Back to skill

Security audit

自动化工作流引擎

Security checks for vulnerabilities and agentic risk

Overview

This automation skill is coherent but broad enough to need Review because it supports unattended network, file, email, and database workflows without clear scoping or safety controls.

Install only in a constrained environment, review each workflow definition before running it, avoid giving it broad filesystem or database credentials, and do not run daemon mode for workflows that can send emails, call webhooks, or modify data unless you have explicit approvals and rollback plans.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
package.json:12
Finding

Non-Reproducible Dependency Installation Using Unlocked Version Ranges

Content
View full analysis

Vulnerability Details

File Location: package.json:12-17
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Low

json
"dependencies": {
  "node-cron": "^3.0.3",
  "chokidar": "^3.5.3",
  "axios": "^1.6.0",
  "nodemailer": "^6.9.7"
}

Technical Analysis

All four dependencies use caret version ranges, and the audited project contains no package lockfile. Consequently, npm install, as instructed by SKILL.md:32-36, can resolve dependency and transitive-dependency versions that were not represented in or reviewed as part of this artifact.

Caret ranges permit npm to select newer compatible releases. The absence of a lockfile also prevents verification that different installations resolve the same dependency graph. If an allowed future release or transitive dependency is compromised, defective, or contains a malicious installation script, it could enter the project without any modification to package.json.

The dependency names are ordinary npm package names, and no custom registry, Git dependency, remote archive, typosquatted name, or known malicious package is visible in the audited files. This finding therefore concerns supply-chain exposure and build reproducibility; it is not evidence that the currently declared dependencies are malicious.

Attack Path

  1. An attacker compromises the publication account or release process of a declared dependency or one of its transitive dependencies.
  2. The attacker publishes a malicious version that satisfies the declared version range or the dependency resolver's unconstrained transitive requirements.
  3. A user follows the installation instructions and executes npm install.
  4. Because no reviewed lockfile constrains the dependency graph, npm resolves and downloads the newly published package version.
  5. Malicious package installation hooks, if present, execute with the privileges of the user running npm. Alternatively, malicious dependenc ...[truncated 735 chars]
Remediation
View remediation

Remediation Suggestions

  1. Generate and commit a package-lock.json after resolving and reviewing the complete dependency graph.
  2. Use npm ci in development, deployment, and continuous-integration environments so installation fails if the manifest and lockfile disagree.
  3. Consider pinning direct dependencies to exact reviewed versions rather than caret ranges.
  4. Review dependency updates before regenerating the lockfile, including transitive changes and package lifecycle scripts.
  5. Run automated dependency vulnerability and integrity checks in continuous integration.
  6. Perform installation with a non-privileged account and restrict access to secrets and sensitive files.
  7. Where operationally feasible, disable package lifecycle scripts during installation with npm ci --ignore-scripts, enabling only explicitly reviewed scripts when required.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises automated HTTP, file, email, webhook, and database operations plus daemonized triggers, but it does not warn users that these actions can cause persistent external communication, file modification, outbound notifications, or data changes without close review. In an automation skill, missing disclosure materially increases the chance of unsafe deployment or overbroad trust, especially when workflows can be triggered on a schedule or by incoming events.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
"name": "daily-report",
  "trigger": { "type": "cron", "expr": "0 9 * * *" },
  "tasks": [
    { "type": "http", "url": "https://api.example.com/data", "save": "temp.json" },
    { "type": "transform", "input": "temp.json", "output": "report.json" },
    { "type": "email", "to": "user@example.com", "subject": "日报", "attach": "report.json" }
  ]

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The package description is written entirely in Chinese, which signals a fixed language choice without any indication that users can select another language or locale. Under the policy criteria, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and the user-facing markdown headings and instructions are presented in Chinese, but the file does not state that the skill is China-specific or provide an option for another language. This can violate language/locale policy where user-facing content should not force a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

Using a caret range for node-cron allows newer compatible versions to be installed without explicit review, which increases supply-chain risk and can introduce vulnerable or malicious updates unexpectedly. In an automation engine that runs on schedules and may execute unattended, dependency drift is more dangerous because compromised updates can persist and trigger automatically.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"keywords": ["workflow", "automation", "cron", "scheduler"],
  "license": "MIT",
  "dependencies": {
    "node-cron": "^3.0.3",
    "chokidar": "^3.5.3",
    "axios": "^1.6.0",
    "nodemailer": "^6.9.7"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
91% confidence
Finding

Using a caret range for chokidar permits unreviewed upstream releases to be pulled in, creating supply-chain exposure and reducing build reproducibility. Because this skill monitors files and likely runs continuously, a compromised or breaking dependency update could affect long-lived automation behavior.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"license": "MIT",
  "dependencies": {
    "node-cron": "^3.0.3",
    "chokidar": "^3.5.3",
    "axios": "^1.6.0",
    "nodemailer": "^6.9.7"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The unpinned axios dependency creates supply-chain and reproducibility risk, and the context is more concerning because axios is used for outbound HTTP where known classes of issues can include SSRF, proxy bypass, or response-handling flaws. In a workflow engine that performs data collection and webhook-style interactions, an unsafe or unexpectedly changed HTTP client can materially increase attack surface.

Content

Scanner excerpt · package.json (reported line 15)May include surrounding context.

json
"dependencies": {
    "node-cron": "^3.0.3",
    "chokidar": "^3.5.3",
    "axios": "^1.6.0",
    "nodemailer": "^6.9.7"
  }
}

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

Axios has multiple known advisories, and because the manifest does not pin the installed version, there is no reliable way to determine from this file whether a vulnerable release will be used. In an automation product that performs HTTP requests, exploitable axios flaws could affect data exfiltration, SSRF boundaries, or request integrity depending on application usage.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The unpinned nodemailer dependency exposes the project to supply-chain drift and makes it unclear which security fixes are present. This is more dangerous in a workflow tool that sends notifications, because historical nodemailer issues have included injection-oriented flaws and the component may process attacker-influenced email fields or content.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
"node-cron": "^3.0.3",
    "chokidar": "^3.5.3",
    "axios": "^1.6.0",
    "nodemailer": "^6.9.7"
  }
}

Unverifiable Dependency: nodemailer has 15 known advisory(ies) (CVE-2026-82661 (Nodemailer: CRLF injection in Nodemailer List-* header comments allows arbitrary); GHSA-2x7j-588g-ccc2 (Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote den); CVE-2020-7769 (Command injection in nodemailer) +12 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Nodemailer has known security advisories, and the lack of version pinning makes the actual deployed risk unverifiable from the manifest alone. In a workflow engine that sends email notifications, this can be meaningful because mail-related injection or parsing bugs may be reachable through automated, externally influenced inputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.