Back to skill

Security audit

英语打卡(每日学习 每日练)

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed English-study check-in wrapper, but it can execute any local Python file supplied as its dependency path without integrity checks.

Install only if you trust the separate learning-checkin script and can control the exact path being executed. Do not set LEARNING_CHECKIN_PATH or --learning-checkin-path to files from untrusted locations, and prefer a pinned, verified dependency before using this skill for routine check-ins.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
english_checkin.py:68
Finding

Unpinned and Unverified External Python Dependency Is Executed

Content
View full analysis

Vulnerability Details

File Location: english_checkin.py:68-75, 95-105, 115-159; SKILL.md:27-31
Vulnerability Type: Unverified third-party dependency execution
Risk Level: Medium

Vulnerable Code

The dependency path can be supplied through an environment variable or command-line argument, with existence being the only validation:

python
def parse_global_args():
    """Parse global arguments."""
    global _LEARNING_CHECKIN_PATH
    
    # Prefer the environment variable
    env_path = os.environ.get("LEARNING_CHECKIN_PATH")
    if env_path:
        script_path = Path(env_path)
        if script_path.exists():
            _LEARNING_CHECKIN_PATH = script_path
            return
    
    # Read from the command-line argument
    new_argv = []
    i = 1
    while i < len(sys.argv):
        arg = sys.argv[i]
        if arg == "--learning-checkin-path" and i + 1 < len(sys.argv):
            script_path = Path(sys.argv[i + 1])
            if script_path.exists():
                _LEARNING_CHECKIN_PATH = script_path
            i += 2
        else:
            new_argv.append(arg)
            i += 1

The selected file is subsequently executed as Python code:

python
def init_learning_checkin():
    """Initialize learning-checkin."""
    script_path = get_learning_checkin_script()
    if not script_path or not script_path.exists():
        return None, "learning-checkin is not installed"
    
    try:
        result = subprocess.run(
            [sys.executable, str(script_path), "init"],
            capture_output=True,
            text=True,
            encoding='utf-8',
            timeout=30
        )
python
def run_learning_checkin_command(command):
    """Run a learning-checkin command."""
    script_path = get_learning_checkin_script()
    if not script_path or not script_path.exists():
        return None, "
...[truncated 3183 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to a specific, audited, immutable release rather than directing users to an unversioned external artifact.
  2. Publish an expected SHA-256 digest or a verifiable digital signature and validate it before every execution. Fail closed when verification cannot be completed.
  3. Resolve the configured path with Path.resolve() and enforce an allowlisted dependency directory. Reject paths outside that directory.
  4. Require the target to be a regular file and, where supported, reject symbolic links, unsafe ownership, and files writable by untrusted users.
  5. Prefer importing a versioned package through a locked dependency mechanism with hash verification, such as a lockfile and hash-pinned installation.
  6. Execute the dependency with least privilege in a restricted environment. Remove unnecessary environment variables and limit filesystem and network access where platform controls permit.
  7. Display the resolved dependency path, validated version, and digest in the check command so users can confirm exactly which artifact will execute.
  8. Document a trusted installation and update process, including how releases are authenticated and how compromised versions are revoked.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill intentionally supports selecting and executing another Python script from an environment variable or command-line flag. That is a substantial expansion of capability unrelated to English study tracking and creates an execution trampoline for arbitrary code. The mismatch between stated purpose and actual capability makes the behavior especially suspicious.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code repeatedly spawns subprocesses to invoke another script's commands, effectively turning the skill into a launcher for external code. That broadens the attack surface, inherits all risks of the external script, and enables abuse when the target path is untrusted. For this skill's simple purpose, the capability is not justified by functional need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This Python file contains natural-language strings and comments presenting the skill as a Chinese-language experience, including the title line '每日英语学习打卡工具'. The skill does not offer a language/locale option or explain why Chinese is required, which can violate language-choice policy for general-purpose skills.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

This code executes an external Python script via subprocess. Although it avoids shell injection by passing an argument list, it still grants code execution to whatever file is selected as script_path, and that path can originate from an environment variable or CLI input. For a simple English check-in skill, delegating execution to an arbitrary external script is unnecessary and materially increases risk.

Content

Scanner excerpt · english_checkin.py (reported line 125)May include surrounding context.

python
return None, "learning-checkin 未安装,请先安装 learning-checkin skill"
    
    try:
        result = subprocess.run(
            [sys.executable, str(script_path), "init"],
            capture_output=True,
            text=True,

Tainted flow: 'script_path' from os.environ.get (line 79, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
99% confidence
Finding

There is a direct tainted flow from LEARNING_CHECKIN_PATH / --learning-checkin-path into subprocess execution. An attacker who can influence the environment or invocation arguments can point the skill at any existing Python file, which will then be executed with the user's interpreter. That is a straightforward arbitrary code execution path.

Content

Scanner excerpt · english_checkin.py (reported line 125)May include surrounding context.

python
return None, "learning-checkin 未安装,请先安装 learning-checkin skill"
    
    try:
        result = subprocess.run(
            [sys.executable, str(script_path), "init"],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
97% confidence
Finding

This subprocess call runs a command against an external Python script selected earlier. The immediate command value is constrained by internal callers, but the larger issue is that the invoked code is arbitrary if script_path is attacker-controlled, resulting in local code execution under the current user context. In the context of a learning tracker, this capability is unjustified and dangerous.

Content

Scanner excerpt · english_checkin.py (reported line 150)May include surrounding context.

python
return None, "learning-checkin 未安装"
    
    try:
        result = subprocess.run(
            [sys.executable, str(script_path), command],
            capture_output=True,
            text=True,

Tainted flow: 'script_path' from os.environ.get (line 79, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
99% confidence
Finding

This is the same tainted execution path in the generic command runner: attacker-influenced script_path reaches subprocess.run. Even though command is not attacker-controlled here, the script itself is, so the protection is insufficient. Executing an arbitrary local Python script can lead to full compromise of local data accessible to the process.

Content

Scanner excerpt · english_checkin.py (reported line 150)May include surrounding context.

python
return None, "learning-checkin 未安装"
    
    try:
        result = subprocess.run(
            [sys.executable, str(script_path), command],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description is written in Chinese and presents the usage instructions in that language for an English-learning workflow, without stating that users may choose another language or locale. This can conflict with language/locale policy requirements when a skill implicitly forces one language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.