Back to skill

Security audit

IDX CMA Report

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but its generated interactive report can run code hidden in listing data if opened or shared.

Review or patch the generated HTML handling before using this skill with untrusted IDX/comparable data or publishing the interactive report. Treat generated CMA files as containing private property/client information, and only upload cma_data.json or reports to Google tools when the user expects that sharing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/build_cma.py:150
Finding

Stored Cross-Site Scripting in Generated Interactive CMA Report

Content
View full analysis
``` The generated page then embeds the serialized payload directly inside an executable script and inserts untrusted comparable-property fields with `innerHTML`: ```javascript
Remediation
View remediation
... ``` Then parse its text: ```javascript const data = JSON.parse(document.getElementById("cma-data").textContent); ``` 3. **Escape HTML-significant characters before embedding JSON.** At minimum, replace `<`, `>`, and `&` with their Unicode escape forms. Escaping U+2028 and U+2029 is also advisable: ```python payload_json = json.dumps(payload, separators=(",", ":")) payload_json = ( payload_json .replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` This measure should complement, not replace, removal of unsafe `innerHTML` usage. 4. **Apply a restrictive Content Security Policy when hosting reports.** Avoid inline scripts where possible and use a policy that disallows inline event handlers and unauthorized network destinations. 5. **Add automated regression tests** that generate and inspect reports containing payloads such as: ```text "> ``` Tests should verify that these values are rende ...[truncated 94 chars]
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to read reference files and invoke a local Python script that writes multiple output artifacts, but the manifest declares no explicit tool scope or allowed-tools restrictions. Without an explicit permission boundary, an agent/runtime may grant broader file read/write capability than intended, increasing the risk of unintended access to local files or filesystem modification if the skill is misused or if adjacent prompt injection influences execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated client-side code formats monetary values using the fixed locale "en-US" and currency "USD", which imposes a specific language/locale convention regardless of user preference. The file does not provide an opt-in, configuration option, or justification that this skill is strictly US-region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code writes markdown, JSON, HTML, and prompt files derived from the provided subject and comps data, which may include addresses and other user-supplied property details. The script does print a completion message after writing, but there is no pre-write warning, confirmation, or explanatory comment/docstring disclosing that these files will be created and persist on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.