Back to skill

Security audit

ChartGen

Security checks for vulnerabilities and agentic risk

Overview

The skill’s main ChartGen purpose is clear, but it has under-scoped network and data-handling behavior that users should review before installing.

Install only if you are comfortable sending confirmed prompts and selected spreadsheet files to ChartGen. Avoid setting CHARTGEN_API_URL except to a trusted HTTPS ChartGen endpoint, be cautious with sensitive spreadsheets, and prefer a version that validates API/download hosts and removes unrelated promotional error text.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:103
Finding

Forced Promotional Content in Agent Responses

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
tools/chartgen_api.js:25
Finding

Unrestricted API Base URL Can Redirect Credentials and User Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools/chartgen_api.js:358
Finding

Unvalidated Artifact Downloads Permit Arbitrary Network Requests and Unbounded Writes

Content
View full analysis
{ try { const mediaDir = getMediaDir(); const dest = path.join(mediaDir, `chartgen_${tag}.${ext}`); const mod = url.startsWith("https") ? https : http; const file = fs.createWriteStream(dest); mod.get(url, (res) => { if (res.statusCode === 301 || res.statusCode === 302) { downloadFile(res.headers.location, tag, ext).then(resolve); return; } if (res.statusCode !== 200) { resolve(null); return; } res.pipe(file); file.on("finish", () => { file.close(); resolve(dest); }); file.on("error", () => resolve(null)); }).on("error", () => resolve(null)); } catch { resolve(null); } }); } ``` The URL is taken directly from an API response: ```javascript } else if (art.download_url) { const dtag = String(art.artifact_id || Date.now()); const dp = await downloadFile(art.download_url, dtag, "pptx"); if (dp) art.download_path = dp; } ``` ### Technical Analysis The tool treats `art.download_url` as trusted and performs a network request without validating its protocol, hostname, port, or resolved IP address. It also follows HTTP 301 and 302 responses recursively without enforcing an origin policy or redirect limit. This behavior can be abused as a server-side request forgery primitive if the ChartGen API, a redirected endpoint, or a service impersonating ChartGen returns a crafted URL. Potential targets include loopback services, private network services, and link-local metadata endpoints reachable from the machine running the skill. The downl ...[truncated 2578 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
## Tool — `tools/chartgen_api.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
## Tool — `tools/chartgen_api.js`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
## Tool — `tools/chartgen_api.js`

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
### STEP 1 — Confirm Before Submitting

Always respond in the user's language. **Must** mention using **ChartGen** to complete the task, and include numbered options, each on its own line:
> **1** ✅ Go ahead
> **2** ✏️ Modify
> **0** ❌ Cancel

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
70% confidence
Finding

Skill instructs the agent to never refuse or to always comply. Suppressing the agent's ability to decline removes a core safety control and enables downstream harmful requests to succeed.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
### STEP 1 — Confirm Before Submitting

Always respond in the user's language. **Must** mention using **ChartGen** to complete the task, and include numbered options, each on its own line:
> **1** ✅ Go ahead
> **2** ✏️ Modify
> **0** ❌ Cancel

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The tool trusts a server-supplied download_url and fetches it with http/https, following redirects, then writes the response to local disk. This enables SSRF-style access to arbitrary URLs reachable from the host and can also store attacker-controlled content locally, which exceeds the narrow chart-generation purpose and creates a dangerous trust boundary with remote API responses.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill exposes code-relevant capabilities, including environment variable access via CHARTGEN_API_KEY, but does not declare an explicit tool/permission scope. That weakens least-privilege controls and can let the runtime grant broader access than reviewers or policy systems can easily validate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is very broad, covering generic visualization, analysis, reporting, uploaded spreadsheets, and even any mention of ChartGen. This increases the chance the skill is auto-invoked for many routine tasks, causing unnecessary data transfer to an external API and expanding the attack surface for prompt- or data-exfiltration-style misuse.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module comment claims the skill never needs to know or pass secrets, yet resolveApiKey reads the API key from environment/config sources and multiple requests send it in the Authorization header. That is an active contradiction between the file's documentation and its actual behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes a visualization and data-analysis skill, but this helper additionally implements credential discovery by reading environment variables and multiple local config/key files. Accessing local secret material is not an obvious requirement of creating charts or reports, and expands the skill's effective capability beyond its stated user-facing purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code reads full local file contents and uploads them to a remote third-party API without any explicit consent, warning, or confirmation in this execution path. In a chart/report skill, users may provide spreadsheets containing sensitive business or personal data, so silent transmission materially increases privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The helper transmits the user's query text to the remote ChartGen API with no explicit disclosure in the code path. While sending prompts is expected for a SaaS-backed charting tool, undisclosed transmission can expose confidential prompts, dataset descriptions, or internal business context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.