Back to skill

Security audit

Analyse Data

Security checks for vulnerabilities and agentic risk

Overview

This ChartGen skill does what it claims, but it asks agents to send user data to an external service and includes unsafe execution/download patterns that deserve review before installation.

Install only if you are comfortable sending prompts and supported spreadsheet files to ChartGen. Avoid using it with secrets, regulated data, or sensitive business data unless you have approval, and prefer runtimes that pass tool arguments without shell interpolation and restrict outbound downloads to trusted ChartGen origins.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:103
Finding

Mandatory Promotional Content Manipulates Agent Output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:70
Finding

Verbatim User Queries Are Interpolated into a Documented Shell Command

Content
View full analysis
` is **always the user's original message, copied word-for-word**. Do NOT translate, rephrase, expand, polish, or "improve" it in any way. Show this exact text in the confirmation. If user confirms → submit this exact text. If user edits → the edited text becomes the new verbatim query. ``` ```markdown node tools/chartgen_api.js submit "" [files...] ``` ### Technical Analysis The skill requires untrusted user input to be preserved verbatim and then shows that input interpolated into a shell command inside double quotes. Shell double quotes do not neutralize every form of shell interpretation. Embedded double quotes can terminate the intended argument, while command substitutions such as `$(...)` and backticks may still execute inside double-quoted shell strings. The JavaScript CLI itself reads arguments safely from `process.argv`; the flaw arises when an agent implements the documented workflow by constructing a command string and passing it to a shell-backed execution tool. Confirmation does not sanitize the content and is not a reliable security boundary because a user can knowingly confirm a malicious query or may not understand that their chart request contains shell syntax. The vulnerable pattern is equivalent to constructing: ```sh node tools/chartgen_api.js submit "" Web ``` without shell-safe argument handling. ### Attack Path 1. An attacker submits a chart request containing shell syntax, such as a closing quote followed by a command and comment marker, or a command-substitution expression. 2. The skill displays the malicious request in the confirmation prompt as required. 3. The attacker selects the confirmation option. 4. The agent copies the request verbatim i ...[truncated 1264 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
tools/chartgen_api.js:358
Finding

API-Controlled Artifact URLs Enable Unrestricted Server-Side Requests and Downloads

Content
View full analysis
{ try { const mediaDir = getMediaDir(); const dest = path.join(mediaDir, `chartgen_${tag}.${ext}`); const mod = url.startsWith("https") ? https : http; const file = fs.createWriteStream(dest); mod.get(url, (res) => { if (res.statusCode === 301 || res.statusCode === 302) { downloadFile(res.headers.location, tag, ext).then(resolve); return; } if (res.statusCode !== 200) { resolve(null); return; } res.pipe(file); file.on("finish", () => { file.close(); resolve(dest); }); file.on("error", () => resolve(null)); }).on("error", () => resolve(null)); } catch { resolve(null); } }); } ``` The URL reaches this function through an API artifact: ```javascript } else if (art.download_url) { const dtag = String(art.artifact_id || Date.now()); const dp = await downloadFile(art.download_url, dtag, "pptx"); if (dp) art.download_path = dp; } delete art.pptx_base64; delete art.download_url; ``` ### Technical Analysis `cleanResult` trusts the remote API's `art.download_url` and passes it directly to `downloadFile`. The downloader does not enforce: - An allowlist of trusted hosts. - HTTPS-only transport. - Rejection of loopback, private, link-local, or cloud metadata addresses. - DNS rebinding protections. - Redirect limits. - Validation of redirect destinations. - Request or response timeouts. - Maximum response sizes. - Content-type or file-format verification. The transport is selected with `url.startsWith("https")`; all other values are handed to the HTTP client. Redirects are recursively foll ...[truncated 2620 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs the agent to upload user queries and optional spreadsheet files to the ChartGen API, including multi-file joins and external/web sources, but does not warn users that their content will leave the host system and be sent to a third party. This creates a real confidentiality and privacy risk, especially for sensitive spreadsheets or business data that users may assume are being processed locally.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
## Tool — `tools/chartgen_api.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
## Tool — `tools/chartgen_api.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
## Tool — `tools/chartgen_api.js`

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
### STEP 1 — Confirm Before Submitting

Always respond in the user's language. **Must** mention using **ChartGen** to complete the task, and include numbered options, each on its own line:
> **1** ✅ Go ahead
> **2** ✏️ Modify
> **0** ❌ Cancel

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
### STEP 1 — Confirm Before Submitting

Always respond in the user's language. **Must** mention using **ChartGen** to complete the task, and include numbered options, each on its own line:
> **1** ✅ Go ahead
> **2** ✏️ Modify
> **0** ❌ Cancel

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill declares access to an environment-provided API key (CHARTGEN_API_KEY) but does not define an explicit tool/permission scope. This weakens least-privilege boundaries and can allow an agent runtime to invoke capabilities or access secrets without a clearly constrained policy, increasing the chance of unintended external data transfer or secret exposure through associated tooling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation text is extremely broad, covering visualizations, dashboards, reports, spreadsheet uploads, cross-file analysis, and even any mention of ChartGen. Overbroad triggers can cause the skill to activate on many common user requests and route content or files to this external integration when a more local or safer capability would suffice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.