Back to skill

Security audit

至简网格端&云应用开发工厂

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Mesh app development skill, but it ships deployable official example services with serious authorization flaws that users should review before real use.

Install only if you trust the publisher and are prepared to review or patch the bundled example services before deploying them. Pay special attention to bios/rootkey and ihr payroll configs, and avoid exposing these services to real users or networks until authorization and formula-execution risks are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
examples/ihr/api/config.cfg:143
Finding

Ordinary authenticated users can persist JavaScript executed by the salary scheduler

Content
View full analysis

Vulnerability Details

File Location: examples/ihr/api/config.cfg:143-175; execution sink at examples/ihr/api/salary.cfg:102,173-211
Vulnerability Type: Stored server-side JavaScript injection caused by missing role-based authorization
Risk Level: High

Vulnerable Code

The update endpoint requires authentication but omits the RBAC and administrative-feature checks used by the adjacent zone-management endpoints:

json
{
    "name" : "updateZone",
    "method" : "PUT",
    "property" : "private",
    "tokenChecker" : "USER",

    "request": [
        {"name":"id", "type":"int", "must":true, "min":0},
        {"name":"subsidy", "type":"float", "must":true, "min":0},
        {"name":"salary", "type":"float", "must":true, "min":0},
        {"name":"timeOff", "type":"int", "must":true, "min":-720, "max":720},
        {"name":"fowSalary", "type":"float", "must":true, "min":0},
        {"name":"oowSalary", "type":"float", "must":true, "min":0},
        {"name":"wowSalary", "type":"float", "must":true, "min":0},
        {"name":"name", "type":"string", "must":true, "min":1, "max":100},
        {"name":"taxFunc", "type":"string", "must":true, "min":0, "max":500},
        {"name":"cmt", "type":"string", "must":true, "min":0, "max":500}
    ],

    "process" : [
        {
            "name" : "update_zone_info",
            "type" : "rdb",
            "db":"hr",
            "sqls" : [
                "update zone set
                    name='@{name}',
                    subsidy=@{subsidy},
                    salary=@{salary},
                    timeOff=@{timeOff},
                    fowSalary=@{fowSalary},
                    oowSalary=@{oowSalary},
                    wowSalary=@{wowSalary},
                    taxFunc='@{taxFunc}',
                    cmt='@{cmt}'
                  where id=@{id}"
            ]
        }
    ]
}

The persisted val ...[truncated 3108 chars]

Remediation
View remediation

Remediation Suggestions

  1. Apply the same authorization controls used by the other zone administration endpoints:

    json
    "property": "private",
    "tokenChecker": "USER",
    "aclChecker": "RBAC",
    "feature": "admin"
    
  2. Do not represent tax formulas as arbitrary JavaScript. Replace taxFunc with structured tax brackets or a constrained expression language supporting only approved arithmetic and comparisons.

  3. If programmable formulas are unavoidable:

    • Parse the formula into an AST and allowlist permitted operators, variables, and return statements.
    • Reject property access, loops, function creation, global identifiers, and runtime API references.
    • Execute formulas in a capability-free sandbox with strict CPU, memory, and time limits.
    • Never expose DB, Mesh, filesystem, process, or network capabilities to the formula.
  4. Validate authorization before writing the configuration, not only before displaying its administrative UI.

  5. Record the authenticated account, old formula, new formula, timestamp, and zone ID in an immutable audit log.

  6. Review existing zone.taxFunc values for unexpected code and replace any untrusted formulas before running the salary scheduler.

  7. Add regression tests proving that an ordinary USER token receives an authorization error from updateZone.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
examples/bios/api/rootkey.cfg:22
Finding

Unauthenticated public endpoint exposes a root-key decryption oracle

Content
View full analysis

Vulnerability Details

File Location: examples/bios/api/rootkey.cfg:22-35
Vulnerability Type: Missing authentication on a privileged cryptographic operation
Risk Level: High

Vulnerable Code

json
{
    "name": "decode",
    "property" : "public",
    "method": "POST",

    "request": [
        {"name":"cipher", "type":"string", "must":true}
    ],

    "process" : [
        {
            "name" : "decode",
            "type" : "java",
            "handler":"cn.net.zhijian.mesh.builtin.bios.rootkey.Decode"
        }
    ]
}

The same file also exposes the corresponding encryption operation without authentication:

json
{
    "name": "encode",
    "property" : "public",
    "method": "POST",

    "request": [
        {"name":"plain", "type":"string", "must":true}
    ],

    "process" : [
        {
            "name" : "encode",
            "type" : "java",
            "handler":"cn.net.zhijian.mesh.builtin.bios.rootkey.Encode"
        }
    ]
}

Technical Analysis

The decode endpoint is explicitly marked public and has no tokenChecker, caller identity check, tenant binding, or purpose restriction. It accepts caller-controlled ciphertext and invokes the privileged cn.net.zhijian.mesh.builtin.bios.rootkey.Decode handler.

Consequently, possession of the root key is replaced by network access to the endpoint: any unauthenticated caller can ask the BIOS service to perform decryption and return the result. The companion public encode endpoint additionally exposes a chosen-plaintext encryption oracle using the same root-key subsystem.

This is not merely public-key retrieval. The endpoint performs decryption and returns plaintext, an operation that must remain restricted to trusted service identities. The adjacent BIOS endpoints demonstrate that sensitive operations normally use private properties and token checkers such as OMPWD, `M ...[truncated 1957 chars]

Remediation
View remediation

Remediation Suggestions

  1. Change both cryptographic endpoints from public to private.
  2. Require a narrowly scoped service identity rather than a general user token. Restrict access to an explicit allowlist of internal callers that require the operation.
  3. Prefer removing the generic network-accessible decryption endpoint entirely. Perform decryption inside the trusted component that owns the protected record.
  4. Bind every cryptographic operation to:
    • An authenticated tenant or company.
    • An approved calling service.
    • A specific data purpose.
    • A record identifier or key namespace.
  5. Do not return unrestricted plaintext from a generic root-key API. Return only the minimum derived result needed by the authorized workflow.
  6. Add rate limits, request-size limits, replay controls, and security audit logging for all privileged cryptographic operations.
  7. Review logs and deployed configurations for historical unauthenticated calls to these endpoints.
  8. Rotate affected keys and re-encrypt protected records if unauthorized oracle use cannot be ruled out.
  9. Add tests proving that anonymous requests and unauthorized service tokens are rejected.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (521)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 2027)May include surrounding context.

md
![serviceauth](imgs/server/service_auth.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 2070)May include surrounding context.

md
![userauth](imgs/server/user_auth.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 2425)May include surrounding context.

md
![workflowset](imgs/server/workflowset.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 2429)May include surrounding context.

md
![customerworkflow](imgs/server/customer_workflow.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3157)May include surrounding context.

md
![userauth](imgs/client/user_auth.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3257)May include surrounding context.

md
![member1](imgs/client/member1.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3259)May include surrounding context.

md
![member2](imgs/client/member2.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3263)May include surrounding context.

md
![member3](imgs/client/member3.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3271)May include surrounding context.

md
![classhour1](imgs/client/classhour1.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3275)May include surrounding context.

md
![classhour2](imgs/client/classhour2.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3279)May include surrounding context.

md
![classhour3](imgs/client/classhour3.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3283)May include surrounding context.

md
![classhour4](imgs/client/classhour4.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3367)May include surrounding context.

md
![aclient_install1](imgs/client/androidclient_install1.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3371)May include surrounding context.

md
![aclient_install2](imgs/client/androidclient_install2.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3387)May include surrounding context.

md
![personalreg1](imgs/client/personal_reg1.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3391)May include surrounding context.

md
![personalreg2](imgs/client/personal_reg2.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3399)May include surrounding context.

md
![comlogin1](imgs/client/company_login1.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3405)May include surrounding context.

md
![comlogin2](imgs/client/company_login2.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3409)May include surrounding context.

md
![comlogin3](imgs/client/company_login3.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3417)May include surrounding context.

md
![comlogin4](imgs/client/company_login4.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3421)May include surrounding context.

md
![comlogin5](imgs/client/company_login5.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3425)May include surrounding context.

md
![comlogin6](imgs/client/company_login6.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3438)May include surrounding context.

md
![mktlist](imgs/client/market_list.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3878)May include surrounding context.

md
![mktlist](imgs/client/market_list.png)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3444)May include surrounding context.

md
![mktappdtl](imgs/client/market_appdtl.png)

Static analysis

No suspicious patterns detected.