Back to skill

Security audit

POI 详情页问题排查编排器

Security checks for vulnerabilities and agentic risk

Overview

This POI debugging skill has a coherent purpose, but it can query sensitive internal logs, replay captured requests, and run a shell script with unsafe input handling and shared temporary-file storage.

Install only in an authorized internal environment and treat GSIDs, trace IDs, logged URLs, response bodies, and reports as sensitive. Before routine use, tighten triggers, add confirmation before log queries and request replay, validate inputs, avoid plaintext HTTP where possible, and store outputs in a private directory with cleanup instead of shared /tmp.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/poi-debug.sh:329
Finding

Arbitrary Python Code Execution Through an Unquoted Heredoc

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/poi-debug.sh:82
Finding

Log Query and JSON Injection Through Unvalidated Arguments

Content
View full analysis
&1) ``` ### Technical Analysis `GSID`, `PAGE_INDEX`, `SOURCE_ID`, and `TIME_RANGE` are derived from command-line arguments and are not constrained to expected formats. They are concatenated directly into the Loghouse query language and then inserted into a JSON document through string interpolation. This creates two related injection surfaces: 1. Query-language operators supplied in an argument can alter the meaning or scope of the Loghouse search. 2. Quotes, backslashes, or JSON delimiters can break the generated JSON or introduce unintended fields if accepted by the downstream CLI parser. This is not ordinary shell command injection because shell metacharacters introduced through variable expansion are not reparsed as shell syntax. The security boundary being crossed is the Loghouse query parser and the JSON request parser. ### Attack Path 1. An attacker supplies a crafted GSID, module, page index, or time-range argument. 2. The script inserts the value directly into `LOG_QUERY`. 3. The attacker-provided query operators broaden, negate, or otherwise modify the intended search expression. 4. The resulting query is submitted using the authenticated user's Loghouse access. 5. Matching internal log records are returned and subsequently proce ...[truncated 755 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/poi-debug.sh:165
Finding

Sensitive Logged Requests Are Replayed Over Plaintext HTTP

Content
View full analysis
/dev/null ``` ### Technical Analysis The script extracts a complete request URL from internal logs and replays its path and query parameters to a fixed destination using unencrypted HTTP. Logged request URLs may contain GSIDs, POI identifiers, trace information, experiment identifiers, or session-related parameters. Because HTTP provides neither transport confidentiality nor server authenticity, any party capable of observing or modifying the network path may read these parameters or alter the returned response. The script also suppresses curl error output and does not check the HTTP status code, making interception or server-side errors harder to detect. ### Attack Path 1. The script retrieves a request URL and its query parameters from Loghouse. 2. It replaces the logged internal IP with an HTTP hostname. 3. The complete path and query string are transmitted without TLS. 4. A network-positioned attacker observes or modifies the request. 5. The attacker captures sensitive identifiers or substitutes a manipulated response. 6. The script parses the manipulated response and may produce an incorrect diagnostic report. ### Impact Assessment A network observer may obtain sensitive request metadata and business identifiers. An active attacker may tamper with responses and cause: - Disclosure of GSIDs, POI IDs, trace IDs, or other query parameters. - Exposure of internal request structure. - False diagnostic finding ...[truncated 293 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/poi-debug.sh:176
Finding

Predictable Shared Temporary File Enables Data Exposure and Symlink Attacks

Content
View full analysis
/dev/null ``` The script later creates another fixed shared location without setting restrictive permissions: ```bash RESULT_DIR="/tmp/poi-debug-results" mkdir -p "$RESULT_DIR" TIMESTAMP=$(date +%Y%m%d_%H%M%S) RESULT_FILE="$RESULT_DIR/poi_debug_${GSID: -8}_${TIMESTAMP}.json" ``` ### Technical Analysis The raw response filename is derived from only the final eight characters of the GSID and is therefore predictable. It is created under the globally shared `/tmp` directory without `mktemp`, exclusive creation, ownership checks, a restrictive `umask`, or symlink protection. A local attacker can pre-create the expected path as a symbolic link. When curl opens the output path, it may follow that link and overwrite a file writable by the victim. A local user may also read the response if the process umask permits group or world access. The result directory is similarly predictable and is created without verifying that it is a genuine directory owned by the current user. Raw response and report files are not automatically removed. ### Attack Path 1. A local attacker predicts the response filename from a known or observed GSID suffix. 2. Before the Skill runs, the attacker creates that path as a symbolic link to another file writable by the victim, or prepares a malicious shared result-directory path. 3. The victim runs the Skill. 4. Curl follows the attacker-controlled link when writing the response. 5. The target file is overwritten, or the attacker reads or modifies the diagnostic response. 6. The Skill may parse attacker-controlled content and generate false findings. A passive local attacker may instead monitor `/tmp` and read newly created response or report fil ...[truncated 565 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/faq.md (reported line 210)May include surrounding context.

ppend('累积流量为 0,可能数据异常')

text

### Q13: 如何输出为 Markdown 报告?

```bash
# 添加导出选项
./poi-debug.sh <gsid> <poiid> --format markdown > report.md

故障排查

Q14: 脚本执行报错 "command not found"

原因: aone-kit 或 sf 不在 PATH 中

解决:

bash
export PATH="/app/501280/.local/bin:$PATH"
# 或添加到 ~/.bashrc
echo 'export PATH="/app/501280/.local/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

Q15: Loghouse 返回 "no match routingMapping"

原因: log_name 不正确

解决:

bash
# 确认正确的 log_name
# 从 Loghouse UI 查看:https://loghouse.alibaba-inc.com/
# 对于 lse2-us-business-service,通常是 nginx_uni

Q16: curl 请求超时

原因: 灰度环境响应慢或网络问题

解决:

bash
# 增加超时时间
curl -s --max-time 60 "$FULL_URL"

# 或尝试线上环境
./poi-debug.sh <gsid> <poiid> online

最佳实践

Q17: 排查问�

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad or ambiguous terms such as "contentPerson" and "手艺人模块", which can cause the skill to activate outside the intended POI-debugging context. Because this skill orchestrates code lookup, log access, and request reproduction, accidental invocation could expose internal diagnostics or cause unnecessary access to sensitive engineering systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrase list contains broad terms like “poi 问题”, “详情页异常”, and “poi 调试” that can match ordinary troubleshooting conversations rather than explicit requests to run this specific skill. In an agent environment, ambiguous activators can cause unintended invocation of a powerful debugging workflow that may access logs, source mappings, trace data, or internal code paths without the user clearly intending that action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README instructs users to replay requests and query logs using a GSID/session identifier, but it does not warn that these identifiers and resulting logs may contain sensitive user or operational data. In a debugging skill that accesses production-like telemetry and reproduces user flows, missing handling guidance increases the risk of oversharing, insecure storage, or misuse of session-linked information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatically persisting troubleshooting results to /tmp can expose sensitive internal data such as GSIDs, trace IDs, response payloads, and service details to other local users or processes, especially on shared systems. In this skill's context, the orchestrator handles internal debugging artifacts, so storing them in a broadly accessible temporary directory increases the chance of accidental disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README includes full example values for GSID, POIID, TraceID, internal hostnames, file paths, and response characteristics without any handling guidance. Even if illustrative, exposing realistic internal identifiers and operational details in documentation can normalize unsafe sharing practices and may leak sensitive environment information if the examples are real or copied from production-like debugging sessions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill orchestrates shell commands, file reads/writes, curl, and code/log retrieval but does not declare any explicit tool scope or allowed-tools boundary. That means an agent may execute powerful actions without least-privilege constraints, increasing the chance of unauthorized data access, arbitrary network requests, and unsafe file operations during routine troubleshooting.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to activate on common support or debugging language such as 'POI 排查', 'poi 问题', or 'traceId 分析' without clear exclusions or confirmation gates. In practice this can cause the skill to run in contexts where the user did not intend log queries, request replay, or code inspection, exposing sensitive identifiers and initiating unnecessary high-privilege actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to extract full logged URLs and replay them with curl while handling gsid, traceId, and other debugging identifiers, but it provides no user-facing warning or safety controls around sensitive data handling. Replaying captured URLs can reuse privileged query parameters or session-linked identifiers, leading to inadvertent exposure of internal data, privacy issues, or unintended requests against production-like environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest declares many broad trigger phrases such as generic POI/debug/troubleshooting terms, which can cause the skill to activate in conversations beyond its intended scope. Because this skill appears to orchestrate internal diagnostic steps involving code, logs, request replay, and trace/gsid analysis, overbroad activation increases the chance of exposing sensitive operational workflows or causing the agent to perform powerful actions on insufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The FAQ instructs users to list and copy debugging artifacts from /tmp into a personal documents directory without any warning that these files may contain GSIDs, trace IDs, POI identifiers, logs, and raw response payloads. In this skill context, those artifacts are operational data gathered from internal systems, so normalizing long-term local retention and copying increases the chance of sensitive internal data exposure beyond its original troubleshooting purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file provides a ready-to-run log query template that includes a concrete employee ID and explicitly instructs operators to query logs by GSID, which is a user session identifier. Even though the GSID value in the template is placeholder text, this materially lowers the barrier to accessing and correlating sensitive session-linked telemetry, and there is no warning about authorization, minimization, redaction, or retention when handling user/session data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script automatically replays a backend request with curl using parameters derived from log data, without any explicit operator confirmation or warning that a live internal service call will be made. In this debugging context, replaying requests can trigger side effects, hit sensitive internal endpoints, or unintentionally resend production traffic patterns, especially since the URL path is taken from logs and the script targets internal gray/prod hosts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script stores replayed backend response data and generated debug reports under /tmp, which is commonly world-readable or accessible to other local users/processes depending on system configuration. Because this skill processes production debugging artifacts such as GSID, traceId, URLs, response bodies, and code-location metadata, persisting them without warning, access controls, or cleanup can expose sensitive operational and user-related data beyond the intended debugging session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

SQP-3 适用于所有文件类型。该文件整体以中文强制性说明操作步骤与触发词配置,未声明这是面向特定中文团队的限定文档,也未提供语言选择或说明可按用户语言偏好提供内容,存在语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Natural-language content throughout the file is Chinese-only, including the title, descriptions, examples, and operational guidance. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the constraint is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README header states the skill '自动执行 6 步排查流程', while the concrete feature list and sample run enumerate only five visible stages: 日志查询, 请求复现, 响应解析, 代码定位, 生成排查报告. This is an active documentation inconsistency about what the skill does, not merely omitted detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language instructions and operational guidance in the README are presented entirely in Chinese, with no indication that users may choose another language or that the language restriction is intentional and scoped. This can constitute a language/locale policy issue because the skill imposes a specific language by default rather than offering user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language content throughout the skill FAQ forces a specific language/locale experience for users, and there is no indication of opt-in, alternative language support, or documented regional justification. SQP-3 applies to all file types and covers language or locale policy violations of this kind.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.