Back to skill

Security audit

Cn Hash Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a local hash/Base64/HMAC utility with documentation and secret-handling caveats, but no evidence of hidden network access, persistence, or destructive behavior.

Before installing, verify the intended entry point because the README examples name a missing script. Avoid passing production HMAC keys with --hmac on the command line; use this for local/test data unless the tool is changed to read secrets from a safer prompt or stdin pattern. Expect some Chinese-only help and branding text.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cn_hash_generator.py:58
Finding

HMAC Secret Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/cn_hash_generator.py, lines 58 and 100-103
Vulnerability Type: Sensitive information exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

python
parser.add_argument('--hmac', metavar='KEY', help='HMAC密钥')
python
# HMAC模式
if args.hmac:
    result = hmac_sign(args.text, args.hmac, args.algo)
    if result:
        print(result.upper() if args.upper else result)
    return

Technical Analysis

The interface requires users to supply an HMAC signing key directly through the --hmac command-line option. Command-line arguments are not an appropriate transport for sensitive cryptographic material because they may be:

  • Recorded in the user's shell history.
  • Visible through operating-system process inspection while the command is running.
  • Captured by process-monitoring, audit, telemetry, or job-orchestration systems.
  • Included in debugging output, execution logs, or terminal session records.

The key is used locally and is not transmitted by the script. Nevertheless, its placement in the process argument vector unnecessarily exposes it beyond the cryptographic operation. This exceeds the minimum exposure necessary for the declared HMAC functionality.

The project does not access the network, elevate privileges, or persist the key. Exploitation therefore depends on an attacker or monitoring system having access to the user's command history, process metadata, or execution logs.

Attack Path

  1. A user invokes the utility with a sensitive key, for example:
    bash
    python3 scripts/cn_hash_generator.py "message" --hmac "production-secret"
    
  2. The shell records the complete command in its history, or the operating system exposes the argument vector while the process is running.
  3. A local attacker, administrator, monitoring agent, or other party with access to that history or ...[truncated 938 chars]
Remediation
View remediation

Remediation Suggestions

  • Accept HMAC keys through a non-echoing interactive prompt using Python's getpass.getpass().
  • Provide an option to read the key from standard input or a dedicated file descriptor so it does not appear in the process argument vector.
  • If file-based secret input is supported, require restrictive file permissions and avoid printing the key or including it in error messages.
  • Avoid environment variables for high-value long-lived secrets where possible, because environment data may also be exposed through process inspection or diagnostic systems.
  • Retain --hmac only for non-sensitive testing if backward compatibility is required, and emit a clear warning that command-line keys may be recorded or observed.
  • Update documentation with a safe invocation pattern, such as prompting securely for the key.
  • Ensure logs, exceptions, and diagnostic output never include the key.
  • Encourage key rotation if a production key has previously been supplied through the command-line interface.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill file includes mandatory Chinese-language branding and call-to-action text in the footer, while the rest of the document is in English. This introduces a language/locale constraint without user opt-in and without stating that the skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language strings such as the module docstring and CLI help text in Chinese only. Under the policy, forcing a specific language without opt-in can be a locale-policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.