Back to skill

Security audit

Opc Board

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated idea-review purpose, but its HTML report path can render unescaped user-provided content in a browser.

Install only if you are comfortable using a Chinese-oriented idea-review assistant. Prefer Markdown output or ensure the host escapes all HTML placeholders, validates class/style/SVG values, and renders HTML reports in a sandbox before opening reports built from untrusted input.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/report-template-pro.html:239
Finding

Unescaped User-Controlled Content in Generated HTML Reports

Content
View full analysis
__project_name__

__one_line_summary__

``` ```html __info_item____info_value____info_source__ ``` ```html L1 __l1_name____l1_score____l1_note__ ``` ```html 1 __challenge__ __level__ __concern__ ``` The same advisor row pattern is repeated for all five advisors at lines 517-537. ```html P0 __point__ __impact__ __cost__ __solution__ ``` ```html
  • __owner__ completes __deliverable__ by __deadline__
  • ``` The Skill instructs the host to copy and open HTML assets in a browser when embedding is unavailable: ```markdown - Host support permitting, embed it; otherwise copy the asset and open it in a browser. ``` ### Technical Analysis The HTML template contains placeholders populated from report data, including values derived from user-controlled fields such as the project name, positioning, and other intake information. No instruction requires contextual HTML encoding, sanitization, or strict validation before these values are su ...[truncated 2433 chars]
    Remediation
    View remediation
    `, `"`, and `'` before inserting untrusted values into HTML. - Apply encoding at the final rendering boundary rather than relying on prior input processing. 2. **Use context-specific validation** - Permit only numeric values for scores, percentages, SVG coordinates, and gauge offsets. - Map CSS classes such as decision and risk styles through a fixed allowlist. - Reject arbitrary values in class, style, SVG, and other attribute contexts. 3. **Prefer safe DOM construction** - Build reports with DOM APIs and assign untrusted values through `textContent`. - Set validated numeric and enumerated attributes explicitly with `setAttribute`. - Avoid raw string concatenation and unrestricted placeholder replacement. 4. **Add a restrictive Content Security Policy** - For a self-contained report, use a policy such as: ```html ``` - If additional resources become necessary, allow only explicitly trusted origins. - Do not permit inline scripts or event handlers. 5. **Sandbox embedded reports** - If the host embeds the report in an iframe, omit `allow-scripts` unless scripts are essential. - Use a unique or opaque origin so report content cannot access host-origin data. 6. **Add security regression tests** - Test every placeholder with payloads including: ```html "> ``` - Verify that payloads appear only as visible text and never create executable DOM nodes. ]]>
    Vulnerability Patterns
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    Findings (10)

    Hidden Instructions

    High
    Category
    Prompt Injection
    Confidence
    70% confidence
    Finding

    Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

    Content

    Scanner excerpt · references/report-template-pro.html (reported line 205)May include surrounding context.

    html
    </style>
    </head>
    
    <!--
      OPC Board Dashboard Report Template
      ====================================
      Placeholder format:  __placeholder_name__
    

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The trigger list includes very broad, natural-language phrases such as '这个想法靠谱吗?' and 'is this idea viable', which are common in ordinary conversation and can cause the skill to activate when the user did not explicitly request this workflow. Unintended activation can derail the conversation, force an unsuitable intake/reporting flow, and make the assistant mis-handle user intent, especially in multilingual contexts where these phrases are generic.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The file declares lang="zh-CN" and all visible UI text is written in Chinese, which imposes a specific language/locale on users. Under the policy, locale constraints should either be optional for the user or clearly justified as region-specific; neither is present in this file.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    97% confidence
    Finding

    This markdown template is written entirely in Chinese and presents all report headings, labels, and disclaimers in a single fixed language. There is no indication that the user can choose another language or that the locale restriction is required for a justified region-specific use case, which matches the policy's language/locale violation criteria.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The HTML root element hard-codes lang="zh-CN", which makes the template default to Simplified Chinese locale behavior. The file does not offer a user-selectable language/locale option or explain that the template is intended only for a China-specific context, so this is a natural-language locale policy concern.

    Content

    No source excerpt is available for this finding.

    Ae4

    Medium
    Category
    analysis-evasion
    Confidence
    80% confidence
    Finding

    Suspicious Unicode normalization or mixed-script content

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The skill content strongly constrains output to Chinese and defines a Chinese-only reporting structure without offering user-language choice or documenting locale limitations. This can cause unsafe or misleading behavior in multilingual environments, including user misunderstanding of risk decisions, failed operator review, and reduced accessibility for downstream systems expecting another language.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The skill content is written entirely in Chinese and prescribes a fixed output/style without indicating any user-language detection, preference check, or opt-in path. This can override or conflict with a user's requested language, reducing transparency and reliability of the agent's behavior, though it does not by itself create direct code-execution or data-exfiltration risk.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    76% confidence
    Finding

    The top-level presentation and examples are explicitly bilingual in Chinese and English, but the file does not state that the skill should follow the user's preferred language or ask for language choice. This can create a locale-policy issue if the skill consistently responds in a fixed bilingual format rather than honoring user preference.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    82% confidence
    Finding

    The manifest includes the tag "chinese", which can indicate a language or locale limitation. In this file, there is no accompanying explanation that the skill offers language choice or that a Chinese-specific scope is required, so the metadata may imply a language policy constraint without explicit opt-in.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.