Back to skill

Security audit

需求管理

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its demand-management purpose, but it lets callers read and change business workflow state and trigger production-style events without clear authorization controls.

Review this skill before installing in a shared or production workspace. It should only be enabled where command invocation is already restricted, or after adding explicit authorization for reviewers, owners, and production roles, minimizing approval event payloads, and redacting or validating logged event data.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
index.ts:62
Finding

Missing authorization checks permit unauthorized demand review and workflow manipulation

Content
View full analysis
{ const demand = this.demands.get(id); if (!demand) { throw new Error(`Demand not found: ${id}`); } if (demand.status !== "pending_review") { throw new Error(`Cannot review demand in status: ${demand.status}`); } demand.status = result === "approved" ? "approved" : "rejected"; demand.reviewer = reviewer || this.api.user?.id; demand.reviewComments = comments; demand.updatedAt = new Date(); this.api.log(`info`, `Demand ${id} reviewed: ${result}`); // If approved, trigger production pipeline if (result === "approved") { await this.triggerProduction(id); } return true; } ``` The command handler invokes this method without performing an authorization check: ```typescript execute: async (args) => { await manager.review(args.id, args.result, args.comments); return { success: true, message: `Demand ${args.id} has been ${ args.result === "approved" ? "approved" : "rejected" }` }; } ``` ### Technical Analysis The skill uses `this.api.user?.id` only to record who performed a review. It never verifies that the current caller is a configured reviewer, demand owner, administrator, or other authorized principal. The configured reviewer list is used only by `notifyReviewers`; it is not enforced by `review`. Consequently, the application treats caller identity as audit metadata rather than as an authorization control. The same design issue affects the following operations: - `get` and `list` expose demand records without ownership or role ...[truncated 2096 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
index.ts:336
Finding

Unvalidated external event payload is serialized wholesale into logs

Content
View full analysis
{ api.log("info", `Received demand.created event: ${JSON.stringify(data)}`); }); ``` ### Technical Analysis The event handler treats `data` as trusted and serializes the complete payload directly into an informational log message. It does not perform schema validation, sensitive-field redaction, size enforcement, or safe serialization. Because the event originates from another skill or event publisher, its contents are outside this handler's direct control. A crafted payload can therefore: - Place credentials, personal information, demand descriptions, or other sensitive values into persistent logs. - Insert attacker-controlled line breaks or formatting into log output if the logging backend does not normalize messages. - Consume excessive storage and processing resources through a very large serializable object. - Cause `JSON.stringify` to throw when supplied with a cyclic object, potentially disrupting event processing. The reviewed code does not establish that event data actually contains secrets, so the confidentiality impact is conditional on the payload supplied by publishers. ### Attack Path 1. Another skill or event-capable component publishes a `demand.created` event. 2. The payload includes sensitive fields, misleading log content, excessive nested data, or a cyclic reference. 3. The handler receives the payload without validating its type or structure. 4. It attempts to serialize the complete object. 5. Serializable content is forwarded to the logging backend, where it may be retained and accessible to log readers. A cyclic value instead causes serialization to fail and can interrupt the handler. ### Impact Assessment The primary risk is unintended disclosure and retenti ...[truncated 380 chars]
Remediation
View remediation
{ const demandId = typeof data === "object" && data !== null && typeof data.demandId === "string" ? data.demandId.slice(0, 128) : "unknown"; api.log("info", `Received demand.created event for ${demandId}`); }); ``` 3. Do not log descriptions, prompts, authentication data, tokens, personal information, or complete arbitrary objects. 4. Enforce input and output length limits before writing any externally controlled value to logs. 5. Normalize control characters if untrusted strings must be logged. 6. Wrap event processing in error handling so malformed or cyclic payloads cannot cause an unhandled serialization failure. 7. Configure retention periods and access controls for the logging backend according to the sensitivity of workflow metadata. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This TypeScript skill hard-codes Chinese natural-language identifiers and user-facing text such as the method name 拆解, Chinese log/output strings, and Chinese command descriptions. The file does not indicate that the skill is region-specific or provide any opt-in/locale selection, which creates a language-policy issue for users expecting language neutrality.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language description is entirely in Chinese and presents the skill as a general-purpose ad creative demand management tool, with no indication that use is limited to Chinese-speaking users or a China-specific workflow. This can violate language/locale policy because it imposes a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions and descriptions in the README are presented only in Chinese, which can imply a fixed language requirement. There is no note that the skill is Chinese-only, region-specific, or that users may choose another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README states that the skill will trigger workflow-orchestrator and update material-library metadata, but it does not warn users that invoking the skill may cause side effects in downstream systems. This is risky because users may treat the skill as a documentation or planning tool while it can actually create workflows or mutate shared data, increasing the chance of unintended operational changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill description and primary explanatory content are written in Chinese, while the file title and structure are bilingual only in part. This can amount to a language/locale policy issue if users are not given an explicit option to receive instructions in another language.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 23)May include surrounding context.

json
"license": "MIT",
  "dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
"dependencies": {},
  "devDependencies": {
    "@types/node": "^20.0.0",
    "typescript": "^5.0.0"
  }
}

Static analysis

No suspicious patterns detected.