T07 · Tool Hijacking and Spoofing
- Location
skill.py:14- Finding
Untrusted Python Module Loading from a Mutable External Directory
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is mostly a disclosed long-term context manager, but it depends on unaudited code loaded from a user-writable external directory and stores/searches persistent user content.
Review before installing. Use only if you trust the external context-manager directory and its Python files, install dependencies in an isolated environment with pinned versions, and avoid storing secrets or sensitive private files unless you accept that they may be indexed, cached, logged, and optionally sent to configured model services.
skill.py:14Untrusted Python Module Loading from a Mutable External Directory
skill_demo.py:63Unpinned Third-Party Dependency Installation Guidance
This markdown file presents all user-facing instructions, examples, and warnings exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue unless the locale constraint is explicitly justified, which is not present here.
The test invokes the skill exclusively with Chinese-language prompts such as creating, listing, and searching agents/files. This reflects a language-specific usage assumption without any visible opt-in, fallback, or documented justification, which can violate language/locale policy requirements for user choice.
The skill returns user-facing output in Chinese and relies on Chinese trigger phrases throughout the command handling logic. This creates a language policy concern because the file does not offer user opt-in, fallback language support, or any documented justification that the skill is intentionally Chinese-only.
The activation logic depends on Chinese words like '创建', '删除', '搜索', and '帮助', while only partially supporting English via 'agent' and 'help'. This effectively enforces a specific language for core functionality, which is a policy violation unless the locale restriction is explicitly justified or made optional.
The skill enables creation of persistent agents and associated long-term context without any visible authorization, approval, ownership checks, retention limits, or user confirmation. In an agent environment, this can be abused to store sensitive data indefinitely, create unauthorized persistent state, or poison future retrievals across sessions if the underlying context manager is shared.
# Generate agent ID
agent_id = agent_name.lower().replace(" ", "_").replace("-", "_")
# Create agent
response = await self.context_manager.create_agent(
agent_id=agent_id,
name=agent_name,
The trigger logic only recognizes Chinese command words such as "创建", "列出", "删除", "保存", "搜索", and most responses/help text are written exclusively in Chinese. This creates a language-policy issue because users are not given an opt-in or alternative locale, and no region-specific justification is provided.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
pip install chromadb sentence-transformers fastapi uvicorn redis aiofiles openai"""
def _create_agent(self, message: str) -> str:
"""Create an agent."""
import re
match = re.search(r"为\s+['\"]?([^'\"]+)['\"]?\s+创建", message)
if match:
The test inputs are written only in Chinese string literals, which reflects a language-specific usage pattern without any visible opt-in or alternative locale handling. Under the policy rule, forcing a specific language without user choice can be a natural-language policy concern even in code examples.
The script sends only Chinese natural-language prompts to the skill, such as help, create, list, and search requests. This imposes a specific language/locale in the interaction flow without documenting user choice or indicating that the skill is intentionally region-specific.
No suspicious patterns detected.