Back to skill

Security audit

DaoReview

Security checks for vulnerabilities and agentic risk

Overview

This document-review skill is mostly coherent, but its file-reading instructions use shell command templates that could execute unintended commands if a document path is crafted maliciously.

Install only if you are comfortable with a skill that asks the agent to read documents through local shell tools. Use it on trusted filenames and documents, and prefer revising the skill to use safe file-reading APIs or argument-array execution before handling untrusted uploads.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:18
Finding

Shell Command Injection Through Unsafe File-Path Interpolation

Content
View full analysis
/dev/null || \ docx2txt "/path/to/file.docx" 2>/dev/null || \ unzip -p "/path/to/file.docx" word/document.xml | sed 's/<[^>]*>//g' # txt 文件 cat "/path/to/file.txt" # md 文件 cat "/path/to/file.md" ``` ### Technical Analysis The Skill instructs the agent to read user-selected documents by substituting their paths into shell command templates. Document paths are attacker-controlled input, but the templates do not provide a safe argument-passing or escaping mechanism. Wrapping a substituted path in double quotes is not sufficient when command text is assembled and then interpreted by a shell. Shell constructs embedded in the resulting command, including command substitution such as `$(...)` or backticks, may still execute. An embedded quotation mark can also terminate the intended quoted argument and introduce shell operators or additional commands. This risk affects all documented extraction paths: `pandoc`, `docx2txt`, `unzip`, and `cat`. The later instruction to quote paths containing spaces or non-ASCII characters does not prevent shell injection. ### Attack Path 1. An attacker supplies a document or document path containing shell syntax, such as command substitution or an embedded quote followed by a shell operator. 2. The agent replaces the placeholder path in one of the documented command templates with the attacker-controlled value. 3. The assembled command is passed to a shell for execution. 4. The shell evaluates the injected syntax while attempting to read or extract the document. 5. The injected command executes with the operating-system permissions of the agent process. Exploitation requires the agent or its command-execution tool to construct shell command text through direct path interpolation, as directed by the Skill. ...[truncated 744 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are very broad and match common user intents such as reviewing, checking, scoring, evaluating, or analyzing documents. This can cause unintended invocation over ordinary document-assistance requests, leading the skill to take over interactions unexpectedly and apply its own workflow instead of the user’s intended task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Mandating Chinese-only responses without checking user preference can override the user's requested language and reduce usability or accessibility. While not a direct code-execution risk, it is a policy and safety issue because it can cause unexpected behavior, miscommunication, and poor handling of multilingual or accessibility-sensitive contexts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.