Back to skill

Security audit

Cn Slug Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward local Chinese URL-slug generator with one optional dependency hygiene note, not evidence of hidden or harmful behavior.

Install only if you want a Chinese-focused local slug generator. For Pinyin mode, install `pypinyin` in a virtual environment and preferably pin the package version; avoid running pip with administrator privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:65
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:65
Vulnerability Type: Unpinned and unverifiable third-party dependency
Risk Level: Medium

Complete vulnerable snippet:

markdown
- pypinyin (pip install pypinyin) - Only required for Pinyin mode

The dependency is subsequently imported by scripts/cn_slug_generator.py:101-110:

python
def pinyin_slug(text, separator='-'):
    """Convert text to a Pinyin slug."""
    try:
        import pypinyin
        text = re.sub(r'[^\w\s\u4e00-\u9fff]', ' ', text)
        py = pypinyin.lazy_pinyin(text)
        words = [w for w in py if w.strip()]
        return separator.join(words)
    except ImportError:
        return text

Technical Analysis

The installation instruction uses pip install pypinyin without a pinned version, integrity hashes, lockfile, or an explicitly trusted package index. Consequently, the exact code installed depends on package-index state at installation time rather than on a version reviewed with this project.

Python packages may execute package-controlled build or installation logic during installation. They also execute top-level module code when imported. If the package distribution, a maintainer account, the configured package index, or the dependency resolution path is compromised, attacker-controlled code could execute when the user installs the dependency or invokes Pinyin mode.

This is a supply-chain weakness rather than evidence that the current pypinyin package is malicious.

Attack Path

  1. An attacker compromises a future pypinyin release, its package-index publishing account, or a package index configured in the victim's environment.
  2. A user follows the documented pip install pypinyin instruction.
  3. Because no version or hash is specified, pip resolves and downloads the attacker-controlled distribution.
  4. Malicious code executes during package build or i ...[truncated 776 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin pypinyin to a reviewed, exact version rather than installing the latest available release:

    text
    pypinyin==REVIEWED_VERSION
    
  2. Record cryptographic hashes in a requirements file and install with hash enforcement:

    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Generate and commit a lockfile using a dependency-management tool so direct and transitive dependency versions are reproducible.

  4. Explicitly use a trusted package index and prevent unintended fallback to untrusted or organization-controlled indexes.

  5. Review dependency updates before changing the pinned version, including package provenance, release history, and transitive dependencies.

  6. Install and run the dependency in an isolated virtual environment under a non-privileged account. Do not invoke pip with root or administrator privileges.

  7. Consider removing the optional dependency by using a reviewed in-project implementation if the additional supply-chain exposure is not justified.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill name, description, usage notes, and examples are written entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to Chinese-speaking users. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code file contains natural-language descriptions entirely in Chinese, including the module docstring and later CLI help strings. Under the policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.