Back to skill

Security audit

CMIC Skill Scanner (BCLinux 21 / 低版本 glibc Linux x64)

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible local skill scanner, but its install path downloads and runs a native binary from mutable release metadata and the docs conflict about external scanner execution.

Review this before installing. Prefer building from source or using a pinned, signed release. Do not let an agent download and execute the release ZIP automatically unless you trust the release host and have verified provenance. Treat external scanner mode as an opt-in capability that may clone code and install dependencies.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
INSTALL.md:15
Finding

Remote-controlled binary retrieval and execution through a mutable release manifest

Content
View full analysis

Vulnerability Details

File Location: INSTALL.md, lines 15-27
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

The following is an English translation of the relevant installation instructions; the executable commands are reproduced exactly:

text
1. Read `latest.json` from the repository root.
2. Select the entry in `assets[*]` matching the current platform.
3. Download the ZIP using `download_url`.
4. Calculate the ZIP's SHA-256 and compare it with `assets[*].sha256`.
5. Extract the ZIP and enter the extracted skill root directory.
6. Open `SKILL.md` and `INSTALL.md` from the extracted package.
7. Run the bundled program to confirm that it works:

./assets/bin/skillscan version
./assets/bin/skillscan review /path/to/skill
./assets/bin/skillscan review /path/to/skills --output-dir /tmp/skillscan-out

Technical Analysis

The installation workflow obtains both the executable download location and its expected SHA-256 digest from the same remotely maintained latest.json manifest. A checksum proves only that the downloaded file matches the value in that manifest; it does not establish publisher authenticity when the payload and checksum share the same trust boundary.

If the release branch, repository account, release-hosting account, or manifest-delivery channel is compromised, an attacker can replace both download_url and sha256. The documented validation will then accept the attacker's ZIP, after which the Agent is explicitly instructed to execute the extracted binary.

The reviewed artifact does not contain latest.json, assets/bin/skillscan, or the binary's source code. Although SKILL.md and assets/build/build-info.json state an expected checksum, the executable itself is absent, so its contents and behavior cannot be independently audited from this package.

Attack Path

  1. An attacker compromises the account, branch, rele ...[truncated 1582 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not obtain the payload URL and sole trust decision from the same mutable manifest.
  2. Pin the approved release URL, version, archive digest, and platform mapping in the reviewed skill package.
  3. Sign release artifacts or manifests with a detached cryptographic signature and verify them using a public key distributed through a separate, trusted channel.
  4. Restrict downloads to an explicit allowlist of HTTPS hosts and reject redirects to unapproved domains.
  5. Require explicit user confirmation before downloading, extracting, or executing any native binary.
  6. Extract archives into a newly created restricted directory and reject absolute paths, parent-directory traversal, symlinks, and unexpected executable files.
  7. Include the corresponding source code and reproducible build instructions so reviewers can verify that the published binary matches the audited source.
  8. Run the scanner with least privilege in a sandbox that limits filesystem access, credentials, environment variables, process creation, and network access.
  9. Fail closed if signature verification, checksum validation, platform matching, or provenance validation cannot be completed.
  10. Ensure documentation consistently describes external-engine behavior and never enables external execution or dependency installation without explicit user authorization.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
**What the tool does NOT do by default:**
- Does NOT upload data anywhere
- Does NOT connect to the network
- Does NOT access credentials, SSH configs, or environment variables
- Does NOT execute external tools unless you explicitly configure `--engine external`

## 工作流程

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installation flow explicitly instructs the agent to download an archive, verify its hash from the same release metadata source, extract it, and execute an included binary. Even with integrity checking, this still results in running untrusted remote code, and the document does not clearly warn that installation includes code execution or require an explicit user confirmation boundary before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The optional external scanner path clones a remote repository and states that first run will automatically create a virtual environment and install dependencies. This introduces additional network access, supply-chain exposure, and environment changes, but the instructions do not clearly disclose those effects or require consent before fetching and executing code from external sources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file mixes English and Chinese, but the main description field is only in Chinese. This can violate a language/locale policy when the skill imposes a specific language without giving the user a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Several headings and usage instructions, such as prerequisites and workflow, are presented in Chinese only. Because the file does not state that the skill is region-specific or let the user choose a language, this creates a natural-language locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 适用于所有文件。标题和整体指令均以中文固定表达“给 Agent 的安装说明”“当用户要求安装…时,按下面流程执行”,未体现任何语言/locale 选择或用户 opt-in,构成语言策略上的潜在限制。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest text in short_description and default_prompt is written only in Chinese, which effectively constrains the skill's interaction language without any indication of user opt-in or locale-specific justification. Under the policy rule, language restrictions should be optional or clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.