Back to skill

Security audit

AntV S2 海量数据表格指南

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-style AntV S2 guide; it has one unsafe example users should harden, but no bundled code that runs or persists.

Install only if a Chinese-language AntV S2/Vue3 guide is useful to you. If you reuse its link-field click example, add URL parsing, protocol/origin allowlisting, and open approved links with noopener,noreferrer.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:205
Finding

Unvalidated Table Field Passed to window.open()

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:205-208
Vulnerability Type: Unvalidated external navigation
Risk Level: Medium

typescript
// 链接字段点击
s2Instance.on(S2Event.GLOBAL_LINK_FIELD_JUMP, (data) => {
  window.open(data.fieldValue)
})

Technical Analysis

The example passes data.fieldValue directly to window.open() without parsing the value, restricting permitted URL schemes, or validating the destination against an origin allowlist.

If the table data can be influenced by an attacker, a malicious value could cause the application to open an attacker-controlled website when a user activates the corresponding link field. This creates a phishing or unsafe-redirection risk. The call also does not explicitly request noopener,noreferrer; depending on browser behavior, the opened document may receive an opener reference and attempt reverse-tabnabbing or manipulation of the originating page.

Exploitation requires an attacker to control or influence a link-field value and persuade a user to click that field. This is documentation example code rather than an executable component bundled in the audited package, but applications adopting the example unchanged would inherit the weakness.

Attack Path

  1. An application implements the documented event handler without additional validation.
  2. An attacker inserts or influences a table record whose link field points to an attacker-controlled destination.
  3. The application renders the malicious field as an interactive link.
  4. A user clicks the field, triggering GLOBAL_LINK_FIELD_JUMP.
  5. The handler forwards the untrusted value directly to window.open().
  6. The browser opens the attacker-controlled page, which can present phishing content and, where an opener reference remains available, attempt to manipulate the original page.

Impact Assessment

Successful exploitation can redirect a user to an untrusted site and facilitate phishi ...[truncated 431 chars]

Remediation
View remediation

Remediation Suggestions

Treat all link-field values as untrusted input:

  1. Parse the value with new URL() inside a try/catch block.
  2. Permit only required schemes, preferably https:.
  3. Restrict destinations to an explicit hostname or origin allowlist where business requirements permit.
  4. Reject malformed URLs and dangerous or unnecessary schemes.
  5. Open approved links with _blank and noopener,noreferrer.
  6. Consider showing the validated destination to the user before leaving the application.

Example hardened implementation:

typescript
const allowedOrigins = new Set([
  'https://reports.example.com',
])

s2Instance.on(S2Event.GLOBAL_LINK_FIELD_JUMP, (data) => {
  try {
    const url = new URL(String(data.fieldValue))

    if (url.protocol !== 'https:' || !allowedOrigins.has(url.origin)) {
      return
    }

    window.open(url.href, '_blank', 'noopener,noreferrer')
  } catch {
    // Reject malformed URLs.
  }
})
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example binds a link-field jump handler directly to window.open(data.fieldValue) with no validation, protocol allowlist, or user warning. If fieldValue can be influenced by data, this can open arbitrary external sites or dangerous URI schemes, enabling phishing, tabnabbing, or execution of browser-handled schemes depending on the environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The display name is written in Chinese ("AntV S2 海量数据表格指南") and the manifest provides no indication that users can choose another language or that the skill is intended only for a Chinese-speaking or region-specific audience. This can violate language/locale policy when a skill implicitly constrains interaction language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.