Back to skill

Security audit

Pm Requirement Review Simulator

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent PRD review simulator, but its HTML report template can carry script-injection risk when report fields include untrusted PRD content.

Install only if you are comfortable with a Chinese-oriented PRD review workflow and treat HTML output as unsafe for untrusted PRD content until the template or generation step explicitly HTML-escapes all dynamic fields, allowlists style/class/numeric placeholders, and preferably uses a restrictive CSP. Markdown output is lower risk for reviewing untrusted inputs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/report-template-pro.html:505
Finding

Unescaped Dynamic Content Enables Script Injection in Generated HTML Reports

Content
View full analysis
📝 Review Meeting Script
🎯 Opening (3 min)
__script_open__
🔥 Core Argument (10 min)
__script_core__
⚠ Risk Mitigation (5 min)
__script_risk__
✅ Plan Selection
__script_plan__
🎤 Closing (5 min)
__script_close__
``` The same unsafe placeholder pattern also appears elsewhere in the template, including the requirement name in the document title and report heading, the summary, challenges, replies, RACI entries, and action items. ### Technical Analysis The report template places dynamically generated, user-influenced values directly into HTML element content. No contextual HTML encoding, sanitization, or safe DOM assignment mechanism is specified before placeholders such as `__script_open__` and `__script_core__` are replaced. PRD content is attacker-controlled input. Generated meeting-script text can preserve or reproduce malicious markup from that content. If a placeholder is replaced with a payload such as: ```html ``` the browser interprets the result as an HTML element rather than plain report text. ...[truncated 1784 chars]
Remediation
View remediation
`, `"`, and `'` in values intended to be plain text. 2. Prefer constructing the report through DOM APIs and assigning untrusted values with `textContent` rather than concatenating or substituting raw HTML. 3. If limited rich-text formatting is required, process content with a maintained allowlist-based sanitizer. Permit only necessary formatting elements and remove scripts, event-handler attributes, dangerous URL schemes, SVG, iframes, forms, and embedded objects. 4. Validate non-text placeholders separately: - Restrict CSS class placeholders to explicit allowlists. - Parse numeric and SVG-coordinate placeholders as finite numbers. - Reject arbitrary values in style attributes. 5. Add a restrictive Content Security Policy, for example by disallowing scripts and external content where the static report requires neither. CSP should be treated as defense in depth rather than a replacement for encoding. 6. Add regression tests covering payloads such as: - `` - `` - `` - Closing-tag payloads such as `` - `javascript:` links 7. Document a mandatory safe-rendering step in `SKILL.md` so any agent using the template knows that all PRD-derived and model-generated values must be encoded before placeholder replacement. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions present the skill title, usage guidance, and examples primarily in Chinese, and the trigger phrases in the manifest are also Chinese-centric, but there is no explicit statement that users may choose another language for interaction or outputs. That creates a locale/language preference constraint without clear user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares several broad, conversational phrases that should directly trigger it even when the user has not clearly asked for this specific workflow. This can cause over-invocation and context hijacking, where ordinary requests about reviewing requirements are routed into a rigid simulator flow, potentially producing unwanted structured outputs or bypassing normal intent disambiguation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file sets lang="zh-CN" and all visible UI text is in Chinese, which imposes a specific language on users. Under the policy, language constraints should either offer user opt-in/choice or be clearly documented as a justified region-specific requirement, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown playbook is written as normative operational guidance and establishes the skill's behavior entirely in Chinese from the title onward, with no indication that users may choose another language. Under the policy rule for natural-language violations, a skill that effectively forces a specific language or locale without opt-in should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The quality standards prescribe output tone and wording conventions such as '扎心' and '怼回去' in Chinese, but do not provide any alternative locale handling or user choice. Because these are mandatory output requirements for the skill, they amount to a language/locale constraint that is not clearly optional or region-justified.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes Chinese-only output and instructions without offering language negotiation or documenting a strict locale requirement. In an agent setting, this can cause user-intent mismatch, reduce reviewability by downstream operators, and make security or policy outputs less accessible to users who do not read Chinese, increasing the chance that important warnings or decisions are misunderstood or ignored.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document declares lang="en" while the title and visible branding include Chinese text (PM 需求评审模拟器), and the template contains a fixed mixed-language presentation rather than an explicit user-selectable language option. This can violate a language/locale policy where user-facing output must respect user preference or provide opt-in for a forced locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.