T09 · Insecure Skill Coding Practices
- Location
assess.sh:170- Finding
Assessment Results Are Discarded and Replaced with Fabricated Scores
- Content
View full analysis
"$report_file" << EOF # 技能评估报告:$skill_name ## 评估摘要 - **评估时间**:$(date '+%Y-%m-%d %H:%M:%S') - **评估方式**:静态分析(选项1 - 轻量) - **技能路径**:$skill_path ## 评估结果 > 报告生成中,需要完善评估模块... ## 下一步 1. 实现各个评估模块 (doc_checker.sh, code_analyzer.sh 等) 2. 完善报告模板 3. 添加评分计算逻辑 EOF log_success "报告已生成: $report_file" # 显示摘要 show_summary "$skill_name" "$report_file" } show_summary() { local skill_name="$1" local report_file="$2" echo "" echo -e "${CYAN}🔍 技能评估报告:$skill_name${NC}" echo -e "${BLUE}📊 综合评分:★★★★☆ (4.2/5)${NC}" echo -e "${BLUE}⏱️ 评估用时:$(($SECONDS))秒${NC}" echo -e "${BLUE}📁 技能路径:$skill_path${NC}" echo "" echo -e "${YELLOW}维度得分:${NC}" echo -e " 文档完整性:★★★★☆ (4.0/5)" echo -e " 代码规范性:★★★★★ (4.5/5)" echo -e " 配置友好度:★★★☆☆ (3.5/5)" echo -e " 维护活跃度:★★★★☆ (4.0/5)" echo "" echo -e "${YELLOW}⚠️ 发现问题:3个${NC}" echo -e "${GREEN}✅ 通过检查:21个${NC}" echo -e "${BLUE}📋 详细报告:$report_file${NC}" echo "" } ``` ### Technical Analysis The four evaluator scripts write their findings to temporary JSON files, and those file paths are passed into `generate_report`. Although the function stores the paths in `result_files`, it never reads, validates, aggregates, or reports their contents. Instead, the generated report contains a placeholder, while the terminal summa ...[truncated 1462 chars]- Remediation
View remediation
/dev/null; then log_error "Invalid evaluator output: $result_file" return 1 fi done ``` 2. Calculate the overall score from actual evaluator scores and configured weights. 3. Populate the report with the real issues and suggestions from each evaluator. 4. Remove all hard-coded scores, star ratings, issue counts, and pass counts. 5. Fail closed if an evaluator terminates unexpectedly, emits invalid JSON, or does not run. 6. Add automated tests using both safe and intentionally vulnerable fixture Skills. Verify that different inputs produce corresponding scores and findings. 7. Clearly distinguish incomplete assessments from successful assessments; never show a favorable score when aggregation has failed. ]]>
