T07 · Tool Hijacking and Spoofing
- Location
main.py:13- Finding
Unauthenticated Local Backend Can Be Spoofed to Capture Input Documents
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Chinese summarization skill appears legitimate, but it should be reviewed because it auto-starts a hidden local server and has weaknesses that could expose documents or run the wrong local script.
Install only if you are comfortable with a background local ML server that reads full documents you provide. Avoid summarizing sensitive files until the backend authenticates its localhost API, launches server.py by an absolute trusted path, pins dependencies and model revisions, and provides clearer start/stop controls.
main.py:13Unauthenticated Local Backend Can Be Spoofed to Capture Input Documents
main.py:23Relative Backend Script Path Allows Execution of an Unintended Python File
requirements.txt:1Unpinned Dependencies and Mutable Remote Model Artifacts Create Supply-Chain Risk
The declared purpose is text summarization, but the implementation reportedly also starts a background server, probes localhost services, and reads local files as input. This is a strong behavior mismatch and is dangerous because it can conceal data collection, lateral interaction with local services, or covert execution paths unrelated to the user-requested task.
Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.
The README explicitly states '仅支持中文文本处理' and presents the skill as '纯血中文专注', which is a natural-language locale restriction. Under the policy rules, forcing a specific language without user opt-in or a clearly documented policy/compliance justification is reportable.
The skill manifest declares no tool scope or permission boundaries even though the associated implementation reportedly has file read, network, and shell capabilities. For a summarization skill, undocumented access to these capabilities increases the risk of unauthorized local file access, command execution, or outbound communication without user awareness.
The skill uses broad trigger phrases like '总结' and '摘要' and says it must be invoked, which can cause overbroad automatic activation during ordinary conversation. In the context of a skill with suspicious hidden capabilities, loose trigger scope makes accidental or coerced invocation more dangerous because it increases opportunities to run privileged code unexpectedly.
The description states this is a professional Chinese summarization tool and says it must be invoked for certain requests involving Chinese text, but it does not mention any user opt-in or alternative language handling. This creates a natural-language locale constraint that may violate policy if the skill forces a specific language by default.
The skill's comments, status messages, and argument help text are presented in Chinese only, which can impose a language/locale requirement on users without opt-in. This matches the policy category for language or locale constraints that are not optional or justified.
The manifest presents a summarization skill, but the code is primarily an HTTP client plus local server orchestrator. This discrepancy increases security risk because users may provide sensitive content under the assumption of a simple local text utility, while the code actually manages another process and transmits data to a service endpoint.
A tool described as a text summarizer silently starts a background server process when it is not running, which is behaviorally broader than users would reasonably expect. This mismatch is dangerous because it can mask unauthorized code execution and makes trust decisions harder, especially when the spawned process is hidden and unaudited.
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
"""检查后端服务是否存活,如果死了就静默拉起它"""
try:
# 尝试 ping 一下服务,超时设为极短的 0.5 秒
requests.get(f"{API_URL}/health", timeout=0.5)
return True # 服务存活
except requests.exceptions.ConnectionError:
pass # 服务未启动
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
"""检查后端服务是否存活,如果死了就静默拉起它"""
try:
# 尝试 ping 一下服务,超时设为极短的 0.5 秒
requests.get(f"{API_URL}/health", timeout=0.5)
return True # 服务存活
except requests.exceptions.ConnectionError:
pass # 服务未启动
The client silently spawns a background Python process to run server.py without explicit user consent or integrity checks. While the command arguments are not shell-injected, this still creates execution risk because whatever file is present as server.py in the working directory will be launched, and the hidden/background behavior reduces user visibility.
# 以后台静默方式启动 server.py (跨平台支持)
if sys.platform.startswith('win'):
subprocess.Popen([sys.executable, "server.py"], creationflags=subprocess.CREATE_NO_WINDOW)
else:
subprocess.Popen([sys.executable, "server.py"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
On non-Windows systems, the skill launches server.py in the background with stdout and stderr redirected to DEVNULL, obscuring what the process does and any failures it encounters. This hidden execution is risky in a summarization tool because it expands behavior from text processing into covert local code execution and persistence-like backend management.
if sys.platform.startswith('win'):
subprocess.Popen([sys.executable, "server.py"], creationflags=subprocess.CREATE_NO_WINDOW)
else:
subprocess.Popen([sys.executable, "server.py"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
# 循环等待服务就绪,最多等 30 秒 (模型加载时间)
for _ in range(30):
The program reads arbitrary local files and forwards their full contents to the backend service without any explicit warning at the point of use. In a summarization context, users may accidentally expose sensitive local data, and the hidden transmission path to another process increases the chance of unintended disclosure.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 2. 极速发送请求并获取秒回结果
try:
response = requests.post(f"{API_URL}/summarize", json={"text": input_text, "length": args.length})
response.raise_for_status()
# print("\n=== 🎯 核心摘要 ===\n")
Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.
# 2. 极速发送请求并获取秒回结果
try:
response = requests.post(f"{API_URL}/summarize", json={"text": input_text, "length": args.length})
response.raise_for_status()
# print("\n=== 🎯 核心摘要 ===\n")
The file contains user-facing status strings in Chinese only (for example at model load and readiness), with no indication that the skill is intentionally Chinese-only or that users can choose another language. This creates a natural-language locale policy issue because the skill imposes a specific language without opt-in or documented justification.
The skill launches a background server with limited disclosure, and on some platforms suppresses all output, reducing transparency around what code is running. Although this is not direct code injection, it is still unsafe operational behavior because it hides side effects from the user in a tool that appears to be a simple summarizer.
Using 'transformers>=4.30.0' permits any later version, including releases with new vulnerabilities or incompatible behavior, and does not guarantee a currently safe version. Given this skill's core function depends on ML model handling, dependency drift in transformers can materially affect parsing, deserialization, and model-loading attack surface.
transformers>=4.30.0
torch>=2.0.0
sentencepiece
fastapi
The manifest does not pin 'transformers', and that package has multiple known advisories, so the actual installed version could be affected without any visibility from this file alone. In a summarization skill built around transformer models, this is more concerning than a generic utility dependency because model processing and serialization paths are central to the application's functionality.
Using 'torch>=2.0.0' leaves the runtime free to install any newer release, making builds non-reproducible and obscuring whether vulnerable versions are in use. Because PyTorch has historically had unsafe model-loading and native-code attack surface concerns, unconstrained upgrades are a meaningful supply-chain weakness.
transformers>=4.30.0
torch>=2.0.0
sentencepiece
fastapi
uvicorn
The unpinned 'torch' dependency has known advisories, making it impossible to verify from this manifest whether a safe release is installed. This is especially important in an ML skill, since PyTorch often handles native extensions and model deserialization paths that can have severe consequences if a vulnerable version is deployed.
The dependency 'sentencepiece' is unpinned, so installs may resolve to different versions over time, reducing build reproducibility and making it harder to ensure vulnerable releases are excluded. In a skill that processes long Chinese text with ML tooling, supply-chain integrity matters because parser/tokenizer libraries may be exposed to untrusted input and future compromised or vulnerable releases could be pulled in automatically.
transformers>=4.30.0
torch>=2.0.0
sentencepiece
fastapi
uvicorn
requests
Because 'sentencepiece' is unpinned and has known advisories, the deployed environment may unknowingly include an affected tokenizer build. Since this skill processes long Chinese text, the tokenizer is in the direct input path, which makes parser/memory-safety issues more relevant than they might be in an unrelated package.
The 'fastapi' package is unpinned, which allows non-deterministic installs and increases the risk of accidentally deploying a vulnerable or breaking release. Because this skill likely exposes an API surface for summarization, framework version drift can directly affect network-facing attack surface.
transformers>=4.30.0
torch>=2.0.0
sentencepiece
fastapi
uvicorn
requests
No suspicious patterns detected.