Back to skill

Security audit

Cn Math Calculator

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese-language math calculator skill with a bounded purpose and no evidence of hidden access, persistence, or exfiltration.

Consider this suitable for local math use, especially for Chinese-language users. Do not expose it directly to untrusted public input without expression length, numeric-size, and execution-time limits.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/math_calculator.py:128
Finding

Unbounded Exponentiation Allows Resource-Exhaustion Denial of Service

Content
View full analysis

Vulnerability Details

File Location: scripts/math_calculator.py, lines 128-133 and 151-159
Vulnerability Type: Uncontrolled resource consumption through unrestricted exponentiation
Risk Level: Medium

The evaluator exposes both the exponentiation operator and the built-in pow function to untrusted mathematical expressions without limiting exponent size, operand size, expression length, AST depth, execution time, or memory consumption.

Relevant operator mapping:

python
SAFE_OPERATORS = {
    ast.Add: operator.add,
    ast.Sub: operator.sub,
    ast.Mult: operator.mul,
    ast.Div: operator.truediv,
    ast.Mod: operator.mod,
    ast.Pow: operator.pow,
}

Relevant function mapping:

python
SAFE_FUNCTIONS = {
    'sin': math.sin,
    'cos': math.cos,
    'tan': math.tan,
    'asin': math.asin,
    'acos': math.acos,
    'atan': math.atan,
    'sinh': math.sinh,
    'cosh': math.cosh,
    'tanh': math.tanh,
    'log': math.log10,
    'ln': math.log,
    'log2': math.log2,
    'sqrt': math.sqrt,
    'abs': abs,
    'floor': math.floor,
    'ceil': math.ceil,
    'round': round,
    'exp': math.exp,
    'pow': pow,
}

Vulnerable binary-operation execution:

python
elif isinstance(node, ast.BinOp):
    left = self._visit(node.left)
    right = self._visit(node.right)
    op_type = type(node.op)
    if op_type in SAFE_OPERATORS:
        return SAFE_OPERATORS[op_type](left, right)
    raise ValueError(f"Unsupported operator: {op_type.__name__}")

Vulnerable function-call execution:

python
elif isinstance(node, ast.Call):
    # Only allow predefined functions
    if isinstance(node.func, ast.Name):
        func_name = node.func.id.lower()
        if func_name in self.functions:
            args = [self._visit(arg) for arg in node.args]
            return self.functions[func_name](*args)
        raise ValueError
...[truncated 2429 chars]
Remediation
View remediation

Remediation Suggestions

  1. Enforce a strict maximum input length before parsing the expression.
  2. Traverse the AST before evaluation and reject trees exceeding configured node-count or nesting-depth limits.
  3. Add a dedicated exponentiation handler instead of mapping ast.Pow directly to operator.pow.
  4. Reject exponents whose absolute value exceeds a conservative threshold appropriate for the calculator's intended use.
  5. Reject integer operands and intermediate results exceeding a configured bit-length limit.
  6. Remove the built-in pow function from SAFE_FUNCTIONS, or wrap it with the same operand and exponent checks.
  7. Apply bounds to other potentially expensive functions and operations, including nested expressions.
  8. Run calculations in a separate worker process with operating-system or container-level CPU, memory, and wall-clock limits. Terminate the worker when a deadline is exceeded.
  9. Return a controlled validation error when an expression exceeds any complexity or numeric-size limit.
  10. Add regression tests for oversized exponents, nested powers, excessive AST depth, and excessive input length.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill name, description, headings, and usage documentation are written entirely in Chinese, which imposes a specific language on users. The file does not offer an alternative language, opt-in, or explanation that this is a region-specific skill, so it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing descriptions are written only in Chinese, and the CLI emits Chinese-only prompts/errors/results. The policy explicitly flags language or locale constraints when the skill forces a specific language without offering user choice or documenting a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/math_calculator.py:4