Back to skill

Security audit

network-device-scanner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real local-network scanner, but its scan scope is hardcoded and can be broadened without clear user confirmation.

Install only if you are comfortable with a skill that actively probes network hosts. Before use, confirm the target network yourself, avoid shared or corporate networks without permission, and remove or constrain SCAN_EXTRA_IPS and the hardcoded 172.16.10.x assumptions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/scan.py:250
Finding

Network Scanning Targets Are Hardcoded and Not Restricted to the User's Local Network

Content
View full analysis
Optional[str]: try: subprocess.run(['ping', '-c', '1', '-W', '1', ip], capture_output=True, timeout=2) return ip except: return None with ThreadPoolExecutor(max_workers=20) as executor: futures = {executor.submit(ping_ip, f"172.16.10.{i}"): i for i in range(1, 255)} ``` From `scripts/scan.py:250-253`: ```python additional_ips = os.environ.get('SCAN_EXTRA_IPS', '172.16.10.234').split(',') for ip in additional_ips: if ip.strip(): known_ips.add(ip.strip()) ``` From `scripts/scan.cjs:35-43`: ```javascript const output = await execCommand('arp -a'); const pattern = /172\.16\.10\.(\d+)\s+([0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2})/gi; let match; while ((match = pattern.exec(output)) !== null) { const mac = match[2].toLowerCase(); ...[truncated 3062 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior says the skill scans the current LAN and returns a formatted Markdown table, but the underlying behavior reportedly scans a hard-coded subnet, may probe extra IPs from environment/default values, omits some active hosts, and performs additional fingerprinting. This mismatch is dangerous because users and reviewers cannot accurately predict the network scope or data collection, which can lead to unintended reconnaissance beyond what was consented to.

Content

No source excerpt is available for this finding.

Unvalidated Output Injection

High
Category
Output Handling
Confidence
90% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/scan.cjs (reported line 37)May include surrounding context.

js
const output = await execCommand('arp -a');
        const pattern = /172\.16\.10\.(\d+)\s+([0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2})/gi;
        let match;
        while ((match = pattern.exec(output)) !== null) {
            const mac = match[2].toLowerCase();
            if (mac !== 'ff-ff-ff-ff-ff-ff') {
                ips.add(`172.16.10.${match[1]}`);

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes Python and PowerShell scripts that perform network discovery and port scanning, yet the manifest does not declare any tool scope such as shell or file access. This reduces transparency and bypasses least-privilege expectations, making it easier for a user or host agent to trigger active network probing without clear consent boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to activate on ordinary discussion about networks, IPs, MAC addresses, or ports, increasing the chance that the assistant launches an active scan when the user only wanted information. In this context, accidental activation is significant because the skill performs real probing of other devices on the local network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description presents the scanner as a device discovery utility but does not clearly warn that it actively probes hosts and ports on the local network. Without an explicit warning, users may not realize the action could affect other devices, violate policy, or be interpreted as unauthorized reconnaissance in shared environments.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest and file header describe scanning active devices on the local network, which implies discovering devices across the current LAN. In practice, discovery is limited to parsing arp -a output with a regex hard-coded to 172.16.10.*, and the code later adds only one fixed extra IP, so many LAN devices outside that cached subnet would never be discovered.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs local network host enumeration and port probing, then collects MAC addresses and inferred device types, without any visible consent gate, warning, or scope confirmation. In an agent skill context, that can surprise users, probe third-party devices on the local network, and expose sensitive topology and device metadata.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest and module description present this as a LAN device scanner for the user's network, but the implementation fixes the target network to 172.16.10.0/24. The rest of the code reinforces this assumption by filtering ARP entries and sweep targets to that same subnet, so the actual behavior is much narrower than the claimed purpose.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/scan.py (reported line 22)May include surrounding context.

python
# 扫描端口列表
PORTS = [21, 22, 23, 53, 80, 135, 139, 443, 445, 554, 8000, 8080, 8443, 9000, 37777]
NETWORK = "172.16.10.0/24"
TIMEOUT = 0.3  # 端口扫描超时(秒)


@dataclass

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script invokes external commands such as arp, fping, nmap, and ping to interrogate the network, but the user-facing output only shows generic progress text and does not disclose that these tools will be run. For safety-critical subprocess operations, the guidance requires some clear disclosure, confirmation, or documented warning unless this behavior is explicitly part of the skill's stated purpose.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan.py (reported line 57)May include surrounding context.

python
# 方法2: 使用 arp 命令 (如果可用)
    try:
        result = subprocess.run(['arp', '-a'], capture_output=True, text=True, timeout=10)
        # 匹配 172.16.10.x 地址
        pattern = r'172\.16\.10\.(\d+)'
        for line in result.stdout.splitlines():

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This block performs active host discovery using fping, nmap, or repeated ping across an entire subnet without any built-in confirmation, authorization check, or meaningful user disclosure. In skill context, network scanning is the core function, which makes the behavior expected, but also raises the need for explicit consent because it can probe third-party devices on whatever network the agent host is attached to.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan.py (reported line 81)May include surrounding context.

python
# 方法1: 使用 fping (更高效)
    try:
        result = subprocess.run(
            ['fping', '-g', '172.16.10.0/24', '-a'],
            capture_output=True, text=True, timeout=30
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan.py (reported line 94)May include surrounding context.

python
# 方法2: 使用 nmap (如果可用)
    if not ips:
        try:
            result = subprocess.run(
                ['nmap', '-sn', '-PR', '172.16.10.0/24', '-oG', '-'],
                capture_output=True, text=True, timeout=60
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan.py (reported line 109)May include surrounding context.

python
print("Using basic ping sweep...", flush=True)
        def ping_ip(ip: str) -> Optional[str]:
            try:
                subprocess.run(['ping', '-c', '1', '-W', '1', ip], 
                             capture_output=True, timeout=2)
                return ip
            except:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan.py (reported line 142)May include surrounding context.

python
# 方法2: 使用 arp 命令
    try:
        result = subprocess.run(['arp', '-a', ip], capture_output=True, text=True, timeout=5)
        pattern = r'([0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2}-[0-9a-f]{2})'
        match = re.search(pattern, result.stdout, re.IGNORECASE)
        if match:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says the skill scans active devices and their open ports, which implies discovered active hosts should be returned even if no listed ports are open. However, the code only appends a device to results when open_ports is non-empty, so active hosts without those ports are silently excluded.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file's natural-language description and trigger phrases are entirely specified in Chinese, and no option is documented for other languages or locale selection. This can violate a language-choice policy when the skill implicitly requires a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language comments and device labels are written in Chinese, and the skill does not indicate that language is configurable or optional. This can violate a language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The inline documentation labels the first branch as 精确匹配, but macPrefixes entries are 3-byte vendor prefixes such as E4-68-A3, while macUpper is a full MAC address. As written, macPrefixes[macUpper] will almost never succeed for real full MAC addresses, so the behavior contradicts the stated intent of exact matching.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language docstring presents the skill description entirely in Chinese aside from the title fragment, and there is no indication that language is user-selectable or that the tool is intentionally restricted to a Chinese-speaking audience. This can violate language/locale policy when a specific language is imposed without opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Reading SCAN_EXTRA_IPS from the environment allows scan targets outside the discovered LAN scope to be injected without any user-facing justification or validation. In an agent/runtime environment where environment variables may be set by deployment, wrappers, or other components, this can silently broaden reconnaissance to arbitrary internal addresses and violate least surprise and network-access boundaries.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/scan.cjs:18