Back to skill

Security audit

高等数学智能作业布置Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent education purpose, but it asks users to run unverified external code and handles student profiles and assignment release without enough safeguards.

Install only after replacing the placeholder repository with a trusted reviewed source, pinning commits and dependencies, and running it in an isolated non-privileged environment. Confirm the system has appropriate controls for student data privacy, staff authorization, previews, audit logs, and safe assignment release before using it with real classes.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:284
Finding

Unpinned External Repository and Dependency Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 284–293
Vulnerability Type: Unverified external source and insecure dependency execution
Risk Level: High

bash
git clone https://github.com/yourrepo/calculus-homework-assignment.git

# 2. Install dependencies
pip install -r requirements.txt

# 3. Configure the database
python setup_database.py

# 4. Start the service
python main.py --port 8000

Technical Analysis

The deployment instructions tell users to clone an external placeholder repository without pinning an immutable commit or verifying its integrity. They then direct users to install packages from the repository's uncontrolled requirements.txt file and execute setup_database.py and main.py.

The externally referenced repository and executable files are not included in the audited project. Consequently, their source, dependencies, installation hooks, and runtime behavior cannot be reviewed as part of this package. The effective payload may change after this skill has been audited because the instructions retrieve the repository's current state rather than a verified revision.

Python packages installed through pip may execute build or installation logic. The subsequent Python commands directly execute code obtained from the external source. Exploitation therefore does not require a vulnerability in the documented sample code: control of the repository, one of its dependencies, or a resolved package may be sufficient.

There is no evidence in the audited file that the referenced repository is presently malicious. The risk arises from the unverified retrieval and execution process.

Attack Path

  1. An attacker gains control of the referenced repository, causes the placeholder repository reference to resolve to attacker-controlled content, or compromises a dependency named in requirements.txt.
  2. The attacker adds malicious package installation logic, modifies setup_database.py, or modifies main.py.
  3. A user ...[truncated 1441 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the placeholder URL with an official, controlled repository.
  2. Pin the repository to an immutable, reviewed commit instead of cloning and executing the mutable default branch.
  3. Verify signed commits or release artifacts and publish expected cryptographic checksums.
  4. Include the actual implementation in the audited skill package where practical, so executable content is reviewed together with its instructions.
  5. Pin all direct and transitive Python dependencies to reviewed versions.
  6. Use a hash-locked dependency file and install with pip --require-hashes.
  7. Retrieve packages only from explicitly approved package indexes; disable unintended fallback indexes.
  8. Review package source and installation hooks before installation.
  9. Run installation and application scripts inside an isolated virtual environment or container using a non-privileged account.
  10. Grant setup_database.py only the minimum database permissions required for schema initialization; do not use administrative or superuser credentials.
  11. Prevent deployment scripts from receiving unrelated secrets through environment variables.
  12. Require a manual source review and integrity check before executing setup_database.py or main.py.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly processes student profiling data and historical performance, but the documentation provides no privacy warning, consent requirements, data minimization guidance, or retention/access controls. In an educational context, this can lead to unnecessary collection or misuse of student personal and performance data, creating compliance and privacy risks even if the functionality is otherwise legitimate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file presents the skill name, description, parameters, and usage entirely in Chinese, which can impose a language/locale constraint on users without any opt-in or stated regional justification. The policy for SQP-3 allows locale constraints only when choice is offered or the restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill allows scheduling and batch release of assignments to live classes, but does not warn that these actions can immediately affect real students, deadlines, and class operations. This increases the chance of accidental publication, misconfigured deadlines, or broad unintended release, causing operational disruption even without malicious intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.