Back to skill

Security audit

OCAX Passport

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed node-hardware passport tool; it profiles the local machine as advertised but does not show exfiltration, persistence, or destructive behavior.

Install only if you are comfortable with a skill that reads and displays detailed local hardware and node identity information. Prefer using OCAX-specific commands, avoid sharing generated passport output publicly, and review dependency pinning if you need reproducible installs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (20)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README advertises automatic hardware collection and auto-update behavior but does not warn users about privacy exposure, telemetry-like system profiling, or the risks of changing software automatically after installation. In a skill that generates a node identity and reputation score, hardware fingerprinting can expose sensitive host characteristics and auto-update can introduce unreviewed code changes, making the omission materially risky.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language instructions, headings, and trigger descriptions are presented only in Chinese, which effectively forces a specific language for users. The file does not offer an alternative language, opt-in, or a documented reason that the skill is intentionally region- or locale-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises automatic updates but does not warn users that periodic refreshes may repeatedly collect or recompute hardware and node-identifying information. This weakens informed consent and can lead to privacy surprises, especially if the data is stored, transmitted, or surfaced automatically.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase "passport" is very broad and can be invoked during ordinary conversation unrelated to this skill. In an agent environment, that increases the chance of unintended activation and accidental disclosure or collection of node identity and hardware data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The phrase "我的节点" ("my node") is ambiguous and could match many benign requests about systems, devices, or infrastructure. That ambiguity can cause the skill to run outside user intent and expose node metadata or initiate background actions like status refreshes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase "passport" is generic and likely to overlap with common user requests about travel documents, identity, or unrelated account topics. In an agent environment, this can cause unintended invocation of the skill, exposing node or hardware-related actions or responses outside the user's intended context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code gathers extensive host fingerprinting data including hostname, CPU details, memory, storage layout, OS version, and task capability profiling without any user-facing notice, consent flow, or minimization. In an agent/skill context, this can silently expose sensitive system-identifying information that can be used for tracking, profiling, environment targeting, or downstream exfiltration if the passport is transmitted elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The GPU probing routine invokes nvidia-smi to extract model and memory information without explicit user disclosure or consent. While not an injection issue, it increases the precision of device fingerprinting and may reveal high-value hardware characteristics useful for tracking users or tailoring later attacks against the environment.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · ocax_passport.py (reported line 366)May include surrounding context.

python
"""获取GPU信息"""
        gpus = []
        try:
            result = subprocess.run(["nvidia-smi", "--query-gpu=name,memory.total", "--format=csv,noheader"],
                                    capture_output=True, text=True, timeout=5)
            if result.returncode == 0:
                for line in result.stdout.strip().split('\n'):

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The comment at L014 says the code will use a simplified version if import fails, implying the fallback is a working substitute. However, the fallback NodePassport defined here does not implement methods later invoked by the skill such as generate() and to_json(), so the documented intent of graceful fallback contradicts actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill generates and displays a node passport containing hardware and identity-related data such as node ID, owner name, OS, CPU, memory, GPU, and reputation metrics without any consent, disclosure, or access control. In an agent-skill context, this can leak host fingerprinting information and potentially sensitive owner metadata to a requester who only triggers a seemingly simple command.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This handler returns a detailed hardware inventory, including CPU model, core counts, memory availability, GPU names and memory, and storage mount usage, again with no warning or scoping. Such system profiling materially aids fingerprinting, targeting, and environmental reconnaissance, especially if exposed through an agent platform where callers may not be fully trusted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The primary descriptive text for the skill is written in Chinese, and the README does not offer an alternative language or indicate that the skill is intended only for a Chinese-language audience. The policy specifically calls for flagging language or locale constraints when they are imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description mixes English with Chinese ("节点身份证技能") but does not state whether the skill supports multiple languages or whether Chinese is intentional and user-selectable. This can conflict with language/locale policy expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The method to_json is documented as '转换为 JSON', which implies producing JSON output, but it actually returns a native Python dictionary. This is an active documentation/code mismatch rather than mere incompleteness because the file later separately calls json.dumps(...) to perform the real JSON serialization.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified as psutil>=5.9.0 without an upper bound or exact pin, which makes builds non-reproducible and can allow unexpected or vulnerable future releases to be installed. In a skill/package context, this weakens supply-chain assurance even if no currently known exploit is guaranteed from this line alone.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
psutil>=5.9.0

Unverifiable Dependency: psutil has 2 known advisory(ies) (CVE-2019-18874 (Double Free in psutil); CVE-2019-18874 (psutil (aka python-psutil) through 5.6.5 can have a double free. This occurs bec)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest does not pin psutil, so it is impossible to verify from this file whether installation will resolve to a version affected by known advisories such as CVE-2019-18874. The direct risk is limited because the constraint is >=5.9.0, which appears newer than the cited affected range, but the lack of exact pinning prevents reliable assurance and auditing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description string mixes English with Chinese ("节点身份证技能") in package metadata, which may impose a specific language on users without opt-in. There is no accompanying indication that the package is region-specific or that users can choose their preferred language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill emits user-facing content primarily in Chinese and also uses Chinese command keywords such as '节点', '我的节点', '信息', and '评分' without offering a language choice. This can violate language/locale policy when a specific language is enforced without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The docstring at L10 is written as a fixed Chinese-language instruction/name for the skill, with no indication that users can choose another language or that the tool is region-specific. Under the policy, forcing a specific language without opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.