Back to skill

Security audit

Official Doc

Security checks for vulnerabilities and agentic risk

Overview

The main Chinese official-document tool is local and purpose-aligned, but the package includes an undocumented script that persistently logs command arguments.

Review this package before installing. The documented scripts/official.sh workflow appears to generate and check Chinese official-document text locally, but avoid running scripts/script.sh unless you accept that it may create a local official-doc data directory and retain command arguments in plaintext history.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:5
Finding

Undocumented Persistent Plaintext Logging of Command Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 5–7, 35, and 78–89
Vulnerability Type: Undocumented persistent storage of potentially sensitive command arguments
Risk Level: Low

Vulnerable Code

bash
DATA_DIR="${OFFICIAL_DOC_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/official-doc}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }
bash
case "${1:-help}" in
    init) shift; cmd_init "$@" ;;
    check) shift; cmd_check "$@" ;;
    build) shift; cmd_build "$@" ;;
    test) shift; cmd_test "$@" ;;
    deploy) shift; cmd_deploy "$@" ;;
    config) shift; cmd_config "$@" ;;
    status) shift; cmd_status "$@" ;;
    template) shift; cmd_template "$@" ;;
    docs) shift; cmd_docs "$@" ;;
    clean) shift; cmd_clean "$@" ;;

Technical Analysis

The script creates a persistent directory under the invoking user's data directory as soon as it runs. Most supported commands then call _log, which appends the command name and its first argument to history.log in plaintext.

This behavior is not documented in SKILL.md and is unrelated to the advertised official-document generation functionality. If a user supplies confidential project names, document subjects, internal identifiers, tokens, or other sensitive values as the first command argument, that value can remain on disk after execution.

The directory and log file are created using permissions determined by the process umask. The script does not explicitly enforce restrictive permissions. On a system with a permissive umask or shared access to the selected OFFICIAL_DOC_DIR, another local account or process could read the retained arguments.

No evidence indicates that the log is transmitted over a network, executed as code, or used to obtain elevated privileges.

Attack Path

  1. A user or automated agent invokes t ...[truncated 1312 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove scripts/script.sh if it is unrelated to the skill's documented official-document functionality.

  2. If the script is intentionally distributed, document its purpose, filesystem modifications, retention behavior, and log location in SKILL.md.

  3. Disable command-history logging by default and require explicit user opt-in.

  4. Do not log raw command arguments. Record only fixed command identifiers, or redact values that may contain confidential data.

  5. Create the storage directory and log with restrictive permissions:

    bash
    umask 077
    mkdir -p -- "$DATA_DIR"
    touch -- "$DATA_DIR/history.log"
    chmod 700 -- "$DATA_DIR"
    chmod 600 -- "$DATA_DIR/history.log"
    
  6. Validate OFFICIAL_DOC_DIR before use and reject unsafe or unintended shared locations.

  7. Add configurable retention limits and a documented command for securely deleting stored history.

  8. Remove the unused DB variable to reduce ambiguity about the script's persistent storage behavior.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's user-facing output, templates, help text, and formatting logic are entirely hardcoded in Chinese, including date formatting and all generated document content. Because the file provides no language selection, opt-in, or justification that it is intentionally restricted to a Chinese-only/regional compliance context, it violates the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The text states that official documents must avoid colloquial language and uses Chinese formal administrative style throughout, but it does not indicate that this language constraint is optional or limited to a China-specific use case. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill name, description, and body are primarily presented in Chinese, and the usage context implies a Chinese official-document workflow without stating that users may choose another language. This can conflict with language/locale policy requirements when a skill effectively enforces a specific language absent user opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command list and descriptions imply operational behaviors such as initializing projects, running checks, building, testing, deploying, generating docs, and cleaning artifacts. However, the corresponding command handlers only echo status text and call _log, with no actual workflow automation performed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.