Back to skill

Security audit

Shipping Cost Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This skill generates local shipping-cost analysis reports and does not show hidden access, persistence, network use, or destructive behavior.

Installers should treat generated reports as advisory and keep carrier, packaging, and policy changes human-approved. Be cautious when rendering reports from untrusted third-party input because the input snapshot can contain markdown that may look like report content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
handler.py:187
Finding

Untrusted Input Allows Markdown Report Injection

Content
View full analysis
str: if inputs is None: return "" if isinstance(inputs, str): return inputs.strip() if isinstance(inputs, dict): parts: List[str] = [] for key, value in inputs.items(): if value in (None, "", [], {}, ()): # type: ignore[comparison-overlap] continue if isinstance(value, (list, tuple, set)): rendered = ", ".join(str(item) for item in value) else: rendered = str(value) parts.append(f"{key}: {rendered}") return " | ".join(parts) if isinstance(inputs, (list, tuple, set)): return " | ".join(str(item) for item in inputs) try: return json.dumps(inputs, ensure_ascii=False, sort_keys=True) except TypeError: return str(inputs) ``` The resulting text is inserted into the Markdown report without escaping: ```python lines.append(f"**Input snapshot:** {self.text or 'No structured logistics brief was provided, so this report uses default ecommerce fulfillment assumptions.'}") ``` ### Technical Analysis The `handle()` entry point accepts untrusted input and passes it to `ShippingCostOptimizer`. `_normalize_inputs()` preserves embedded line breaks and Markdown control syntax in strings, dictionary keys, dictionary values, and collection elements. The normalized value is then interpolated directly into a Markdown document. An attacker can therefore inject headings, links, images, tables, blockquotes, or fabricated report sections. Because the injected content appears inside a generated optimization report, users or downstream agents may mistake attacker-controlled statements for trusted recommendations. This issue does not provide operating-system c ...[truncated 1811 chars]
Remediation
View remediation
str: value = value.replace("\r", " ").replace("\n", " ") for char in ("\\", "`", "*", "_", "{", "}", "[", "]", "<", ">", "#", "|"): value = value.replace(char, "\\" + char) return value snapshot = _escape_markdown_inline( self.text or "No structured logistics brief was provided, so this report uses default ecommerce fulfillment assumptions." ) lines.append(f"**Input snapshot:** {snapshot}") ``` Escaping order and renderer behavior should be verified with tests. For stronger isolation, represent user input as structured data rather than concatenating it into trusted Markdown prose. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The trigger section uses open-ended conditions like 'when the user wants to' and example prompts such as 'Review packaging and carrier options for our store' and 'Should we raise the free-shipping threshold?'. These are plausible everyday business-analysis requests and the file does not provide exclusion conditions or negative examples to clarify when this skill should not be invoked instead of a more general analysis skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.