T08 · Insecure Dependencies
- Location
analyze.py:11- Finding
Import-Time Arbitrary Code Execution Through an Untrusted External Module Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears intended for retail target tracking, but it loads unreviewed Python code from a hard-coded local path before running.
Review before installing. The main concern is that the skill imports executable code from a hard-coded local directory outside the package, so you cannot tell from this artifact alone what code will run. Only install after replacing that dependency with a packaged, reviewed client or otherwise verifying and controlling the exact api_client module path.
analyze.py:11Import-Time Arbitrary Code Execution Through an Untrusted External Module Path
analyze.py:143API Query-Parameter Injection Through Unencoded Caller-Controlled Values
整体上,这段代码的意图与声明高度相关:它加载门店日目标、按日/周/月汇总目标、调用 BI 接口获取实际业绩、计算达成率与风险等级,并提供单店/批量告警检查,基本属于所述的‘门店目标追踪分析工具’。但从审计角度看,存在实质性描述-行为偏差。最重要的是实现错误:analyze_period() 的返回值使用了未定义变量,analyze() 对 analyze_period() 的参数传递也错位,这意味着主要功能按现状并不能可靠工作。其次,描述将预警状态概括为“黄绿黄灯”,而实现是五档风险;同时代码还包含未声明的多层级(区域/省/市/集团)业绩查询能力。最后,T-N 延迟并非整个分析链路的通用配置,而是仅在告警检查中体现。因此应判定为存在 mismatch,主要原因是主能力实现与声明之间存在可用性和范围上的实质不一致。
The code prepends an absolute external workspace path to sys.path and imports api_client from there, bypassing normal dependency boundaries. This can load unintended or tampered code from a user-specific filesystem location, creating a code-integrity and supply-chain risk with the privileges of the skill runtime.
The entire skill description is written in Chinese and provides no indication that users may interact in other languages or choose a preferred locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the regional constraint is explicitly documented and justified.
The skill includes explicit file paths and usage patterns that imply local file reading, but it does not declare any tool scope or allowed-tools boundary. In an agent environment, undeclared file access increases the chance of over-broad data exposure, accidental access to unrelated local files, and unclear enforcement of least privilege.
The trigger phrases are broad enough to activate on ordinary business-performance questions, which can cause the skill to run in contexts the user did not clearly intend. In agent systems, over-broad routing can expose local data sources unnecessarily or produce actions based on the wrong skill, increasing the risk of inappropriate data access and misleading outputs.
The skill metadata describes store target tracking, but the implementation can query city, province, region, and group-level BI data. This is a scope-expansion issue: a caller expecting store-only analytics could unintentionally expose broader organizational data if the skill is invoked with different level values.
The skill constructs an API endpoint and sends it via get_copilot_data, which transmits store and date-scope information over the network. In this file there is no confirmation prompt, user-facing disclosure, or comment/docstring warning that remote data access will occur when the analysis runs.
Natural-language policy requires avoiding forced language or locale constraints unless the user opts in or the restriction is clearly justified. Here, the skill metadata and trigger descriptions are presented solely in Chinese, and the document does not indicate that the skill is region-specific or provide an alternative language option.
This code file contains natural-language documentation entirely in Chinese and presents the skill description and example usage in that locale without indicating any user language choice. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.
The module-level natural-language description specifies the skill entirely in Chinese, which can amount to a forced language/locale choice without user opt-in. No alternate language option or justification for a Chinese-only audience is provided in the file.
No suspicious patterns detected.