Back to skill

Security audit

Authorship Credit Gen

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a simple CRediT statement formatter, but it overstates its ability to make fair authorship decisions and resolve disputes.

Review this skill carefully before installing. It is best treated as a basic CRediT contribution statement formatter, not as an authority for deciding author order, resolving disputes, or making ICMJE-compliant fairness judgments. Use explicit output paths, avoid feeding untrusted author metadata into XML output, and require human review for any authorship-credit decision.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:231
Finding

XML Injection Through Unescaped Author Metadata

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py, lines 231–233
Vulnerability Type: XML injection caused by missing output encoding
Risk Level: Medium

Vulnerable Code

python
lines.append(f'    <name>{author.name}</name>')
if author.affiliation:
    lines.append(f'    <aff>{author.affiliation}</aff>')

Technical Analysis

The XML generator interpolates the user-controlled author.name and author.affiliation values directly into XML markup. It does not escape XML metacharacters such as &, <, >, ", or '.

These values may originate from an input JSON file supplied with --input, from the --authors command-line option, or from interactive input. A malicious value can therefore terminate the intended element and inject additional XML elements or attributes into the generated document.

For example, a crafted author name conceptually equivalent to:

text
Alice</name><injected>attacker-controlled content</injected><name>

would alter the structure of the generated XML rather than being represented as literal author text. Even ordinary names or affiliations containing & or < can produce malformed XML.

Attack Path

  1. An attacker prepares an input JSON document containing XML markup in an author's name or affiliation.
  2. A user or automated workflow invokes the tool with that file and requests XML output, for example:
    bash
    python scripts/main.py --input attacker-controlled.json --format xml --output contribution.xml
    
  3. generate_xml() inserts the malicious value directly into the document.
  4. The resulting file contains attacker-controlled XML structure or becomes malformed.
  5. A downstream journal submission, metadata, or document-processing system consumes the compromised XML.

Impact Assessment

The vulnerability allows modification of the generated docume ...[truncated 512 chars]

Remediation
View remediation

Remediation Suggestions

Construct the output with a standard XML API such as xml.etree.ElementTree rather than assembling markup through string interpolation. XML libraries automatically encode text nodes correctly when serializing the document.

Example hardening approach:

python
import xml.etree.ElementTree as ET

root = ET.Element("contrib-group")

for author in self.contribution.authors:
    contrib = ET.SubElement(root, "contrib", {"contrib-type": "author"})
    ET.SubElement(contrib, "name").text = author.name

    if author.affiliation:
        ET.SubElement(contrib, "aff").text = author.affiliation

output = ET.tostring(root, encoding="unicode", xml_declaration=False)

If manual generation is unavoidable, apply xml.sax.saxutils.escape() to every user-controlled text value before interpolation. Also validate input types and reasonable length limits, and add regression tests covering ampersands, angle brackets, quotes, closing tags, and nested-element payloads.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill’s declared purpose promises fair, guideline-based authorship determination and dispute resolution, but the content only shows illustrative API calls and user-supplied role mappings, with no evidence of implemented ICMJE logic or objective fairness controls. In a research-credit context, this can mislead users into relying on unsupported recommendations, producing unfair authorship decisions and silent file operations inconsistent with user expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The config sets a fixed language value of "zh", which is a natural-language locale constraint. Because the file provides no indication that this language selection is optional, user-selectable, or justified as region-specific, it may violate the policy against forcing a specific language without opt-in.

Content

No source excerpt is available for this finding.

Tainted flow: 'filename' from input (line 349, user input) → open (file write)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/main.py (reported line 350)May include surrounding context.

python
save = input("\nSave to file? (y/n): ")
    if save.lower() == 'y':
        filename = input("Filename: ")
        with open(filename, 'w', encoding='utf-8') as f:
            f.write(output)
        print(f"Saved to: {filename}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI restricts --language to ['en'], and the help text presents English as the only allowed output language. Under the policy, forcing a specific language without offering a user choice or documenting a justified locale limitation is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The summary phrase "Use when working with authorship credit gen" is overly broad and underspecified, which can cause the skill to activate in contexts beyond its intended scope. Overbroad activation text increases the chance of inappropriate routing, unnecessary exposure of potentially sensitive collaboration data, or misuse in adjacent tasks like dispute handling without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill advertises export functionality that can create or modify local files, but it does not warn users about those side effects or describe where files will be written. While not inherently malicious, undisclosed file-writing behavior can surprise users, overwrite artifacts, or be misused in environments where tool permissions include local filesystem access.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
dataclasses

Static analysis

No suspicious patterns detected.