Back to skill

Security audit

数据分析与反馈

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent advertising analytics helper, with no evidence of hidden access or exfiltration, though its CSV export should be handled carefully.

Install only if Chinese-language commands and output are acceptable for your operators. Treat exported CSVs as potentially unsafe when material IDs can come from untrusted sources, and prefer fixing CSV escaping/formula neutralization before opening exports in spreadsheet software. Pin devDependencies if you build this package from source in a controlled environment.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.ts:322
Finding

CSV Formula and Structure Injection in Report Export

Content
View full analysis
[ p.materialId, p.impressions.toString(), p.clicks.toString(), (p.ctr * 100).toFixed(2) + "%", p.conversions.toString(), (p.cvr * 100).toFixed(2) + "%", p.cost.toFixed(2), p.revenue.toFixed(2), p.roas.toFixed(2) ]); const csv = [headers, ...rows].map(row => row.join(",")).join("\n"); ``` ### Technical Analysis The CSV exporter inserts `p.materialId` directly into a comma-separated row without CSV escaping or spreadsheet-formula neutralization. The material identifier originates from the required `materialId` argument of the `analytics ingest` command and can therefore contain attacker-controlled content. A material identifier beginning with `=`, `+`, `-`, or `@` may be interpreted as a formula when the exported file is opened in spreadsheet software. Depending on the spreadsheet application and its security settings, such formulas may initiate external requests, expose contextual information, or present deceptive content. The implementation also fails to quote fields containing commas, double quotes, carriage returns, or line feeds. An attacker can consequently create additional cells or records, corrupt the report structure, and inject misleading report content. ### Attack Path 1. An attacker or untrusted data source invokes the analytics ingestion command with a malicious `materialId`, such as a spreadsheet formula or a value containing commas and newlines. 2. The application stores the identifier in the in-memory performance map without validation or normalization. 3. A report is generated while the malicious material is included among `topPerformers`. 4. A user invoke ...[truncated 1131 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description and main documentation are written entirely in Chinese, and the skill does not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-language or region-specific context. This creates a natural-language policy concern because it implicitly imposes a language/locale requirement without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command descriptions, help text, and user-facing response strings are hard-coded in Chinese, which forces a specific language regardless of user preference or environment. This is not a code-execution or data-exfiltration issue, but it can mislead users, reduce operator comprehension, and cause unsafe misunderstandings in multilingual deployments where users may misinterpret alerts, errors, or analytics feedback.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description is written entirely in Chinese, which can indicate a language-specific constraint for the skill without documenting any user language choice or opt-in. Under the policy rule for natural-language violations, forcing a specific language without user selection can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 20)May include surrounding context.

json
"license": "MIT",
  "dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
"dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Static analysis

No suspicious patterns detected.