T09 · Insecure Skill Coding Practices
- Location
scripts/generate-all.sh:67- Finding
Python Code Injection Through a Crafted Data-File Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This quotation generator is purpose-aligned overall, but it has under-scoped execution and document-safety issues that merit review before installation.
Install only after reviewing the workflow boundaries. Avoid running generate-all.sh on untrusted filenames, do not open generated HTML from untrusted quotation data, disable or remove the automatic OKKI sync unless you trust the sibling script, and prefer local pinned assets with HTML escaping before sending quotes to customers.
scripts/generate-all.sh:67Python Code Injection Through a Crafted Data-File Path
scripts/generate_quotation_html.py:135Stored HTML and JavaScript Injection in Generated Quotations
{company_tagline}
{company_address}
{company_email}
{company_website}
{customer_name}
Attn: {customer_contact}
{customer_address}
``` Product fields are appended without escaping: ```python html_content += f''' {idx:02d}{description}
{spec_text}
{quantity} ...[truncated 3054 chars]scripts/generate_quotation_html.py:138Unpinned Remote JavaScript Executes in Documents Containing Sensitive Quotation Data
scripts/generate-all.sh:199Routine Generation Automatically Executes an External Synchronization Script
The documented control relies on a simple environment variable, QUOTATION_DEV_ENV=true, to authorize skipping validation. Environment variables are easy to set in many execution contexts, so this is not a strong security boundary and can be abused to generate documents from unvalidated data in misconfigured or shared environments.
if args.skip_validation:
import os
if os.environ.get('QUOTATION_DEV_ENV') != 'true':
print("❌ 错误:--skip-validation 仅限开发环境")
print("请设置环境变量:export QUOTATION_DEV_ENV=true")
print("⚠️ 生产环境禁止跳过数据验证")
sys.exit(1)
The documented successful path confirms that setting QUOTATION_DEV_ENV=true enables validation bypass. Because the protection is only a mutable environment variable, anyone with control over process invocation can suppress data validation and generate outputs from unsafe or placeholder inputs.
export QUOTATION_DEV_ENV=true python3 generate_quotation_html.py --data test.json --output test.html --skip-validation
This test example confirms that merely exporting QUOTATION_DEV_ENV=true is enough to bypass validation. In skill context, the workflow generates customer-facing quotation documents, so bypassing validation can lead to publication of sample, incorrect, or untrusted customer data.
测试 2:设置环境变量
export QUOTATION_DEV_ENV=true
python3 generate_quotation_html.py --data test.json --output test.html --skip-validation
结果:
The document asserts that production cannot bypass validation, but earlier examples show Excel/Word support a quick-test path that skips validation. If that flag is callable outside tightly controlled test contexts, users can generate outputs from unvalidated or sample data, undermining the main safety control.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
Even if some static-analysis details are overstated, the core issue remains that the top-level description promises capabilities not clearly substantiated by the skill definition. Misrepresentation of security controls is a real operational vulnerability because it induces unsafe trust in automation handling external-facing business artifacts.
The documented --skip-validation option explicitly allows bypassing the skill's main safeguard against sample or invalid customer data. Even though it is framed as development-only, the gate is an environment variable, which is easy to set accidentally or intentionally, enabling generation of customer-facing documents without the promised controls.
绕过限制(仅限开发环境):
# HTML 脚本支持 --skip-validation(需环境变量)
export QUOTATION_DEV_ENV=true
python3 generate_quotation_html.py --data test.json --output test.html --skip-validation
This second occurrence confirms that validation bypass is an officially documented workflow rather than an incidental internal hook. In a skill intended to prevent sample data from reaching customers, an easy bypass undermines the integrity of the control and can lead directly to reputational damage or erroneous external communications.
# HTML 脚本支持 --skip-validation(需环境变量)
export QUOTATION_DEV_ENV=true
python3 generate_quotation_html.py --data test.json --output test.html --skip-validation
# Excel/Word 脚本无跳过选项,强制验证
The version history advertises the presence of --skip-validation, reinforcing that the bypass is a supported feature. Supported bypasses for mandatory safety checks are dangerous because they normalize circumvention and make it harder to guarantee that all generated quotations satisfy validation before external use.
- ✅ `pre_send_checklist.py` - 发送前强制检查清单(11.8KB)
- ✅ Excel 脚本集成验证(防止绕过)
- ✅ Word 脚本集成验证(防止绕过)
- ✅ HTML 脚本集成验证 + `--skip-validation` 环境限制
- ✅ `generate-all.sh` 生成前强制验证
- ✅ 示例数据检测(公司名/邮箱/地址/电话/报价单号)
- ✅ 验证失败立即终止,无法绕过
The module docstring at L02 and function docstring at L15-L22 state that the script adds page numbers at the bottom right of a PDF. However, the loop at L35-L45 only copies pages unchanged, and the comments/messages at L38-L58 explicitly admit that no page numbers are added and suggest manual or external-tool workflows instead.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f" {i}. {err}")
print()
print("请检查数据文件,确保使用真实客户信息。")
print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
sys.exit(1)
print("✅ 数据验证通过")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f" {i}. {err}")
print()
print("请检查数据文件,确保使用真实客户信息。")
print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
sys.exit(1)
print("✅ 数据验证通过")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f" {i}. {err}")
print()
print("请检查数据文件,确保使用真实客户信息。")
print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
sys.exit(1)
print("✅ 数据验证通过")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f" {i}. {err}")
print()
print("请检查数据文件,确保使用真实客户信息。")
print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
sys.exit(1)
print("✅ 数据验证通过")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f" {i}. {err}")
print()
print("请检查数据文件,确保使用真实客户信息。")
print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
sys.exit(1)
print("✅ 数据验证通过")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f" {i}. {err}")
print()
print("请检查数据文件,确保使用真实客户信息。")
print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
sys.exit(1)
print("✅ 数据验证通过")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f" {i}. {err}")
print()
print("请检查数据文件,确保使用真实客户信息。")
print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
sys.exit(1)
print("✅ 数据验证通过")
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
print(f" {i}. {err}")
print()
print("请检查数据文件,确保使用真实客户信息。")
print("如需要测试,请使用 --skip-validation 参数(仅限开发环境)")
sys.exit(1)
print("✅ 数据验证通过")
No suspicious patterns detected.