Back to skill

Security audit

元典法条与案例检索

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs disclosed legal-research API work, but it recommends disabling Codex safety controls and has overly broad file-write behavior that users should review before installing.

Review this before installing. Do not follow the instruction to run Codex with danger-full-access and approvals disabled; grant only the network and file access needed for the specific legal search. Configure the API key through a protected environment variable when possible, redact sensitive client facts before sending text to the external API, and avoid using aggressive mode or enterprise lookups unless you explicitly need them. Treat local archive/ reports as sensitive case material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:94
Finding

Skill Instructions Recommend Disabling Sandbox and Approval Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:94
Vulnerability Type: Safety-control bypass instruction
Risk Level: High

Vulnerable Instruction

text
--sandbox danger-full-access --ask-for-approval never

The Skill instructs users to start Codex with these options to address potential network restrictions.

Technical Analysis

The recommended options disable two independent security boundaries:

  • --sandbox danger-full-access removes filesystem and process isolation.
  • --ask-for-approval never prevents the Agent from requesting confirmation before sensitive operations.

Legal-search functionality only requires narrowly scoped HTTPS access to open.chineselaw.com and controlled report writes. Unrestricted system access and unconditional execution are not necessary for that purpose. Presenting these settings as the recommended response to network problems weakens the security posture of the entire Agent session, rather than granting only the specific network capability needed by the Skill.

This is an instruction-layer vulnerability because the unsafe behavior is introduced through the Skill documentation and can alter the safety constraints under which the Agent executes.

Attack Path

  1. A user or Agent loads the Skill and encounters the network troubleshooting instruction.
  2. The user restarts Codex with danger-full-access and approval prompts disabled.
  3. The Skill, another subsequently loaded Skill, compromised local content, or an erroneous Agent action requests a sensitive tool operation.
  4. The operation executes without sandbox containment or interactive approval.
  5. The operation can access or modify resources available to the host user account.

Impact Assessment

Following the instruction can expose all files, credentials, repositories, and processes accessible to the user running Codex. Subsequent commands may read or modify data outside the project, execute arbitrary local programs, or transmit sensit ...[truncated 246 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to use danger-full-access and disable approvals.
  2. Keep filesystem sandboxing and approval prompts enabled by default.
  3. Request only narrowly scoped outbound HTTPS access to:
    • open.chineselaw.com
    • ydzk.chineselaw.com, if source-link connectivity checks genuinely require it
  4. Document sandbox-compatible network configuration instead of instructing users to disable the sandbox.
  5. If a network operation cannot run under the current policy, stop and ask the user to approve that specific network request.
  6. Clearly state that users should not weaken global Agent controls merely to troubleshoot DNS, proxy, or VPN problems.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/yd_search.py:1923
Finding

Unvalidated Project Name Allows Archive Path Traversal

Content
View full analysis

Vulnerability Details

File Location: scripts/yd_search.py:1923-1931
Vulnerability Type: Path traversal and unintended filesystem write
Risk Level: Medium

Vulnerable Code

python
# Parse the project subdirectory name
title = args.title or "Legal Research Report"
if args.project:
    project_name = args.project
elif args.title:
    project_name = _consolidate_slugify(args.title) or f"untitled-{datetime.now().strftime('%Y%m%d_%H%M%S')}"
else:
    project_name = f"untitled-{datetime.now().strftime('%Y%m%d_%H%M%S')}"
project_dir = SKILL_ROOT / "archive" / project_name
project_dir.mkdir(parents=True, exist_ok=True)

The original implementation assigns args.project directly to project_name. Unlike the title-derived value, it is not passed through _consolidate_slugify() and is not checked after path resolution.

Technical Analysis

The --project argument controls a filesystem path used for directory creation, report generation, and movement or copying of archive records. Python path joining does not guarantee confinement beneath the preceding path:

  • A value containing ../ can traverse out of archive/.
  • An absolute path can replace the intended base path.
  • No resolve() and containment check verifies that the final destination remains under ARCHIVE_DIR.

Later consolidation logic writes the main report to project_dir and may copy or move matched Markdown and JSON records into that directory. Consequently, a crafted project value can redirect these operations outside the Skill archive.

The project name is expected to be a logical archive identifier, so accepting arbitrary filesystem paths exceeds the minimum capability needed for report organization.

Attack Path

  1. An attacker influences the consolidate command or convinces a user to invoke it with a crafted project value, such as --project ../../outside-directory.
  2. The command assigns the value directly to project_name.
  3. project_dir.mkdir() creat ...[truncated 1188 chars]
Remediation
View remediation

Remediation Suggestions

  1. Apply the existing project-name sanitizer to explicit project arguments:
python
project_name = _consolidate_slugify(args.project)
if not project_name:
    raise ValueError("Invalid project name")
  1. Reject absolute paths and path components such as . and ...
  2. Resolve and validate the final destination before creating it:
python
archive_root = ARCHIVE_DIR.resolve()
project_dir = (archive_root / project_name).resolve()

if project_dir == archive_root or archive_root not in project_dir.parents:
    raise ValueError("Project directory must remain inside the archive root")
  1. Perform the same containment validation before every copy, move, or write operation.
  2. Refuse to overwrite existing destination files unless the user explicitly approves the replacement.
  3. Treat --project strictly as an identifier, not as an output path. Keep arbitrary output-path functionality isolated behind --output, with explicit user confirmation and separate validation.
  4. Add regression tests covering absolute paths, nested traversal, mixed separators, empty sanitized names, and symbolic-link escape attempts.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (76)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是“元典法条与案例检索”技能,预期能力应是访问或查询法律法规、案例数据。该代码并没有进行任何检索、联网访问、法律分析或返回法条/案例内容;它只是校验 query 的 interface 与 filter 字段是否符合预设规则,并用于 pre-commit/CI 硬门禁。其核心目的与声明的主要用途明显不同,因此属于描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述聚焦于“法条与案例检索”,这确实覆盖了代码中的一部分核心功能,如法条语义/关键词检索、法规详情、案例检索与案例详情。但代码的实际能力明显更广:其一,包含大量企业检索接口(企业基本信息、聚合总览、对外投资、商标、专利、软件著作权、涉诉文书、行政处罚、失信被执行人等),这已超出法条与案例检索范畴;其二,提供 hall-detect 幻觉检测功能,用于核查文本中的法规/案例引用真伪;其三,具有 archive-list、backfill-urls、consolidate、ingest、raw 等归档管理、报告生成、调试和外部 JSON 导入能力。虽然这些部分可被视为法律研究的配套工具,但其中企业信息与企业分项数据查询属于未在声明中体现的实质能力,因此描述不能准确代表代码的完整实际行为,构成不匹配。

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill explicitly instructs the agent to read API credentials from scripts/.env and validate them before each use. Secret access can be acceptable for authentication, but here the skill content normalizes direct secret-file inspection by the agent, increasing the risk of credential exposure in logs, prompts, reports, shell history, or unintended downstream tool output.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
2. 创建 API Key:登录后在个人中心创建 Key
3. 配置密钥:将 Key 填入以下文件

   scripts/.env
   ─────────────
   YD_API_KEY=sk-你的密钥(此处替换为真实 Key)
   # YD_STRATEGY=balanced

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The documented shell snippet reads YD_API_KEY from scripts/.env using grep and shell variables. This pattern materially increases the chance that secrets are exposed through process inspection, debug output, command transcripts, or accidental reuse in later commands, especially in agentic environments that preserve execution traces.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

检测命令

bash
# 检测 .env 文件和 API Key
if [ -f "scripts/.env" ]; then
  KEY=$(grep '^YD_API_KEY=' scripts/.env | cut -d'=' -f2-)
  if [ -n "$KEY" ] && [ "$KEY" != "your-api-key-here" ]; then

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This finding is part of the same credential-handling flow: the skill directs the agent to load the API key from a local secret file and test whether it is non-empty. Even without printing the key, direct secret parsing by an LLM-controlled workflow unnecessarily broadens credential exposure opportunities and violates least-knowledge principles.

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

bash
# 检测 .env 文件和 API Key
if [ -f "scripts/.env" ]; then
  KEY=$(grep '^YD_API_KEY=' scripts/.env | cut -d'=' -f2-)
  if [ -n "$KEY" ] && [ "$KEY" != "your-api-key-here" ]; then
    echo "API Key 已就绪"

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The same code path continues to operate on the extracted API key in shell state. In an agent skill that also writes reports and archives data, secret handling in plaintext shell logic is especially risky because adjacent tooling may capture command context or file snippets, causing accidental leakage of authentication material.

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

bash
# 检测 .env 文件和 API Key
if [ -f "scripts/.env" ]; then
  KEY=$(grep '^YD_API_KEY=' scripts/.env | cut -d'=' -f2-)
  if [ -n "$KEY" ] && [ "$KEY" != "your-api-key-here" ]; then
    echo "API Key 已就绪"
  else

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This line still belongs to the credential-check workflow around scripts/.env access. While checking for file existence is less severe than extracting the key itself, the overall design encourages the agent to inspect secret-storage locations directly, which increases the probability of over-broad file access and accidental disclosure.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
echo "API Key 未配置"
  fi
else
  echo ".env 文件不存在"
fi

# 读取检索策略

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 455)May include surrounding context.

md
def load_api_key():
    """从环境变量或 .env 文件加载 API Key"""
    key = os.environ.get("YD_API_KEY", "")
    if key:
        return key

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
def load_api_key():
    """从环境变量或 .env 文件加载 API Key"""
    key = os.environ.get("YD_API_KEY", "")
    if key:
        return key

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/yd_search.py (reported line 25)May include surrounding context.

python
def load_api_key():
    """从环境变量或 .env 文件加载 API Key"""
    key = os.environ.get("YD_API_KEY", "")
    if key:
        return key

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/yd_search.py (reported line 39)May include surrounding context.

python
def load_api_key():
    """从环境变量或 .env 文件加载 API Key"""
    key = os.environ.get("YD_API_KEY", "")
    if key:
        return key

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/yd_search.py (reported line 44)May include surrounding context.

python
def load_api_key():
    """从环境变量或 .env 文件加载 API Key"""
    key = os.environ.get("YD_API_KEY", "")
    if key:
        return key

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

Reading the API key from a local scripts/.env file creates a secret-at-rest pattern that is easy to misconfigure, accidentally commit, or expose through filesystem access. In agent or shared-workspace deployments, colocating credentials with executable skill code increases the chance of leakage and unauthorized reuse.

Content

Scanner excerpt · scripts/yd_search.py (reported line 30)May include surrounding context.

python
if key:
        return key

    env_path = Path(__file__).parent / ".env"
    if env_path.exists():
        for line in env_path.read_text().splitlines():
            line = line.strip()

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/yd_search.py (reported line 48)May include surrounding context.

python
strategy = os.environ.get("YD_STRATEGY", "").strip().lower()
    if strategy:
        return strategy
    env_path = Path(__file__).parent / ".env"
    if env_path.exists():
        for line in env_path.read_text().splitlines():
            line = line.strip()

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill manifest says it is for Chinese law/article/case retrieval, but the code also exposes enterprise intelligence, litigation aggregation, enforcement, tax, and other business-investigation endpoints. In an agent setting, this materially broadens the skill into organizational reconnaissance and sensitive profile-building that a caller may not expect or authorize.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These enterprise investigation commands provide direct access to company identity, litigation, punishment, tax, abnormal-operation, execution, and related aggregation data that is not justified by the stated law-and-case retrieval purpose. In an autonomous agent context, hidden recon capabilities increase privacy, misuse, and over-collection risk because the skill can be used for background investigation under the cover of legal research.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

L035 将生成报告的结构直接规定为固定中文章节名称,整体文档也未说明用户可选择其他语言或本地化输出格式。按规则,若技能在自然语言层面强制特定语言而没有用户选择或明确合理的区域限定,可视为语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requests or documents capabilities to read environment variables, read/write local files, and access the network, but it does not declare an explicit tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and makes it easier for an agent runtime to grant broader access than users expect, especially because the skill also archives sensitive legal materials locally and sends user content to an external API.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description is written as a normative instruction that the skill should be used for querying Chinese laws and cases, and the entire skill documentation and examples are exclusively in Chinese with no indication that users may choose another language. For a general-purpose skill description, this creates a language/locale constraint without explicit user opt-in or a documented policy justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill description, parameter explanations, and response messaging are presented only in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-only audience. Under the locale policy, a forced language without opt-in or explicit justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all user-facing instructions and parameter descriptions exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents all user-facing instructions, parameters, and response documentation exclusively in Chinese. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale policy issue when no justification or alternative language option is provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill manifest says this skill is for querying Chinese laws, regulations, and related cases to support legal analysis. This file instead documents an endpoint for searching enterprise/company information by name, which is a different business-information capability rather than legal article or case retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The endpoint documentation instructs users to POST arbitrary legal text for hallucination detection but does not warn that submitted text may contain sensitive client facts, case strategy, personally identifiable information, or privileged legal analysis. In a legal-research skill, this omission is more dangerous because users are especially likely to send confidential matter details to third-party analysis services without realizing the privacy and compliance implications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's natural-language description, parameters, and usage notes are entirely in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Under the policy, forcing a specific language without user choice or clear justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/validate-query-filters.py:56

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:65