Back to skill

Security audit

Cn Regex Tester

Security checks for vulnerabilities and agentic risk

Overview

This is a small regex testing skill whose behavior matches its stated purpose, with a limited availability risk from running user-provided regexes without a timeout.

Reasonable to install for local regex testing. Avoid running very large inputs or untrusted complex patterns in shared or long-running environments unless the caller adds process timeouts, input limits, or isolation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/regex_tester.py:4
Finding

Regular Expression Denial of Service Through Unbounded User-Controlled Patterns

Content
View full analysis

Vulnerability Details

File Location: scripts/regex_tester.py, lines 4–10
Vulnerability Type: Regular Expression Denial of Service (ReDoS)
Risk Level: Medium

Vulnerable Code

python
def test_regex(pattern, text, mode='match'):
    try:
        if mode == 'match':
            matches = re.findall(pattern, text)
            return {'matches': matches, 'count': len(matches)}
        elif mode == 'replace':
            result = re.sub(pattern, '', text)
            return {'result': result}

Technical Analysis

The function passes a user-controlled regular expression and user-controlled input text directly to Python's backtracking re engine. Neither re.findall() nor re.sub() is subject to an execution timeout, input-length limit, memory limit, or pattern-complexity restriction.

An attacker can therefore submit a pattern containing nested or ambiguous quantifiers and pair it with a long, near-matching string. For certain patterns, the engine explores an exponentially growing number of matching states before concluding that no match exists. The exception handler does not mitigate this issue because excessive backtracking does not normally raise an exception; it occupies the executing process until evaluation completes or the process is terminated externally.

Attack Path

  1. The attacker invokes the Skill with an expensive pattern, such as (a+)+$.
  2. The attacker supplies a sufficiently long near-matching input, such as a sequence of a characters followed by X.
  3. The CLI forwards both values to test_regex().
  4. re.findall() attempts the match and performs catastrophic backtracking after encountering the final nonmatching character.
  5. The worker consumes excessive CPU and may remain unavailable for an extended period. The same underlying issue applies to re.sub() if replacement mode is exposed programmatically.

Impact Assessment

Successful exploitation does ...[truncated 518 chars]

Remediation
View remediation

Remediation Suggestions

  • Evaluate untrusted regular expressions in an isolated subprocess with a strict wall-clock timeout. Terminate the subprocess if the deadline is exceeded.
  • Apply operating-system CPU and memory limits to the isolated worker so one expression cannot exhaust host resources.
  • Enforce conservative maximum lengths for both the pattern and input text before attempting evaluation.
  • Reject or restrict patterns containing constructs associated with catastrophic backtracking, such as nested quantifiers. Treat static pattern checks only as defense in depth because they cannot reliably identify every expensive expression.
  • Where compatibility permits, replace Python's backtracking engine with a linear-time regular-expression engine suitable for untrusted patterns.
  • Add rate limiting and concurrency limits at the calling boundary.
  • Return a generic timeout or complexity error rather than allowing the request to occupy a worker indefinitely.
  • Add regression tests using adversarial patterns and near-matching inputs to verify that execution is terminated within the configured resource budget.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.