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger set contains broad, common phrases such as '网页抓取', '数据采集', 'web scraping', and 'data extraction', which can cause the skill to activate in contexts where the user did not explicitly intend to invoke it. Because the skill has sensitive capabilities including web_fetch, write, and especially exec, overbroad activation increases the chance of unintended network access, data collection, file writes, or downstream abuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest requests the exec capability even though the stated purpose is web fetching, parsing, and exporting data. Unnecessary command-execution rights materially expand the attack surface: if the skill is triggered on untrusted input or later extended with unsafe command construction, it could run local commands, access sensitive files indirectly, or chain with other capabilities for host compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill name and summary are presented entirely in Chinese, which imposes a specific language on users without indicating any language choice or region-specific justification. Under the policy, locale or language constraints should be optional or clearly documented when they are intentional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file uses Chinese throughout, but does not state that the skill is intended only for Chinese-speaking users or offer any language choice. Under the policy rule for language or locale constraints, forcing a single language without user opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and main documentation are presented in Chinese, which effectively forces a specific language for users without indicating any opt-in or region-specific requirement. The policy allows locale constraints only when user choice is offered or the restriction is clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly encourages bulk web fetching and file export but does not warn users that using it will initiate network requests and write data to local files. In agent environments, missing disclosure can lead to unintended external access or silent file creation, which weakens user consent and operational safety even if the functionality is expected for this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest description is written only in Chinese while the trigger list mixes Chinese and English, which may impose a language-specific experience without documenting user choice or a region-specific constraint. There is no indication that the skill is intentionally limited to Chinese-speaking users or that users can select their preferred language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.