Back to skill

Security audit

Cn Chinese Converter

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Chinese simplified/traditional text conversion skill with a disclosed external dependency and no hidden persistence or data access.

Install only if you are comfortable adding the OpenCC Python dependency. For stronger supply-chain hygiene, install it in a dedicated virtual environment and pin a reviewed version instead of using an unconstrained pip install.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/chinese_converter.py:12
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/chinese_converter.py:12-17; additionally documented in SKILL.md:19
Vulnerability Type: Unpinned package installation from a mutable package index
Risk Level: Medium

Vulnerable Code

python
try:
    from opencc import OpenCC
    return OpenCC
except ImportError:
    print("Error: the opencc library is not installed")
    print("Run: pip install opencc-python-reimplemented")

The installation command communicated by the script is:

shell
pip install opencc-python-reimplemented

SKILL.md:19 also declares opencc-python-reimplemented as an external dependency without specifying a version or integrity hash.

Technical Analysis

The project instructs users to install opencc-python-reimplemented from the configured Python package index without pinning a reviewed version or verifying an artifact hash. Package-index content is mutable: a later release, compromised publisher account, compromised index, or maliciously configured mirror could supply code different from what was reviewed during this audit.

Python package installation may execute package-controlled build backend logic. The installed package is subsequently imported as opencc, causing its runtime initialization code to execute whenever conversion is requested. There is no evidence that the currently published dependency is malicious; the confirmed issue is the absence of version and integrity controls around executable third-party code.

Attack Path

  1. An attacker compromises the dependency publisher, package index, or package mirror, or causes a malicious future release to be selected.
  2. A user follows the displayed pip install opencc-python-reimplemented instruction.
  3. pip resolves the latest acceptable release because no exact version or hash is required.
  4. Malicious build logic may execute during installation.
  5. Malicious runtime logic may also exec ...[truncated 766 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the dependency to an explicitly reviewed version, for example through a locked requirements file:
    text
    opencc-python-reimplemented==REVIEWED_VERSION
    
  2. Record and enforce trusted artifact hashes with pip --require-hashes.
  3. Generate and commit a reproducible lock file containing all transitive dependency versions and hashes.
  4. Update both SKILL.md and the runtime error message to reference the locked installation procedure rather than an unconstrained pip install command.
  5. Recommend installation inside a dedicated virtual environment under a non-administrative account.
  6. Review dependency updates before changing the pinned version, including package provenance, release history, ownership changes, and artifact integrity.
  7. Where feasible, use an internally controlled package mirror containing only reviewed artifacts.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill metadata and user-facing instructions are entirely in Chinese, with no indication that users can choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file's natural-language interface and help text are entirely in Chinese, including the module description, error messages, and CLI argument help. Under the policy rule, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.