Back to skill

Security audit

Architecture Governance

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent architecture-governance helper, with no evidence of hidden execution, persistence, exfiltration, or destructive behavior, though some examples and the bundled script need caution.

Install only if a Chinese-language architecture-governance workflow is appropriate. Before using the integration examples, replace plaintext HTTP credential examples with HTTPS and environment-managed tokens. Treat the bundled health-check script as needing a bug fix before relying on it in CI or governance reporting, and choose report output paths carefully because --output can overwrite a file at the specified path.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/metrics.md:63
Finding

Authentication Token Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: references/metrics.md:63
Vulnerability Type: Credential exposure over an unencrypted transport
Risk Level: Medium

Vulnerable Code

bash
curl -u token: "http://sonarqube/api/measures/component?component=my-service&metricKeys=complexity,duplicated_lines_density,ncloc,function_complexity,coverage"

Technical Analysis

The documented command supplies a SonarQube authentication token through HTTP Basic authentication while connecting over plaintext HTTP. Basic authentication only encodes the credential; it does not encrypt it. Without TLS, the authorization header and returned architecture metrics are exposed to interception and modification.

A user following this integration example on an untrusted or compromised network could disclose the SonarQube token to an on-path attacker. The use of plaintext HTTP also provides no reliable server authentication, allowing an attacker to impersonate the service and collect the supplied credential.

Attack Path

  1. A user follows the documented SonarQube metric-collection example.
  2. curl sends the Basic authorization header to the endpoint over plaintext HTTP.
  3. An attacker with access to the network path captures the request or redirects it to an attacker-controlled endpoint.
  4. The attacker recovers the token and may use it against the SonarQube instance according to the token's assigned permissions.
  5. Alternatively, the attacker modifies metric responses, corrupting architecture-health reports and governance decisions.

Impact Assessment

The maximum privileges obtained are those assigned to the exposed SonarQube token. Depending on its scope, an attacker may gain access to source-quality findings, project metadata, vulnerability reports, or administrative operations.

The affected scope includes users who copy the example without replacing HTTP with an authenticated TLS connection. Metric integrity is also at risk because an on-path attacker ...[truncated 61 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require HTTPS with certificate verification:
bash
curl --fail --show-error --silent \
  -u "${SONAR_TOKEN}:" \
  "https://sonarqube.example.com/api/measures/component?component=my-service&metricKeys=complexity,duplicated_lines_density,ncloc,function_complexity,coverage"
  1. Retrieve the token from a protected environment variable or secret manager rather than embedding it in the command or documentation.
  2. Use a dedicated, read-only, least-privilege token restricted to the required projects and API operations.
  3. Rotate any token that may already have been sent over plaintext HTTP.
  4. Prohibit insecure TLS bypass options such as curl -k.
  5. Document secure token handling, including shell-history risks, log redaction, expiration, and rotation.
  6. Prefer a configuration mechanism that validates the URL scheme and rejects non-HTTPS endpoints when credentials are present.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/health-check.py:25
Finding

Zero-Division Denial of Service in Metric Scoring

Content
View full analysis

Vulnerability Details

File Location: scripts/health-check.py:25-29, 81-108, 136
Vulnerability Type: Unhandled arithmetic exception causing denial of service
Risk Level: Medium

Vulnerable Code

python
DEFAULT_THRESHOLDS = {
    # ...
    'circular_dependency': {'healthy': 0, 'warning': 0},
    'cross_layer_call': {'healthy': 0, 'warning': 0},
    # ...
}
python
def calculate_score(value: float, thresholds: Dict, higher_is_better: bool = True) -> int:
    # ...
    healthy = thresholds['healthy']
    warning = thresholds['warning']

    # ...
    else:
        if value <= healthy:
            return 100
        elif value <= warning:
            ratio = (warning - value) / (warning - healthy)
            return int(75 + ratio * 25)
        else:
            ratio = max(0, 1 - (value - warning) / warning)
            return int(ratio * 75)

The bundled demonstration data directly reaches the vulnerable path:

python
'circular_dependency': 1.0,

Technical Analysis

Both circular_dependency and cross_layer_call are lower-is-better metrics with healthy and warning thresholds set to zero. For any positive value:

  1. value <= healthy is false.
  2. value <= warning is false.
  3. Execution enters the final branch.
  4. (value - warning) / warning divides by zero.

This raises an unhandled ZeroDivisionError and terminates the process before a report is generated. The bundled metric value for circular_dependency is 1.0, so the documented normal invocation is sufficient to trigger the failure.

The issue is deterministic and does not require code execution privileges. Once real metric collectors are integrated, any metric source capable of reporting a positive circular-dependency or cross-layer-call count can trigger it.

Attack Path

  1. The health-check script receives or generates a positive value for circular_dependency or cross_layer_call.
  2. calculate_dimension_scores() identifies the metric as l ...[truncated 923 chars]
Remediation
View remediation

Remediation Suggestions

  1. Explicitly handle zero thresholds for binary violation metrics:
python
else:
    if value <= healthy:
        return 100

    if warning <= healthy:
        return 0

    if value <= warning:
        ratio = (warning - value) / (warning - healthy)
        return int(75 + ratio * 25)

    ratio = max(0, 1 - (value - warning) / warning)
    return int(ratio * 75)
  1. Prefer dedicated binary scoring for metrics where zero is the only acceptable value:
python
if metric in {'circular_dependency', 'cross_layer_call'}:
    score = 100 if value == 0 else 0
  1. Validate threshold configurations before scoring. Reject or specially classify configurations where interpolation denominators would be zero.
  2. Validate metric values as finite, non-negative numbers before calculation.
  3. Add unit tests covering:
    • Zero values with zero thresholds.
    • Positive values with zero thresholds.
    • Equal healthy and warning thresholds.
    • Negative, infinite, and NaN values.
  4. Add integration tests that execute every command shown in SKILL.md, including the bundled default data.
  5. Catch metric-level calculation failures and produce an explicit invalid-metric result rather than terminating the entire report.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill references report and task outputs and includes script usage that can produce files, but it does not declare any explicit tool scope or permissions boundaries. In an agent environment, missing scope can allow broader-than-intended file write behavior or make the runtime fall back to permissive defaults, increasing the risk of unauthorized file creation or overwrite.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger conditions are very broad, covering multiple governance, review, comparison, and reporting scenarios without clear exclusions. Broad activation boundaries can cause the skill to engage in contexts it was not intended for, leading to inappropriate handling of user requests, accidental shadowing of more suitable skills, or overly expansive access to project context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata and role definition are written entirely in Chinese and present the skill as a Chinese-language expert experience, with no indication that users may choose another language. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains a full report template in Chinese only, which can amount to a language/locale policy violation when the skill does not provide user opt-in or an alternative language option. The file does not indicate that it is intended solely for a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire markdown template is written in Chinese and presents a fixed-language reporting format, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code file includes user-facing docstrings, argparse descriptions, console messages, and report content in Chinese, with no option for users to select another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly documented as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire checklist is written only in Chinese, beginning with the title at L001, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy criteria, a fixed language without opt-in or explicit justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown template uses a single forced language throughout the file, which can violate language/locale policy when no user opt-in or alternative is provided. There is no indication that the template is intended only for a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file is entirely presented in Chinese starting from the title, with no indication that other languages are supported or that the locale restriction is required for a region-specific purpose. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is natural-language guidance, and all visible instructional content is presented only in Chinese. Under the language/locale policy rule, forcing a single language without user opt-in or a documented justification can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file title and the entire document are written in Chinese, and there is no surrounding note that this skill documentation is optional by locale, multilingual, or limited to a China-specific context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.