T09 · Insecure Skill Coding Practices
- Location
scripts/render.js:217- Finding
Shell Command Injection Through Attacker-Controlled Output Paths
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real image generator, but crafted content or URLs could make it run local commands or reach internal network resources.
Review before installing. Avoid using this skill on untrusted URLs or untrusted article titles until it replaces shell-string execution with argument-array process execution, pins Playwright in a manifest and lockfile, validates and limits all URL fetches, escapes image/CSS values safely, and offers explicit cache controls.
scripts/render.js:217Shell Command Injection Through Attacker-Controlled Output Paths
scripts/extract-brand.js:26Server-Side Request Forgery Through Unrestricted Page and Logo Fetching
scripts/render.js:71HTML and CSS Injection in Generated Browser Documents
scripts/render.js:220Runtime Execution of an Unpinned Package Through npx
scripts/extract-brand.js:26Unbounded Network Response Buffering Enables Resource Exhaustion
The trigger terms include very broad everyday words such as “图片”, “封面”, and “海报”, which can match many unrelated user requests and cause the skill to activate unexpectedly. In this skill’s context, accidental activation is more dangerous because the workflow then encourages automatic URL fetching and local caching, potentially processing user-supplied pages and storing derived data without the user clearly intending to invoke this capability.
Referenced artifact was not completely inspected
node scripts/render.js --theme <theme> --layout cover --platforms <ids>
Referenced artifact was not completely inspected
node scripts/render.js --theme <theme> --layout cover --platforms <ids>
Referenced artifact was not completely inspected
node scripts/render.js --theme <theme> --layout cover --platforms <ids>
The skill instructs the agent to automatically fetch a URL and extract logo, theme color, fonts, and page content, but the user-facing flow does not clearly require prior consent before that collection begins. This creates a privacy and transparency risk: visiting a user-provided URL may reveal network metadata and collecting page assets/content may exceed what the user expected from a simple image-generation request.
The skill states that extracted brand data is cached in ./.yuanfang/brand-specs/<domain>.json for 7 days and shared via the project workspace, but this persistence is not surfaced as a prominent warning before collection. In context, this makes the issue more serious because cached artifacts may contain user-supplied domains, extracted branding, and other derived data that can persist in source-controlled workspaces and be exposed to collaborators unintentionally.
SQP-3 applies to all file types and covers language or locale policy violations. The file consistently presents instructions and output descriptions only in Chinese, with no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context.
This script performs outbound network requests to arbitrary user-supplied URLs and persists the fetched brand data under the local .yuanfang/brand-specs cache without any explicit user warning or consent beyond CLI behavior. In an agent/skill context, that can expose sensitive browsing targets to remote servers and leave artifacts on disk, which is a meaningful privacy and transparency issue even if the code appears intended for normal functionality.
The script constructs a shell command that invokes npx playwright screenshot without pinning an exact package version. npx may download and execute whatever version is currently resolved from the registry or local environment, creating a supply-chain risk where unexpected or malicious code could run during rendering.
The natural-language comment and implementation state that Chinese is the default primary use case and unconditionally return lang: 'zh-CN' for all non-RTL content. This imposes a specific locale on rendered output without offering a user choice or documenting an opt-in, which matches the language/locale policy violation criteria.
The HTML root element sets lang="zh-CN", which forces a specific language/locale in the rendered output. Under the policy, locale constraints should either be user-selectable or clearly justified as region-specific; this file provides neither.
The template name and description are written only in Chinese, which indicates a language-specific constraint in natural-language metadata. There is no accompanying indication that users can choose another language or that the locale restriction is intentionally limited to a China-specific use case.
The HTML tag hard-codes lang="zh-CN", which imposes a specific language/locale on all rendered output. Under the stated policy, locale-specific behavior should either be user-selectable or clearly documented as justified for a region-specific skill.
The HTML root element sets lang="zh-CN", which enforces a specific language/locale in the rendered output. Under the policy rules, forcing a locale without user opt-in or documented region-specific justification is a natural-language policy violation.
The document root sets lang="zh-CN", which hard-codes a specific language/locale for the skill output. Under the policy criteria, forcing a locale without user opt-in or clear region-specific justification is a natural-language policy violation.
The HTML root element sets lang="zh-CN", which forces a specific language/locale in the rendered output. Under the policy, locale constraints should either be optional for the user or clearly justified as region-specific, and no such opt-in or justification appears in this file.
This markdown file contains user-facing instructions and parameter descriptions exclusively in Chinese, such as the section titles and notes. Under the policy, forcing a specific language without offering a language or locale choice can be a natural-language policy violation.
This is a markdown file, so SQP-2 applies to omissions in the skill description. The examples show fetching content from a URL and redirecting output to content.json, which can affect privacy and local data, but the document does not include any warning about network access or overwriting/creating local files.
This markdown file contains user-facing natural-language instructions only in Chinese, and it does not offer an alternative language, opt-in, or state that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation.
This markdown file contains user-facing guidance exclusively in Chinese, including headings, descriptions, and recommendations. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation when no justification or alternative language option is provided.
This code performs an outbound HTTP request to a user-provided URL and sends request metadata including a custom User-Agent, but there is no confirmation prompt, user-facing log/print, or explanatory comment/docstring disclosing that network activity. For a code file, outbound transmission of user-supplied data should have some visible disclosure unless clearly warned elsewhere.
The comment and thrown error say the renderer refuses to proceed until the user confirms logo, brand name, theme, and platform. However, the actual gate at L404-L406 only checks whether theme is default and whether brand-related fields are absent; it does not verify that platforms were explicitly chosen, and rendering still proceeds with default platforms when those conditions are not met.
The HTML root element sets lang="zh-CN", which forces a specific language/locale in the rendered output. For a generic template, this is a natural-language locale policy concern because the file does not offer a user choice or explain why Chinese is required.
The template name, description, and brand fields are written entirely in Chinese, and the font stack explicitly prioritizes a Chinese locale font. This can indicate a language/locale constraint without any visible opt-in or note that the template is region-specific.
The HTML root sets lang="zh-CN", which forces a specific language/locale in the rendered output. Under the policy, locale constraints should either be user-selectable or clearly documented as justified for a region-specific use case.
Detected: suspicious.dangerous_exec