Back to skill

Security audit

防爆阀设计选型

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local engineering calculator, but validated calculation-safety defects could produce unsafe valve recommendations in a documented use case.

Review this before installing if you plan to use it for real engineering decisions. It does not show agentic abuse such as exfiltration or persistence, but its current calculations need independent validation, especially for 5000-10000 m scenarios and for malformed, zero, negative, or extreme numeric inputs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/breathing_calc.py:625
Finding

Missing Numeric Input Validation Can Crash Calculations or Produce Unsafe Valve Recommendations

Content
View full analysis
Remediation
View remediation

other

Error
Location
scripts/breathing_calc.py:366
Finding

Altitude Conversion Silently Clamps Values Above 5000 Meters and Underestimates Valve Demand

Content
View full analysis
= alts[-1]: return ALTITUDE_PRESSURE_TABLE[alts[-1]] ``` The highest available table entry is: ```python 5000: 54.00, ``` However, `README.md:8` states that air-transport scenarios from 0 to 10000 meters are supported. ### Technical Analysis Atmospheric pressure decreases as altitude increases. The calculation uses the minimum pressure as the reference pressure and derives the flow coefficient as: ```python flow_coeff = volume_l / reference_pressure_kpa ``` Consequently, a lower pressure produces a higher required flow coefficient. Silently replacing every altitude above 5000 meters with the 5000-meter pressure of 54.00 kPa causes the calculation to use a pressure that is too high for the actual altitude. This lowers the computed breathing-flow requirement. The behavior is especially hazardous because no warning or out-of-range error is returned. The result appears to be a successful conversion and may be treated as valid by the agent or user. This contradicts the documented support for calculations through 10000 meters. ### Attack Path 1. A user supplies an air-transport altitude between 5000 and 10000 meters. 2. Following the documented workflow, the agent or caller invokes `altitude_to_pressure`. 3. The function detects that the altitude is above the largest table key. 4. Instead of calculating the corresponding pressure or rejecting the input, it returns 54.00 kPa, the pressure assigned to 5000 meters. 5. The inflated reference pressure reduces `volume_l / reference_pressure_kpa`. 6. ...[truncated 807 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description, feature list, and example invocation are written in Chinese and the example natural-language trigger is also Chinese, with no indication that other languages are supported. This can constitute a language/locale policy issue because the skill appears to require a specific language without explicit user opt-in or alternatives.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This manifest presents the skill name and primary descriptive content entirely in Chinese, while also including some English tags/triggers elsewhere. Because there is no explicit user opt-in, language selection, or justification that the skill is region-specific, this can violate the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The title and all instructional content are presented only in Chinese, with no indication that the skill supports other languages or lets the user opt in to this locale. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the regional constraint is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring and all user-facing CLI help text are written entirely in Chinese, which imposes a specific language on users. The file does not offer an opt-in language selection or explain that the tool is intentionally region- or locale-specific, so it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.