Security checks for vulnerabilities and agentic risk
Overview
This is a local cocktail recipe lookup skill with minor quality and localization issues, but no hidden, destructive, persistent, or data-exfiltrating behavior found.
Install only if a Chinese-language cocktail lookup helper fits your workflow. Be aware that scene-based recommendations and the documented shortcut entrypoint appear incomplete, and unusual regex characters in searches may cause errors.
The search_drink and search_by_ingredient functions pass command-line input into AWK variables and use those variables as the right-hand operand of the ~ operator. AWK therefore interprets the supplied cocktail name or ingredient as an Extended Regular Expression rather than as literal search text.
Shell quoting and AWK's -v argument prevent this input from becoming shell syntax, so the flaw does not permit arbitrary shell-command execution. However, an attacker can supply malformed expressions, such as an unmatched [, to trigger an AWK parsing error and make the requested operation fail. More complex regular expressions may also consume excessive CPU while being evaluated against the bundled database.
Attack Path
An attacker invokes the script with a crafted search argument, for example:
bash
./scripts/query.sh search '['
or:
bash
./scripts/query.sh ingredient '['
main forwards the second command-line argument to search_drink or search_by_ingredient.
The function places the argument in the AWK variable drink or ing.
The AWK ~ operator compiles the attacker-controlled value as a regular expression.
A malformed expression causes AWK to terminate with an error. A sufficiently expensive expression may increase CPU use during database scanning.
Impact Assessment
Exploitation can disrupt the current search operation and may cause localized denial of service through
...[truncated 336 chars]
Remediation
View remediation
Remediation Suggestions
Use literal substring matching instead of AWK's regular-expression operator:
bash
result=$(awk -F',' -v drink="$query" '
NR == 1 { next }
index(tolower($1), tolower(drink)) > 0 { print $0 }
' "$DB_FILE" | head -20)
Apply the following additional hardening measures:
Reject unreasonably long search arguments before invoking AWK.
Check AWK's exit status and return a controlled error instead of continuing with incomplete results.
If regular-expression search is intentionally supported, validate patterns before use, impose input-length and execution-time limits, and clearly document that arguments are regular expressions.
Add regression tests covering malformed metacharacters such as [, (, \, *, and {.
The manifest description and all user-facing instructions are written entirely in Chinese, which indicates the skill is presented in a single language with no opt-in or alternative locale. Under the language/locale policy, this is a natural-language policy concern unless the skill explicitly offers a language choice or documents a justified region-specific constraint.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
This shell script's comments and all displayed help/output are in Chinese, which imposes a specific language on users without offering an alternative or documenting a justified locale restriction. The policy explicitly flags language or locale constraints unless the skill provides user choice or clearly states a justified regional scope.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding
This shell script's comments, prompts, usage text, and results are all presented in Chinese, including the main help output and error messages. Because the file provides no user opt-in, language selection, or documented region-specific justification, it violates the natural-language locale policy for skills that should not force a language unilaterally.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Low
Category
Not specified by scanner
Confidence
87% confidence
Finding
The README says the language is English for drink names and ingredients, which imposes a specific locale/language expectation in the skill description. Under the policy, fixed language constraints should either offer user choice or be clearly justified as region-specific; this line does not do so.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Low
Category
Not specified by scanner
Confidence
97% confidence
Finding
All user-facing strings in the script are in Chinese, including the title, prompts, and example utterances. This imposes a specific language/locale on users without any opt-in or documented justification, which matches the policy-violation category for language or locale constraints.
Content
No source excerpt is available for this finding.
Natural-Language Policy Violations
Low
Category
Not specified by scanner
Confidence
87% confidence
Finding
This manifest presents the skill description and command arguments entirely in Chinese, including user-facing invocation patterns such as "/cocktail [酒名]" and "/scene [场景描述]". Under the policy, forcing a specific language without opt-in or documented justification is a natural-language policy violation.