Back to skill

Security audit

gold-price-auto

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple gold-price reporting script with some reliability and data-integrity caveats, but no evidence of hidden or destructive behavior.

Install only if you are comfortable with a script that runs Node via a sibling Playwright scraper and pulls gold-price text from a single website. Do not rely on its output for financial decisions without independent verification, and review or fix the unchecked directory change and HTTP URL before scheduling it with cron.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
run_gold_price.sh:4
Finding

Unchecked Directory Change Can Cause Execution of an Unintended Local Script

Content
View full analysis

Vulnerability Details

File Location: run_gold_price.sh, lines 4-12
Vulnerability Type: Untrusted relative-path execution after an unchecked directory-change failure
Risk Level: Medium

Vulnerable Code

bash
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)"
PLAYWRIGHT_DIR="$SCRIPT_DIR/../playwright-scraper-skill"

echo "=== 💰 金价自动汇报 ==="
echo "时间: $(date '+%Y-%m-%d %H:%M')"
echo ""

# 使用playwright获取金价
cd "$PLAYWRIGHT_DIR"
OUTPUT=$(node scripts/playwright-simple.js "http://www.huangjinjiage.cn/jinrijinjia.html" 2>&1)

Technical Analysis

The script changes to the expected sibling dependency directory but does not check whether cd "$PLAYWRIGHT_DIR" succeeds. It also does not enable immediate termination on command failures. If the directory is missing or inaccessible, execution continues in the process's previous working directory.

The subsequent Node.js command uses the relative path scripts/playwright-simple.js. Consequently, after a failed directory change, Node.js resolves that path beneath the caller-controlled working directory rather than the intended playwright-scraper-skill directory.

The audited project does not contain the referenced sibling dependency, making a failed directory change a realistic deployment condition. Exploitation still requires an attacker to influence the launch directory and place a file at the expected relative path.

Attack Path

  1. The expected sibling directory, ../playwright-scraper-skill, is absent, inaccessible, or renamed.
  2. An attacker creates a malicious file at scripts/playwright-simple.js beneath a directory they control.
  3. The victim launches run_gold_price.sh while that attacker-controlled directory is the current working directory.
  4. The cd "$PLAYWRIGHT_DIR" command fails, but the shell continues execution.
  5. Node.js resolves scripts/playwright-simple.js from the unchanged working directory.
  6. The atta ...[truncated 498 chars]
Remediation
View remediation

Remediation Suggestions

  • Enable strict shell error handling near the beginning of the script:

    bash
    set -euo pipefail
    
  • Explicitly verify that the dependency directory and target script exist before execution:

    bash
    PLAYWRIGHT_SCRIPT="$SCRIPT_DIR/../playwright-scraper-skill/scripts/playwright-simple.js"
    
    if [[ ! -f "$PLAYWRIGHT_SCRIPT" ]]; then
        printf 'Required scraper script was not found: %s\n' "$PLAYWRIGHT_SCRIPT" >&2
        exit 1
    fi
    
  • Invoke the validated script by its absolute path instead of relying on the current working directory:

    bash
    OUTPUT=$(node "$PLAYWRIGHT_SCRIPT" \
      "https://www.huangjinjiage.cn/jinrijinjia.html" 2>&1)
    
  • If changing directories remains necessary, fail explicitly when it is unsuccessful:

    bash
    cd "$PLAYWRIGHT_DIR" || {
        printf 'Cannot access dependency directory: %s\n' "$PLAYWRIGHT_DIR" >&2
        exit 1
    }
    
  • Deploy the sibling scraper as a pinned, integrity-verified dependency and restrict write access to its installation directory.

T09 · Insecure Skill Coding Practices

Warning
Location
run_gold_price.sh:12
Finding

Gold Price Data Is Retrieved over Unauthenticated Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: run_gold_price.sh, line 12
Vulnerability Type: Unauthenticated transport for financial data
Risk Level: Medium

Vulnerable Code

bash
OUTPUT=$(node scripts/playwright-simple.js "http://www.huangjinjiage.cn/jinrijinjia.html" 2>&1)

Technical Analysis

The target page is requested through plaintext HTTP. HTTP does not authenticate the remote server and does not protect response integrity. A network-positioned attacker, compromised proxy, or malicious hotspot can intercept and modify the returned page.

The script subsequently extracts strings matching a price-oriented regular expression and prints them without verifying their source, plausibility, timestamp, or integrity. An attacker can therefore inject fabricated values that satisfy the expected pattern and cause them to appear as legitimate gold-price results.

Attack Path

  1. A victim runs the Skill over a network controlled or observable by an attacker.
  2. The scraper requests http://www.huangjinjiage.cn/jinrijinjia.html.
  3. The attacker intercepts the unencrypted HTTP response.
  4. The attacker inserts fabricated values matching the script's expected price format, such as a numeric value followed by 元/克.
  5. The scraper returns the modified page content.
  6. The script's regular expression accepts and prints the injected values as gold-price data.

Impact Assessment

Exploitation can compromise the integrity of the reported financial information and mislead users or downstream automation. It does not directly grant local system privileges or code execution through the audited script. The practical scope is data manipulation, although decisions based on the falsified prices could have financial consequences.

Remediation
View remediation

Remediation Suggestions

  • Replace the plaintext URL with the site's verified HTTPS endpoint:

    bash
    OUTPUT=$(node "$PLAYWRIGHT_SCRIPT" \
      "https://www.huangjinjiage.cn/jinrijinjia.html" 2>&1)
    
  • Ensure the scraper does not ignore TLS certificate errors.

  • Reject redirects that terminate on HTTP or an unexpected hostname.

  • Validate extracted values for expected ranges, count, labels, and freshness before presenting them.

  • Prefer a documented, authenticated data API when available.

  • Clearly identify each extracted value and avoid presenting unlabeled regular-expression matches as authoritative financial data.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的核心能力包括“每小时自动查询”以及“国内外金价并汇报”。但所给代码只是一个可手动执行的 shell 脚本:它切换到另一个目录,运行 Playwright 脚本访问单一 URL,然后从输出中提取价格文本并打印来源。代码中没有任何定时任务、循环、cron 或调度逻辑,因此“每小时自动”没有在该代码块中体现;同时也只访问了一个中文金价网站,无法支持“国内外”金价查询这一表述。虽然“汇报”可以勉强对应终端输出结果,但整体上声明比实际行为更宽,存在实质性不匹配。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The phrase '每小时自动查询金价并汇报' describes recurring automatic behavior but does not clearly specify what triggers the skill, under what conditions it should run, or any scope limitations. In a skill description/manifest context, this ambiguity can lead to unintended invocation or confusion between manual execution and scheduled automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.