Back to skill

Security audit

marketing-engineer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent marketing workspace/dashboard skill, but it needs review because it can expose broad workspace contents and includes under-scoped Apple Calendar automation.

Install only if you are comfortable with an agent creating a marketing workspace, scanning its files, generating a dashboard that may include internal text, and starting a localhost server. Keep secrets and sensitive customer or business data out of the served workspace, avoid leaving the server running, use the no-text snapshot mode for sensitive projects, and require explicit confirmation before any Apple Calendar import or AppleScript automation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/serve_dashboard.py:32
Finding

Unauthenticated Workspace File Disclosure Through the Dashboard Server

Content
View full analysis

Vulnerability Details

File Location: scripts/serve_dashboard.py:32-33, 83-84, 94
Vulnerability Type: Unauthenticated local file disclosure
Risk Level: Medium

Complete Code Snippet

python
class Handler(http.server.SimpleHTTPRequestHandler):
    def __init__(self, *a, **kw):
        super().__init__(*a, directory=ROOT, **kw)
python
        if path == '/':
            self.path = '/dashboard.html'
        return super().do_GET()
python
    with Server(('127.0.0.1', port), Handler) as httpd:

The Skill directs the agent to start this server when the user asks to open the dashboard (SKILL.md:21).

Technical Analysis

Handler inherits from SimpleHTTPRequestHandler and configures the entire selected workspace as its document root. Requests not handled by /api/tree or /api/file are delegated to the inherited static-file handler.

Consequently, the safeguards in /api/file—the workspace path-prefix check, text-extension allowlist, and 400 KB read limit—do not protect the fallback route. Any file accepted by the static handler can be requested directly, including dotfiles such as /.env. This is particularly relevant because SKILL.md:53 tells users to store secrets in .env.

Although the service binds only to 127.0.0.1, it does not authenticate clients or distinguish the workspace owner from other local users or sandboxed processes that can connect to the loopback port. The dashboard process accesses files with the privileges of the user who started it.

Attack Path

  1. The user asks to open or inspect the marketing dashboard.
  2. The agent follows SKILL.md:21 and starts serve_dashboard.py for the selected workspace.
  3. An untrusted local process or another local user able to connect to the loopback port discovers or predicts the default port, 8799.
  4. The attacker sends a direct request such as:
    text
    GET http://127.0.0.1:8799/.en
    

...[truncated 810 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not use the workspace root as an unrestricted SimpleHTTPRequestHandler document root.
  2. Implement explicit routes that serve only dashboard.html and a narrowly defined set of required assets.
  3. Deny dotfiles and sensitive names, including .env, credential files, private keys, cache data, and repository metadata.
  4. Canonicalize each requested path with os.path.realpath() or Path.resolve() and verify that the resolved path remains under the resolved workspace root before reading it.
  5. Apply a strict extension and filename allowlist to every file-serving route, not only /api/file.
  6. Require an unguessable per-launch token for dashboard and API requests, or use an owner-restricted local transport where practical.
  7. Return 404 or 403 for every unrecognized route instead of delegating it to the generic static-file handler.
  8. Add regression tests confirming that requests for /.env, /.git/config, cache files, unknown paths, and paths resolving outside the workspace are rejected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (26)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 4)May include surrounding context.

text
__pycache__/
*.pyc
.DS_Store
.env
.cache/

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The playbook states that delivery includes syncing near-term schedules to the system calendar, but it does not warn the user that this modifies a local OS-managed calendar outside the workspace. Hidden host-side effects are dangerous because they can alter personal or work calendars, create persistent reminders, and surprise users who only requested a visual dashboard.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Apple Calendar workflow explicitly prefers direct-write AppleScript because it is 'confirmation-free' and 'idempotent,' and also describes opening .ics files to trigger bulk import. A workflow designed to create persistent calendar events without interactive confirmation is risky because it bypasses user awareness and makes unintended host modifications easier.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The build_text_snapshot function reads many workspace files and embeds their raw contents into dashboard.html, creating a single easily shared file that may contain large amounts of sensitive plaintext. Because the skill is explicitly designed for marketing operations and workspace aggregation, the context increases risk: it centralizes internal content, roadmap material, and possibly API keys or customer-related data into one distributable artifact, greatly amplifying accidental disclosure impact.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README encourages broad natural-language triggers such as '看下整体情况' and '内容更新了,刷新一下驾驶舱' while stating the agent will automatically run scripts. This creates an overbroad invocation surface where ordinary conversation can be interpreted as authorization to create workspaces, scan files, or launch tooling, increasing the chance of unintended local actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README says 'no commands' and presents ordinary natural-language requests as sufficient to make the agent automatically build workspaces, refresh state, and record publication activity. That creates ambiguous trigger boundaries and increases the chance the skill will perform side-effecting actions from casual user phrasing without an explicit confirmation step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README describes automatic workspace scaffolding and launching a local dashboard server, but it does not prominently warn that the skill may create files on disk and expose a local HTTP service. Users may invoke it expecting advisory help only, while the agent performs filesystem and local-network side effects that could be surprising or unsafe in sensitive environments.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises and orchestrates shell execution, file reads/writes, and local network serving, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch creates an over-privilege and transparency problem: an agent may invoke powerful capabilities without a clear allowlist, increasing the chance of unintended command execution, filesystem modification, or data exposure via the local dashboard server.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document root sets lang="zh-CN", and the interface text throughout the template is hard-coded in Chinese. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase is very broad: a generic request for visibility into marketing status or tasks causes the playbook to both create a dashboard and sync recent schedules to the system calendar. Because ordinary planning queries could match this phrasing, the skill may initiate unexpected side effects without the user specifically asking for local calendar changes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction says that whenever the user says 'look at the overall situation,' the agent should open the dashboard and sync before viewing. This couples a benign read-only request with a state-changing synchronization step, making unintended local modifications more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The playbook instructs the agent to perform OS-level Apple Calendar automation using AppleScript and osascript, including confirmation-free event creation and launching local files with open. That exceeds the core scope of generating a static marketing dashboard and introduces host-side side effects on the user's machine, including persistent calendar modification and local app invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s instructions and operational guidance are fully presented in Chinese, and there is no statement that the skill is China-specific or that users may choose another language. This can violate language/locale policy when a skill implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manual explicitly tells the agent to run build actions that rewrite dashboard.html and create backups, but it does not require an explicit confirmation or warning that files in the workspace will be modified. In an agentic context, silent file writes can surprise users, overwrite hand-edited dashboard content outside the protected custom block, or alter a repository working tree without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

Line L39 states that domestic and overseas channels must use their respective language versions and that this is '强制执行' (mandatory). This is a natural-language locale policy constraint that forces language selection rather than offering a user choice or opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script embeds a workspace-wide JSON map and, by default, textual snapshots of many files directly into a portable dashboard.html artifact without any warning, consent gate, or sensitivity filtering. In a marketing workspace, source files commonly contain campaign plans, customer notes, credentials-in-config, internal strategy, or unpublished content, so distributing the generated HTML can unintentionally leak sensitive data.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/init_workspace.py (reported line 136)May include surrounding context.

python
fj.write_text(FOLDERS_JSON.replace('__PRODUCT__', product), encoding='utf-8')
        print("  + workspace-folders.json(可定制目录说明)")
    py = sys.executable or 'python3'
    r = subprocess.run([py, str(dst_dir / 'build_dashboard.py'), str(root), '--title', product],
                       capture_output=True, text=True)
    print((r.stdout or '').strip() or (r.stderr or '').strip())

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, usage guidance, status labels, and folder descriptions are written entirely in Chinese, which imposes a specific language on users and maintainers. Under the stated policy, locale or language constraints should either be optional or explicitly justified; this file provides no opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and runtime status messages are entirely in Chinese, which imposes a specific language on users without opt-in. The file does not indicate that the tool is region-specific or offer an alternative locale, so this is a natural-language policy violation under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

Line L05 states that a complete English version was added specifically for overseas platform publication, which suggests a fixed language/locale decision in the skill materials. Under the policy, language constraints should be user-selectable or clearly justified as region-specific; this line presents a forced locale choice without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The primary instructions, examples, and interaction model are presented entirely in Chinese, while the English option is only mentioned later as a separate document for overseas publishing. This can be read as a default language constraint without an explicit user opt-in or statement that other interaction languages are supported.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The README says the agent normally auto-executes a local dashboard server and provides a localhost URL, but does not prominently warn users that a process will bind to a local port. Even if bound to 127.0.0.1, silently starting services can surprise users, conflict with existing processes, or expose local workspace contents to other local users or browser extensions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The file presents all instructions, example prompts, and expected user interactions in Chinese, such as the quoted invocation phrases and workflow guidance. Because no language choice or opt-in is offered, this can be read as imposing a specific language/locale on users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manual instructs the agent to start a local HTTP service on 127.0.0.1:8799 without an explicit notice that a listening server process will be launched. Even though loopback binding is lower risk than exposing a public interface, starting background services can create user confusion, conflict with local policy, or unintentionally expose workspace contents to other local processes or browser extensions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstring and command-line messages are written in Chinese, and the default title is also Chinese, which imposes a specific language on users without opt-in. Under the policy, locale-specific behavior should either offer a language choice or clearly document and justify the restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.