Back to skill

Security audit

3d Filament Tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and local-only, but it can turn screenshot-derived order text into executable HTML without required escaping or validation.

Review this skill before installing if you may process screenshots from other people or untrusted sellers. It should require HTML escaping, strict data-id validation, safe DOM construction instead of innerHTML/inline onclick, and a privacy warning for order screenshots. For trusted personal screenshots, its file, localStorage, and JSON behaviors are otherwise aligned with the inventory-tracker purpose.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
templates/template.html:375
Finding

Unescaped Screenshot-Derived Data Can Produce Executable HTML

Content
View full analysis
` must have a unique `data-id`. ``` The template demonstrates direct insertion of inventory values into HTML elements and attributes: ```html PLA Example Brand PLA Basic Black Bulk 1 ``` The `data-id` value is subsequently interpolated into markup and inline JavaScript through `innerHTML`: ```javascript const cell = tr.querySelector('.use-cell'); cell.innerHTML = `
In use − ${r.using}/${total} +
Consumed
Remediation
View remediation
``` ...[truncated 514 chars]
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · templates/template.html (reported line 451)May include surrounding context.

html
function resetState() {
  if (!confirm('清除所有「在用 / 已用」选择记忆?')) return;
  localStorage.removeItem(STORAGE_KEY);
  Object.keys(state).forEach(k => delete state[k]);
  document.querySelectorAll('tr[data-id]').forEach(renderRow);
  recomputeAggregates();
  updateTotals();

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · templates/template.html (reported line 475)May include surrounding context.

html
function resetState() {
  if (!confirm('清除所有「在用 / 已用」选择记忆?')) return;
  localStorage.removeItem(STORAGE_KEY);
  Object.keys(state).forEach(k => delete state[k]);
  document.querySelectorAll('tr[data-id]').forEach(renderRow);
  recomputeAggregates();
  updateTotals();

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire natural-language documentation is presented in Chinese, and there is no indication that this skill is intentionally limited to Chinese-speaking users or that alternative language support is available. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says the skill triggers when users '丢一堆订单截图说「帮我看看买了哪些料」', where the quoted phrase is generic everyday speech rather than a narrowly scoped invocation. Because the activation condition depends on loosely defined screenshots plus a broad phrase, it may overlap with ordinary conversation and cause unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is described as a local, single-file HTML inventory tracker using localStorage and JSON export/import, yet it instructs operators to publish it to public GitHub and ClawHub. That expands distribution beyond the stated need, increasing the risk of unintentionally exposing embedded sample data, screenshots, file paths, or implementation details, and creates an unnecessary supply-chain/disclosure surface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN", which hard-codes a specific language/locale for the skill UI. The file does not indicate that this locale is optional, user-selected, or required for a region-specific use case, so it appears to violate the language/locale policy constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The markdown explains that users can give order screenshots to Claude for automatic extraction of material, brand, color, and quantity data, but it does not include any privacy or data-sensitivity warning. Since screenshots can contain personal or order information, the skill description should disclose that the images' contents will be analyzed before use.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The trigger section lists positive examples but does not explain when the skill should not activate, especially for broad phrases like 'filament tracker' or questions about remaining PLA. Without negative examples or scope boundaries, the activation behavior remains somewhat ambiguous.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.