Back to skill

Security audit

魔杖选择你

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Chinese wand-quiz skill that runs local scripts to generate quiz results and optional local artwork, with no evidence of hidden persistence, exfiltration, or destructive behavior.

Install this if you want a Chinese-language local wand quiz and are comfortable with it running Python scripts and creating local HTML/PNG outputs. Review the generated files before sharing results, since quiz cards include a reproducible answer string/tree identity intended for comparison with friends.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

描述强调的是面向用户的交互式人格/魔杖测验功能,包括启动测试、逐题记录、提前结束自动补答、生成魔杖卡、以及与朋友比对结果。所给代码却完全没有任何与魔杖判定、答题会话管理、结果生成、用户输入处理或双人比较有关的逻辑。相反,它是一个离线数据预处理脚本:基于固定种子生成多套题目/选项乱序的“试卷”,并对 papers.json 做结构校验。这不是描述中的支撑性小细节,而是明显不同的主要用途,因此属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

描述的核心能力是面向终端用户的互动测评技能,而代码的核心功能是离线生成魔杖艺术图。代码通过命令行参数接收已确定的 wood/core/len/flex/seed,读取本地 data/woods.json、cores.json、meta.json,绘制视觉卡片并保存到文件。它没有任何会话式问答、触发词处理、提前结束补答、结果判定、好友比较或杖码机制。因此主用途与声明明显不符。虽然描述中提到“一键出卡”,图像生成可能是整个技能系统中的一个支持组件,但就这段代码本身而言,它并不实现声明中的主要功能,而是一个配套的素材生成脚本,所以应判定为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
无 canvas 环境回退 `assets/wand_hero.png` 静态图;结果页还可用「换个样式看」随时互换。

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/wand_shop.py (reported line 342)May include surrounding context.

python
cond = rule["when"]
        ok = all(env.get(k.strip(), False) for k in cond.split("AND"))
        if ok:
            return rule, env
    return None, env

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill instructs the agent to read local files, write files, and invoke shell commands, but it declares no explicit tool scope or permission boundaries. In an agent environment, undeclared capabilities increase the chance of overbroad execution, accidental access to unrelated local data, or misuse of shell/file operations beyond the user-facing wand quiz purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are broad, common-language prompts like '选魔杖' or '进店逛逛', which can overlap with ordinary conversation and cause unintended triggering. In a skill that can execute local scripts and read/write files, accidental invocation expands risk because tool-using behavior may start without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The text-mode activation conditions remain ambiguous and permit activation from loosely phrased natural-language inputs. Because the skill's fallback path can lead to command execution and data processing, ambiguous activation makes unintended tool use more likely and weakens consent and predictability controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON file contains user-facing natural-language strings exclusively in Chinese across names, origins, verses, and companion text. Under the language/locale policy rule, forcing a specific language without opt-in or documented justification can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest-like JSON contains all user-facing strings in Chinese, including the opening, prompts, and result text, but does not indicate that the skill is Chinese-only or provide any user opt-in for language selection. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated document declares lang="zh-CN", and the surrounding UI strings throughout the template and module docstring are Chinese-only. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_quiz_html.py (reported line 998)May include surrounding context.

python
tdp = Path(td)
        (tdp / "cases.json").write_text(json.dumps(cases, ensure_ascii=False), encoding="utf-8")
        (tdp / "driver.js").write_text(driver, encoding="utf-8")
        proc = subprocess.run(
            [node, str(tdp / "driver.js"), str(tdp / "cases.json"), str(tdp / "got.json")],
            capture_output=True, timeout=120)
        if proc.returncode != 0:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script includes its primary docstring and runtime status/error messages in Chinese, which effectively forces a specific language for users interacting with the skill. The policy allows locale-specific behavior only when it is explicitly justified or when users are given a language choice, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON file contains all end-user question text and option text in Chinese, and there is no natural-language indication that the skill offers users a language choice or that it is intentionally restricted to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON contains user-facing natural-language strings exclusively in Chinese across names, descriptions, and profile text. Under the language/locale policy rule, forcing a specific language without opt-in or justification can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The module docstring and all user-facing command descriptions are written only in Chinese, and later user prompts/errors also assume Chinese-only interaction. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

L14 的模块说明写明“只做四件事:解析 → 计分 → 查表 → 渲染”,给人的意图是该引擎仅限于核心出卡流程。但代码实际还实现了 --list-papers、--scores、--random、--audit、--selftest 等额外能力,并在入口处对外暴露。这属于文档对代码行为的主动性缩窄,与实际实现不一致。

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/build_quiz_html.py:927