Back to skill

Security audit

Quotation Workflow

Security checks for vulnerabilities and agentic risk

Overview

This quotation generator is purpose-aligned overall, but it has under-scoped execution and document-safety issues that merit review before installation.

Install only after reviewing the workflow boundaries. Avoid running generate-all.sh on untrusted filenames, do not open generated HTML from untrusted quotation data, disable or remove the automatic OKKI sync unless you trust the sibling script, and prefer local pinned assets with HTML escaping before sending quotes to customers.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate-all.sh:67
Finding

Python Code Injection Through a Crafted Data-File Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_quotation_html.py:135
Finding

Stored HTML and JavaScript Injection in Generated Quotations

Content
View full analysis
Quotation {quotation_no} - {customer_name} ``` ```python

{company_name}

{company_tagline}

{company_address}

{company_email}

{company_website}

``` ```python

{customer_name}

Attn: {customer_contact}

{customer_address}

``` Product fields are appended without escaping: ```python html_content += f''' {idx:02d}

{description}

{spec_text}

{quantity} ...[truncated 3054 chars]
Remediation
View remediation
`, ``, SVG handlers, quotes, ampersands, and closing HTML tags. 8. Verify the rendered bank and total fields against the source data immediately before sending. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/generate_quotation_html.py:138
Finding

Unpinned Remote JavaScript Executes in Documents Containing Sensitive Quotation Data

Content
View full analysis
``` The downloaded Lucide code is then invoked: ```html ``` ### Technical Analysis Every generated quotation references executable JavaScript hosted by third-party content-delivery networks. In particular, `lucide@latest` explicitly tracks a mutable release rather than a reviewed version. Neither JavaScript resource has a Subresource Integrity hash. Consequently, the effective code executed by the quotation can change after this project has been audited. A compromised CDN, package publisher, DNS path, or upstream release can cause attacker-controlled JavaScript to execute in a document containing customer identity, prices, product details, and bank information. The headless PDF workflow also waits while external resources are available, so remote code may execute during automated PDF creation. The result is not reproducible and may vary based on network state or upstream changes. ### Attack Path 1. A third-party package account, CDN endpoint, distribution path, or mutable release is compromised or changed. 2. A user generates and opens a quotation while connected to the network, or headless Chrome renders it to PDF. 3. The browser downloads the current remote JavaScript because no integrity hash or local pin is enforced. 4. The remote script executes in the quotation DOM. 5. The script can inspect or modify document content and initiate outbound requests. 6. Modified content may be embedded into the P ...[truncated 656 chars]
Remediation
View remediation
``` The exact policy should be tested against the locally bundled assets. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/generate-all.sh:199
Finding

Routine Generation Automatically Executes an External Synchronization Script

Content
View full analysis
&1 || true else echo "⚠️ OKKI synchronization script does not exist; skipping" fi ``` ### Technical Analysis The standard generation workflow automatically locates and executes JavaScript outside the audited project. The default target is a sibling Skill, while the `OKKI_SYNC_SCRIPT` environment variable can replace the target with another existing file. The external script receives the quotation data-file path and quotation number. Its implementation is absent from this project, so its behavior, authentication handling, destination, and data-retention controls cannot be verified by this audit. This creates two trust-boundary problems: 1. Routine document generation implicitly triggers an integration operation that may transmit customer information. 2. The workflow executes code whose contents and lifecycle are controlled outside this package. The `|| true` suffix suppresses synchronization failure, preventing callers from reliably determining whether external processing succeeded, partially succeeded, or failed. ### Attack Path 1. A malicious or compromised `okki-sync.js` is placed at the expected sibling path, or the process environment sets `OKKI_SYNC_SCRIPT` to an attacker-controlled JavaScript file. 2. A user runs the normal `generate-all.sh` workflow without requesting ...[truncated 1104 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (115)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The documented control relies on a simple environment variable, QUOTATION_DEV_ENV=true, to authorize skipping validation. Environment variables are easy to set in many execution contexts, so this is not a strong security boundary and can be abused to generate documents from unvalidated data in misconfigured or shared environments.

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 47)May include surrounding context.

md
if args.skip_validation:
    import os
    if os.environ.get('QUOTATION_DEV_ENV') != 'true':
        print("❌ 错误:--skip-validation 仅限开发环境")
        print("请设置环境变量:export QUOTATION_DEV_ENV=true")
        print("⚠️  生产环境禁止跳过数据验证")
        sys.exit(1)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The documented successful path confirms that setting QUOTATION_DEV_ENV=true enables validation bypass. Because the protection is only a mutable environment variable, anyone with control over process invocation can suppress data validation and generate outputs from unsafe or placeholder inputs.

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 63)May include surrounding context.

设置环境变量(应通过)

export QUOTATION_DEV_ENV=true python3 generate_quotation_html.py --data test.json --output test.html --skip-validation

结果:⚠️ 警告:开发环境,跳过数据验证

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This test example confirms that merely exporting QUOTATION_DEV_ENV=true is enough to bypass validation. In skill context, the workflow generates customer-facing quotation documents, so bypassing validation can lead to publication of sample, incorrect, or untrusted customer data.

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 244)May include surrounding context.

测试 2:设置环境变量

bash
export QUOTATION_DEV_ENV=true
python3 generate_quotation_html.py --data test.json --output test.html --skip-validation

结果:

text

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document asserts that production cannot bypass validation, but earlier examples show Excel/Word support a quick-test path that skips validation. If that flag is callable outside tightly controlled test contexts, users can generate outputs from unvalidated or sample data, undermining the main safety control.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The documented --skip-validation option explicitly allows bypassing the skill's main safeguard against sample or invalid customer data. Even though it is framed as development-only, the gate is an environment variable, which is easy to set accidentally or intentionally, enabling generation of customer-facing documents without the promised controls.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

绕过限制(仅限开发环境):

bash
# HTML 脚本支持 --skip-validation(需环境变量)
export QUOTATION_DEV_ENV=true
python3 generate_quotation_html.py --data test.json --output test.html --skip-validation

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This second occurrence confirms that validation bypass is an officially documented workflow rather than an incidental internal hook. In a skill intended to prevent sample data from reaching customers, an easy bypass undermines the integrity of the control and can lead directly to reputational damage or erroneous external communications.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

bash
# HTML 脚本支持 --skip-validation(需环境变量)
export QUOTATION_DEV_ENV=true
python3 generate_quotation_html.py --data test.json --output test.html --skip-validation

# Excel/Word 脚本无跳过选项,强制验证

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The version history advertises the presence of --skip-validation, reinforcing that the bypass is a supported feature. Supported bypasses for mandatory safety checks are dangerous because they normalize circumvention and make it harder to guarantee that all generated quotations satisfy validation before external use.

Content

Scanner excerpt · SKILL.md (reported line 378)May include surrounding context.

md
- ✅ `pre_send_checklist.py` - 发送前强制检查清单(11.8KB)
  - ✅ Excel 脚本集成验证(防止绕过)
  - ✅ Word 脚本集成验证(防止绕过)
  - ✅ HTML 脚本集成验证 + `--skip-validation` 环境限制
  - ✅ `generate-all.sh` 生成前强制验证
  - ✅ 示例数据检测(公司名/邮箱/地址/电话/报价单号)
  - ✅ 验证失败立即终止,无法绕过

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module docstring at L02 and function docstring at L15-L22 state that the script adds page numbers at the bottom right of a PDF. However, the loop at L35-L45 only copies pages unchanged, and the comments/messages at L38-L58 explicitly admit that no page numbers are added and suggest manual or external-tool workflows instead.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 15)May include surrounding context.

md
print(f"  {i}. {err}")
        print()
        print("请检查数据文件,确保使用真实客户信息。")
        print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
        sys.exit(1)
    
    print("✅ 数据验证通过")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 31)May include surrounding context.

md
print(f"  {i}. {err}")
        print()
        print("请检查数据文件,确保使用真实客户信息。")
        print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
        sys.exit(1)
    
    print("✅ 数据验证通过")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 58)May include surrounding context.

md
print(f"  {i}. {err}")
        print()
        print("请检查数据文件,确保使用真实客户信息。")
        print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
        sys.exit(1)
    
    print("✅ 数据验证通过")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 59)May include surrounding context.

md
print(f"  {i}. {err}")
        print()
        print("请检查数据文件,确保使用真实客户信息。")
        print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
        sys.exit(1)
    
    print("✅ 数据验证通过")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 228)May include surrounding context.

md
print(f"  {i}. {err}")
        print()
        print("请检查数据文件,确保使用真实客户信息。")
        print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
        sys.exit(1)
    
    print("✅ 数据验证通过")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 232)May include surrounding context.

md
print(f"  {i}. {err}")
        print()
        print("请检查数据文件,确保使用真实客户信息。")
        print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
        sys.exit(1)
    
    print("✅ 数据验证通过")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 236)May include surrounding context.

md
print(f"  {i}. {err}")
        print()
        print("请检查数据文件,确保使用真实客户信息。")
        print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
        sys.exit(1)
    
    print("✅ 数据验证通过")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · P0-REVISE-REPORT.md (reported line 337)May include surrounding context.

md
print(f"  {i}. {err}")
        print()
        print("请检查数据文件,确保使用真实客户信息。")
        print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
        sys.exit(1)
    
    print("✅ 数据验证通过")

Static analysis

No suspicious patterns detected.