T07 · Tool Hijacking and Spoofing
- Location
scripts/run.py:12- Finding
Untrusted External Module Execution via Hard-Coded Import Path
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a crypto content-planning helper, but it loads unreviewed code from a hard-coded local workspace path and overstates publishing support involving session cookies.
Review this skill carefully before installing. Do not provide social-platform cookies unless you are comfortable treating them as account credentials, and do not run scripts/run.py unless the external workspace import path is removed or you have verified the module it will load. The package should be corrected to include its scanner modules locally and clearly separate planned publishing from implemented scan/planning features.
scripts/run.py:12Untrusted External Module Execution via Hard-Coded Import Path
The documented purpose overstates the level of automation and external platform integration compared with what is actually described in the skill file. In a crypto-content context, overstated capabilities increase the chance that users will trust the skill with credentials or rely on it for actions affecting public accounts without adequate transparency.
The documented purpose overstates the level of automation and external platform integration compared with what is actually described in the skill file. In a crypto-content context, overstated capabilities increase the chance that users will trust the skill with credentials or rely on it for actions affecting public accounts without adequate transparency.
The README presents the skill description entirely in Chinese and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
The skill advertises scripts that read and write local files but does not declare any explicit tool scope or permissions boundary. This can lead to overbroad execution in agent environments, where the skill may gain filesystem access beyond what users reasonably expect.
The skill promotes one-click publishing to external social platforms without clearly warning that posts may affect real user accounts. In an agent setting, omission of this warning can cause accidental or unauthorized publication, reputational harm, and loss of account control expectations.
The skill instructs users to configure platform cookies for publishing but does not warn that cookies are sensitive session credentials that can enable account takeover if exposed. Because the target platforms are real external services, mishandling these cookies could let an attacker post, impersonate the user, or access account data.
The file’s natural-language description and user-facing help are written in Chinese, indicating the skill is designed to operate in a specific language. Under the policy, language constraints should either be optional for the user or clearly documented as justified; this file provides neither.
The command help shown to users is exclusively in Chinese, which constitutes a language/locale restriction in natural-language content. The file does not offer an alternative language, prompt for preference, or explain a region-specific reason for this limitation.
This Python file contains user-facing docstrings and CLI output entirely in Chinese, including the title, status messages, and command help text. Because the skill does not offer language selection or explain that it is intentionally region-specific, it creates a natural-language locale policy issue for users who may expect language neutrality or opt-in.
The manifest description is entirely in Chinese and presents the skill as a Chinese-language social media automation workflow, with no indication that users can choose another language or locale. This creates a natural-language policy concern because it implicitly fixes the skill to a specific language context without documented opt-in or region-specific justification.
This markdown file documents that running the skill produces report and planning files in the logs directory, but it does not explicitly warn the user that executing the workflow will create or overwrite local files. For markdown files, user-facing descriptions should disclose behaviors that affect user data or the local system, even when the effect is modest.
The skill description uses Chinese-language instructions and does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when a specific language is imposed without opt-in or justification.
No suspicious patterns detected.