Back to skill

Security audit

Meal Subsidy

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-built for meal-subsidy automation, but it can automatically submit HR claims through a remotely debuggable browser and stores sensitive work records locally without strong controls.

Review this before installing. Only run it in an isolated, trusted user account or disposable browser profile, avoid leaving Chrome remote debugging open, remove `--no-sandbox`, require confirmation before each HR submission, and clean or restrict access to generated screenshots, CSVs, logs, and browser profile data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/meal_subsidy.py:149
Finding

Chrome Is Launched Without Its Security Sandbox

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/meal_subsidy.py:128
Finding

Fixed Unauthenticated CDP Endpoint Exposes an Authenticated HR Browser Session

Content
View full analysis
Optional[str]: if port is None: port = Config.CDP_PORT try: with urllib.request.urlopen(f"http://127.0.0.1:{port}/json/version", timeout=5) as r: return json.loads(r.read()).get("webSocketDebuggerUrl") except Exception as e: log_d(f"CDP fail: {e}") return None def init_browser(p): cdp = get_cdp_url() if cdp: try: b = p.chromium.connect_over_cdp(cdp); log("chrome connected via CDP"); return b except Exception as e: log_w(f"CDP connect fail: {e}") log("auto-start chrome...") import subprocess path = next((p for p in Config.CHROME_PATHS if p and os.path.exists(p)), None) if not path: raise RuntimeError("Chrome not found") subprocess.Popen( [path, "--remote-debugging-port=9222", f"--user-data-dir={Config.CHROME_DATA}", "--no-sandbox", "--disable-dev-shm-usage", "--disable-gpu"], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, creationflags=getattr(subprocess,'CREATE_NO_WINDOW',0)) time.sleep(Config.CHROME_WAIT) cdp = get_cdp_url() if cdp: b = p.chromium.connect_over_cdp(cdp); log("chrome auto-started"); return b raise RuntimeError("Cannot connect to Chrome") ``` The documentation also instructs users to expose the same interface: ```bash "C:\Program Files\Google\Chrome\Application\chrome.exe" --remote-debugging-port=9222 ``` ### Technical Analysis Chrome DevTools Protocol provides extensive control over a browser, including page navigation, DOM inspection, JavaScript execution, network observation, and interaction with authenticated pages. The skill enables this interface on predictable port `9222` and discovers its ...[truncated 2189 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:36
Finding

Third-Party Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (11)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · screenshots/late_202604.csv (reported line 1)May include surrounding context.

text
date,off,cross,yuan
2026-04-28,21:33,False,20

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documentation describes capabilities that imply shell execution, network access, local file writes, and potential environment use, but it does not declare any tool scope or permissions boundary. This is dangerous because an automation skill that can launch browsers, connect to remote-debugging endpoints, access authenticated web sessions, and write local artifacts creates meaningful execution and data-handling risk without explicit user-visible constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description emphasizes convenience but does not clearly warn that it will automatically fill and submit forms on the user's behalf. In an HR workflow, silent or insufficiently disclosed submission behavior can cause unauthorized actions, mistaken claims, or compliance issues because users may assume the tool only checks eligibility rather than filing requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation lists screenshots and CSV records that will be stored locally, but it does not present this as a clear privacy/security warning to the user. This is dangerous because attendance screenshots and application logs may contain sensitive employment data, and undisclosed local persistence increases the risk of data leakage, retention beyond need, or accidental sharing.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · scripts/meal_subsidy.py (reported line 132)May include surrounding context.

python
def get_cdp_url(port: int = None) -> Optional[str]:
    if port is None: port = Config.CDP_PORT
    try:
        with urllib.request.urlopen(f"http://127.0.0.1:{port}/json/version", timeout=5) as r:
            return json.loads(r.read()).get("webSocketDebuggerUrl")
    except Exception as e:
        log_d(f"CDP fail: {e}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/meal_subsidy.py (reported line 149)May include surrounding context.

python
import subprocess
    path = next((p for p in Config.CHROME_PATHS if p and os.path.exists(p)), None)
    if not path: raise RuntimeError("Chrome not found")
    subprocess.Popen(
        [path, "--remote-debugging-port=9222",
         f"--user-data-dir={Config.CHROME_DATA}",
         "--no-sandbox", "--disable-dev-shm-usage", "--disable-gpu"],

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script automatically fills and submits HR reimbursement forms based on parsed attendance data with no final user confirmation step. In an agent-skill context, this can trigger unintended submissions, duplicate claims, or fraudulent-looking actions if the data is wrong, the page state changes, or the skill is invoked ambiguously.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation says Chrome remote debugging is a one-time manual setup, but later states the script will automatically launch a new Chrome with a debugging port if unavailable. This mismatch is risky because remote-debugging startup changes the trust model: it may attach to or create an authenticated browser context with broader access than the user expects.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The stated purpose is HR meal-subsidy automation based on attendance records and automatic form submission. Automatically starting a new Chrome process is a broader host-control capability that is not clearly justified by the manifest's purpose statement, especially since the rest of the document frames login and browser startup as a manual prerequisite.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code saves attendance screenshots, logs, and CSV files containing work schedule and overtime-related personal data to disk without explicit consent, minimization, or retention controls. In a shared workstation or agent environment, these artifacts can expose sensitive employee activity data to other local users or later processes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.