Back to skill

Security audit

Pro Zh Summary

Security checks for vulnerabilities and agentic risk

Overview

This Chinese summarization skill appears legitimate, but it should be reviewed because it auto-starts a hidden local server and has weaknesses that could expose documents or run the wrong local script.

Install only if you are comfortable with a background local ML server that reads full documents you provide. Avoid summarizing sensitive files until the backend authenticates its localhost API, launches server.py by an absolute trusted path, pins dependencies and model revisions, and provides clearer start/stop controls.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T07 · Tool Hijacking and Spoofing

Error
Location
main.py:13
Finding

Unauthenticated Local Backend Can Be Spoofed to Capture Input Documents

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
main.py:23
Finding

Relative Backend Script Path Allows Execution of an Unintended Python File

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Dependencies and Mutable Remote Model Artifacts Create Supply-Chain Risk

Content
View full analysis
=4.30.0 torch>=2.0.0 sentencepiece fastapi uvicorn requests ``` `server.py`: ```python MODEL_NAME = "heack/HeackMT5-ZhSum100k" ``` ```python tokenizer = T5Tokenizer.from_pretrained(MODEL_NAME) model = MT5ForConditionalGeneration.from_pretrained(MODEL_NAME) ``` ### Technical Analysis The Python dependencies are not locked to exact reviewed versions and do not have integrity hashes. Two dependencies use open-ended lower bounds, while the remaining dependencies have no version constraint. A future installation can therefore resolve to package versions that were not included in the audit. The tokenizer and model are also loaded from a remote namespace without specifying an immutable repository revision. The effective model artifacts can change after this source code has been reviewed. No evidence in the audited files shows that the current named packages or model are intentionally malicious. The vulnerability is the absence of reproducibility and integrity controls, which expands the trust boundary to future package releases, dependency resolution results, and mutable remote model contents. ### Attack Path A package-based exploitation path is: 1. An upstream package account, release process, index, or dependency is compromised. 2. A malicious or unsafe version is published while still satisfying the broad requirement. 3. A user performs a new installation or rebuild. 4. The package resolver installs the newly published version because no exact lock or hash rejects it. 5. Package installation or import-time code executes in the Skill environment with the user's privileges. A model-based exploitation or integrity path is: 1. The remote model repository or its publishing account is ...[truncated 990 chars]
Remediation
View remediation
" tokenizer = T5Tokenizer.from_pretrained( MODEL_NAME, revision=MODEL_REVISION, ) model = MT5ForConditionalGeneration.from_pretrained( MODEL_NAME, revision=MODEL_REVISION, use_safetensors=True, ) ``` 7. Verify downloaded model files against approved checksums and prefer safe serialization formats. 8. Cache reviewed artifacts in a controlled repository so production execution does not depend on mutable upstream content. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose is text summarization, but the implementation reportedly also starts a background server, probes localhost services, and reads local files as input. This is a strong behavior mismatch and is dangerous because it can conceal data collection, lateral interaction with local services, or covert execution paths unrelated to the user-requested task.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly states '仅支持中文文本处理' and presents the skill as '纯血中文专注', which is a natural-language locale restriction. Under the policy rules, forcing a specific language without user opt-in or a clearly documented policy/compliance justification is reportable.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill manifest declares no tool scope or permission boundaries even though the associated implementation reportedly has file read, network, and shell capabilities. For a summarization skill, undocumented access to these capabilities increases the risk of unauthorized local file access, command execution, or outbound communication without user awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill uses broad trigger phrases like '总结' and '摘要' and says it must be invoked, which can cause overbroad automatic activation during ordinary conversation. In the context of a skill with suspicious hidden capabilities, loose trigger scope makes accidental or coerced invocation more dangerous because it increases opportunities to run privileged code unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description states this is a professional Chinese summarization tool and says it must be invoked for certain requests involving Chinese text, but it does not mention any user opt-in or alternative language handling. This creates a natural-language locale constraint that may violate policy if the skill forces a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill's comments, status messages, and argument help text are presented in Chinese only, which can impose a language/locale requirement on users without opt-in. This matches the policy category for language or locale constraints that are not optional or justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest presents a summarization skill, but the code is primarily an HTTP client plus local server orchestrator. This discrepancy increases security risk because users may provide sensitive content under the assumption of a simple local text utility, while the code actually manages another process and transmits data to a service endpoint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A tool described as a text summarizer silently starts a background server process when it is not running, which is behaviorally broader than users would reasonably expect. This mismatch is dangerous because it can mask unauthorized code execution and makes trust decisions harder, especially when the spawned process is hidden and unaudited.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · main.py (reported line 15)May include surrounding context.

python
"""检查后端服务是否存活,如果死了就静默拉起它"""
    try:
        # 尝试 ping 一下服务,超时设为极短的 0.5 秒
        requests.get(f"{API_URL}/health", timeout=0.5)
        return True # 服务存活
    except requests.exceptions.ConnectionError:
        pass # 服务未启动

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · main.py (reported line 33)May include surrounding context.

python
"""检查后端服务是否存活,如果死了就静默拉起它"""
    try:
        # 尝试 ping 一下服务,超时设为极短的 0.5 秒
        requests.get(f"{API_URL}/health", timeout=0.5)
        return True # 服务存活
    except requests.exceptions.ConnectionError:
        pass # 服务未启动

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

The client silently spawns a background Python process to run server.py without explicit user consent or integrity checks. While the command arguments are not shell-injected, this still creates execution risk because whatever file is present as server.py in the working directory will be launched, and the hidden/background behavior reduces user visibility.

Content

Scanner excerpt · main.py (reported line 25)May include surrounding context.

python
# 以后台静默方式启动 server.py (跨平台支持)
    if sys.platform.startswith('win'):
        subprocess.Popen([sys.executable, "server.py"], creationflags=subprocess.CREATE_NO_WINDOW)
    else:
        subprocess.Popen([sys.executable, "server.py"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

On non-Windows systems, the skill launches server.py in the background with stdout and stderr redirected to DEVNULL, obscuring what the process does and any failures it encounters. This hidden execution is risky in a summarization tool because it expands behavior from text processing into covert local code execution and persistence-like backend management.

Content

Scanner excerpt · main.py (reported line 27)May include surrounding context.

python
if sys.platform.startswith('win'):
        subprocess.Popen([sys.executable, "server.py"], creationflags=subprocess.CREATE_NO_WINDOW)
    else:
        subprocess.Popen([sys.executable, "server.py"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)

    # 循环等待服务就绪,最多等 30 秒 (模型加载时间)
    for _ in range(30):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The program reads arbitrary local files and forwards their full contents to the backend service without any explicit warning at the point of use. In a summarization context, users may accidentally expose sensitive local data, and the hidden transmission path to another process increases the chance of unintended disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · main.py (reported line 74)May include surrounding context.

python
# 2. 极速发送请求并获取秒回结果
    try:
        response = requests.post(f"{API_URL}/summarize", json={"text": input_text, "length": args.length})
        response.raise_for_status()
        
        # print("\n=== 🎯 核心摘要 ===\n")

Tainted flow: 'input_text' from sys.stdin.read (line 62, user input) → requests.post (network output)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · main.py (reported line 74)May include surrounding context.

python
# 2. 极速发送请求并获取秒回结果
    try:
        response = requests.post(f"{API_URL}/summarize", json={"text": input_text, "length": args.length})
        response.raise_for_status()
        
        # print("\n=== 🎯 核心摘要 ===\n")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains user-facing status strings in Chinese only (for example at model load and readiness), with no indication that the skill is intentionally Chinese-only or that users can choose another language. This creates a natural-language locale policy issue because the skill imposes a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill launches a background server with limited disclosure, and on some platforms suppresses all output, reducing transparency around what code is running. Although this is not direct code injection, it is still unsafe operational behavior because it hides side effects from the user in a tool that appears to be a simple summarizer.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Using 'transformers>=4.30.0' permits any later version, including releases with new vulnerabilities or incompatible behavior, and does not guarantee a currently safe version. Given this skill's core function depends on ML model handling, dependency drift in transformers can materially affect parsing, deserialization, and model-loading attack surface.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
transformers>=4.30.0
torch>=2.0.0
sentencepiece
fastapi

Unverifiable Dependency: transformers has 16 known advisory(ies) (CVE-2023-2800 (transformers has Insecure Temporary File); CVE-2026-4372 (HuggingFace transformers vulnerable to remote code execution); CVE-2025-3933 (Transformers is vulnerable to ReDoS attack through its DonutProcessor class) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The manifest does not pin 'transformers', and that package has multiple known advisories, so the actual installed version could be affected without any visibility from this file alone. In a summarization skill built around transformer models, this is more concerning than a generic utility dependency because model processing and serialization paths are central to the application's functionality.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

Using 'torch>=2.0.0' leaves the runtime free to install any newer release, making builds non-reproducible and obscuring whether vulnerable versions are in use. Because PyTorch has historically had unsafe model-loading and native-code attack surface concerns, unconstrained upgrades are a meaningful supply-chain weakness.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
transformers>=4.30.0
torch>=2.0.0
sentencepiece
fastapi
uvicorn

Unverifiable Dependency: torch has 16 known advisory(ies) (CVE-2025-2953 (PyTorch susceptible to local Denial of Service); CVE-2022-45907 (PyTorch vulnerable to arbitrary code execution); CVE-2025-32434 (PyTorch: `torch.load` with `weights_only=True` leads to remote code execution) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The unpinned 'torch' dependency has known advisories, making it impossible to verify from this manifest whether a safe release is installed. This is especially important in an ML skill, since PyTorch often handles native extensions and model deserialization paths that can have severe consequences if a vulnerable version is deployed.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency 'sentencepiece' is unpinned, so installs may resolve to different versions over time, reducing build reproducibility and making it harder to ensure vulnerable releases are excluded. In a skill that processes long Chinese text with ML tooling, supply-chain integrity matters because parser/tokenizer libraries may be exposed to untrusted input and future compromised or vulnerable releases could be pulled in automatically.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
transformers>=4.30.0
torch>=2.0.0
sentencepiece
fastapi
uvicorn
requests

Unverifiable Dependency: sentencepiece has 2 known advisory(ies) (CVE-2026-1260 (Sentencepiece has a a heap overflow issue); CVE-2026-1260 (Sentencepiece has a a heap overflow issue)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Because 'sentencepiece' is unpinned and has known advisories, the deployed environment may unknowingly include an affected tokenizer build. Since this skill processes long Chinese text, the tokenizer is in the direct input path, which makes parser/memory-safety issues more relevant than they might be in an unrelated package.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The 'fastapi' package is unpinned, which allows non-deterministic installs and increases the risk of accidentally deploying a vulnerable or breaking release. Because this skill likely exposes an API surface for summarization, framework version drift can directly affect network-facing attack surface.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
transformers>=4.30.0
torch>=2.0.0
sentencepiece
fastapi
uvicorn
requests

Static analysis

No suspicious patterns detected.