T09 · Insecure Skill Coding Practices
- Location
tools/quality_gate_checker.py:47- Finding
Security Gate Can Be Bypassed Using Unrecognized Execution Primitives
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly aligned with quality governance, but its quality-checker writes into checked directories and its broad agent-coordination scope is under-scoped enough to require review before installation.
Review this skill before installing, especially if it will run in CI or on third-party skill packages. Run the checker only with low privileges and on trusted directories, and do not treat its security result as authoritative without stronger scanning. Narrow activation triggers and avoid any instruction that asks agents to expose chain-of-thought reasoning.
tools/quality_gate_checker.py:47Security Gate Can Be Bypassed Using Unrecognized Execution Primitives
tools/quality_gate_checker.py:326Attacker-Controlled Report Symlink Can Overwrite Arbitrary Writable Files
The trigger list includes broad generic terms such as “质量”, “品质”, and “PDCA”, which can appear in many unrelated conversations and cause the skill to activate unintentionally. Because this skill has MCP access to sessions_send and subagents, accidental invocation is more risky than a purely passive formatting skill: it can steer workflows, influence agent coordination, and impose its governance logic outside the user’s intent.
The skill prescribes mandatory output behavior, including fixed terminology, banned wording, and retention of reasoning process, without any user opt-in. This is risky because it can override user preferences and system-safe response norms, and the explicit requirement to preserve reasoning may pressure downstream agents to reveal chain-of-thought or internal deliberation that should remain hidden.
The listed triggers such as '需要审核Skill是否符合质量标准' and 'CI/CD流水线需要自动质量检查' describe general situations rather than specific invocation phrases or boundaries. The section does not clarify what exact request should activate this skill or when it should not be used, which can lead to unintended invocation in common quality-review conversations.
Natural-language strings in the module docstring and later CLI output are Chinese-only, and the skill does not offer an alternative language or locale selection. This can violate language/locale policy where user-facing tools should not force a specific language without opt-in.
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
report = []
report.append("# Skill质量门禁检查报告")
report.append(f"\n**检查对象**: {self.skill_path}")
report.append(f"**检查时间**: {__import__('datetime').datetime.now().strftime('%Y-%m-%d %H:%M:%S')}")
report.append(f"**总得分**: {self.score}/{self.max_score}")
report.append(f"**检查结果**: {'✅ 通过' if self.score >= 80 else '❌ 未通过'}")
The module docstring and G3 security-check description state that the tool checks for malicious or dangerous code features, and the dangerous pattern list explicitly includes __import__( as dangerous. However, generate_report() uses __import__('datetime') directly, meaning the checker contains code matching the very pattern it treats as dangerous. This is an intent/documentation contradiction, not just an implementation omission.
The natural-language instructions, headings, and usage guidance are written entirely in Chinese, and the file does not indicate that language selection is optional or limited to a China-specific deployment. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy issue.
This code unconditionally creates or overwrites quality-gate-report.md, which is a file write affecting user data in the scanned directory. While it prints the save location after writing, there is no prior warning, confirmation, or comment/docstring disclosure near the write operation itself.
No suspicious patterns detected.