Back to skill

Security audit

Ai Company Cqo 2.0.0

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with quality governance, but its quality-checker writes into checked directories and its broad agent-coordination scope is under-scoped enough to require review before installation.

Review this skill before installing, especially if it will run in CI or on third-party skill packages. Run the checker only with low privileges and on trusted directories, and do not treat its security result as authoritative without stronger scanning. Narrow activation triggers and avoid any instruction that asks agents to expose chain-of-thought reasoning.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
tools/quality_gate_checker.py:47
Finding

Security Gate Can Be Bypassed Using Unrecognized Execution Primitives

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
tools/quality_gate_checker.py:326
Finding

Attacker-Controlled Report Symlink Can Overwrite Arbitrary Writable Files

Content
View full analysis
") print("示例: python quality_gate_checker.py ./my-skill") sys.exit(1) skill_path = sys.argv[1] if not os.path.exists(skill_path): print(f"❌ 错误: 路径不存在 {skill_path}") sys.exit(1) checker = QualityGateChecker(skill_path) passed, results = checker.check() # 保存报告 report = checker.generate_report() report_path = Path(skill_path) / 'quality-gate-report.md' report_path.write_text(report, encoding='utf-8') print(f"\n📝 报告已保存: {report_path}") sys.exit(0 if passed else 1) ``` ### Technical Analysis The checker accepts an arbitrary Skill directory from the command line and writes its report directly into that directory under the predictable name `quality-gate-report.md`. `Path.write_text()` follows symbolic links. The implementation does not verify whether the destination already exists as a symlink, whether the resolved destination remains inside the submitted Skill directory, or whether the output directory is trusted. Consequently, an attacker who controls the submitted directory can pre-create `quality-gate-report.md` as a symbolic link to another file. When a more privileged user or CI process runs the checker, the generated report overwrites the symlink target using the checker's filesystem privileges. This write operation also conflicts with the root manifest declaration at `SKILL.md:57`, which states `files: [read]`. The executable tool requires write access and therefore operates beyond the documented file-permission scope. ### Attack Path 1. An attacker creates or controls a directory that will be passed to `quality_gate_checker.py`. 2. Inside that director ...[truncated 1494 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad generic terms such as “质量”, “品质”, and “PDCA”, which can appear in many unrelated conversations and cause the skill to activate unintentionally. Because this skill has MCP access to sessions_send and subagents, accidental invocation is more risky than a purely passive formatting skill: it can steer workflows, influence agent coordination, and impose its governance logic outside the user’s intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill prescribes mandatory output behavior, including fixed terminology, banned wording, and retention of reasoning process, without any user opt-in. This is risky because it can override user preferences and system-safe response norms, and the explicit requirement to preserve reasoning may pressure downstream agents to reveal chain-of-thought or internal deliberation that should remain hidden.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The listed triggers such as '需要审核Skill是否符合质量标准' and 'CI/CD流水线需要自动质量检查' describe general situations rather than specific invocation phrases or boundaries. The section does not clarify what exact request should activate this skill or when it should not be used, which can lead to unintended invocation in common quality-review conversations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Natural-language strings in the module docstring and later CLI output are Chinese-only, and the skill does not offer an alternative language or locale selection. This can violate language/locale policy where user-facing tools should not force a specific language without opt-in.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · tools/quality_gate_checker.py (reported line 296)May include surrounding context.

python
report = []
        report.append("# Skill质量门禁检查报告")
        report.append(f"\n**检查对象**: {self.skill_path}")
        report.append(f"**检查时间**: {__import__('datetime').datetime.now().strftime('%Y-%m-%d %H:%M:%S')}")
        report.append(f"**总得分**: {self.score}/{self.max_score}")
        report.append(f"**检查结果**: {'✅ 通过' if self.score >= 80 else '❌ 未通过'}")

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and G3 security-check description state that the tool checks for malicious or dangerous code features, and the dangerous pattern list explicitly includes __import__( as dangerous. However, generate_report() uses __import__('datetime') directly, meaning the checker contains code matching the very pattern it treats as dangerous. This is an intent/documentation contradiction, not just an implementation omission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language instructions, headings, and usage guidance are written entirely in Chinese, and the file does not indicate that language selection is optional or limited to a China-specific deployment. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code unconditionally creates or overwrites quality-gate-report.md, which is a file write affecting user data in the scanned directory. While it prints the save location after writing, there is no prior warning, confirmation, or comment/docstring disclosure near the write operation itself.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.