Back to skill

Security audit

PRD GENERATOR - Interactive Demo & iWiki Publish

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent PRD generator, but its iWiki publishing setup grants broad authenticated document authority and handles tokens in a risky persistent way.

Review this before installing if you will use iWiki publishing. Use a narrowly scoped, revocable token, avoid putting it in ~/.bashrc, and confirm the exact project directory, parent page ID, and overwrite mode before any upload. Treat connect_mcp.py as a broad iWiki client, not just a PRD publisher.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:741
Finding

Overbroad Trigger Rules Can Redirect Benign Requests into the Publishing Workflow

Content
View full analysis
🚫 **绝对禁止**: > - ❌ 任何不经过 `publish_to_iwiki.py` 的上传方式(包括手动调用 connect_mcp.py、手动上传.md文件) > - ❌ 使用 base64 内嵌图片(见顶部§核心约束速览) > - ❌ 跳过 Step 7.0 前置检查直接上传 > - ❌ 凭记忆执行发布,不回读本章节 ``` ### Technical Analysis The Skill declares publishing-related words as highest-priority triggers and states that the agent must execute one specific publishing command. The matching rule is substring-based and lacks an explicit intent check. Consequently, benign requests such as discussing an upload failure, asking what “publish” means, or requesting a security review of publishing behavior can be redirected into the iWiki publication workflow. This is instruction hijacking because loading the Skill introduces instructions that supersede the agent's current task-selection logic and force a network-capable action based on broad keywords. Although later portions of the document describe pre-publication checks, the highest-priority language and “only permitted action” create conflicting instructions. The safer checks are therefore not reliably guaranteed to run before the command. The publishing script defaults to non-overwrite mode, which reduces destructive impact, but it can still create a new remote page and transmit project contents. ### Attack Path 1. The Skill is enabled in an agent session with filesystem and network permissions. 2. A message contains any listed substring, such as `upload` or `publish`, even when the user is not authorizing publication. 3. The highest-priority routing instruction redirects th ...[truncated 913 chars]
Remediation
View remediation
`. 2. Never treat generic words such as `upload` or `publish` as sufficient authorization. 3. Require a confirmation immediately before any network operation. Display: - The exact local project directory. - The selected Markdown file. - The number and names of images. - The destination service and parent page ID. - Whether a page will be created or overwritten. 4. Separate preparation from execution: - First run `--dry-run`. - Show the resulting manifest. - Only upload after a distinct user confirmation. 5. Remove language claiming precedence “over everything” or identifying a single mandatory action. Skill instructions must remain subordinate to the current user request and platform safety requirements. 6. Require explicit confirmation for every `--cover` operation and reject inferred overwrite authorization. 7. Add a machine-enforced `--confirm-publish` flag or confirmation token so documentation-only safeguards cannot be skipped by the agent. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/connect_mcp.py:145
Finding

Generic MCP Client Exposes Capabilities Beyond the Declared PRD Publishing Function

Content
View full analysis
dict: if arguments is None: arguments = {} return self._send_request( "tools/call", { "name": tool_name, "arguments": arguments } ) ``` The command-line interface accepts a server-provided tool name and caller-controlled JSON arguments: ```python tool_name = sys.argv[2] args = parse_tool_args(sys.argv[3:]) ... result = client.call_tool(tool_name, args) ``` ### Technical Analysis Sending a bearer token over HTTPS to the fixed iWiki MCP endpoint is necessary for the declared publication feature and is not, by itself, unauthorized exfiltration. The least-privilege issue is that `connect_mcp.py` is a general-purpose MCP client rather than a narrowly scoped publisher. It can enumerate server tools and invoke any tool exposed by the remote MCP server using arbitrary JSON arguments. Its own documentation identifies read, create, update, search, metadata, and file-import functionality. The declared Skill functionality only requires packaging and publishing a PRD, plus narrowly scoped post-upload image adjustment. There is no local allowlist restricting calls to the minimal operations used by `publish_to_iwiki.py`, such as `getDocument`, `metadata`, and `saveDocument`. There is also no operation-level confirmation fo ...[truncated 1431 chars]
Remediation
View remediation
`, abbreviated tool invocation, interactive arbitrary calls, and caller-supplied tool names. 4. Separate read-only and write-capable operations into different code paths and require explicit confirmation for write operations. 5. Validate every argument against a local schema before transmission: - Numeric document IDs. - Expected parent page ID. - Maximum body length. - Allowed task type. 6. Restrict upload paths to the selected PRD project directory and permit only generated ZIP archives. 7. Require the narrowest available PAT scope. Documentation should not suggest selecting “all applications.” 8. Consider using separate short-lived credentials for publishing rather than a broadly scoped personal token. 9. Log operation names and destination IDs, but redact tokens and sensitive document bodies. 10. Add tests proving that unknown or newly introduced server tools cannot be invoked without a reviewed client update. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:124
Finding

Documentation Persists the Personal Access Token in Plaintext Shell Startup Files

Content
View full analysis
> ~/.bashrc && source ~/.bashrc ``` ``` The same practice is repeated in `guide.md`, lines 16-21: ```bash echo 'export TAI_PAT_TOKEN="你的token"' >> ~/.bashrc && source ~/.bashrc ``` ### Technical Analysis The recommended command writes the PAT as plaintext into `~/.bashrc`, making the credential persist across sessions. Shell startup files are commonly read by interactive shells, development environments, support tooling, backup software, and any process running as the same operating-system user. The recommended verification command, `echo $TAI_PAT_TOKEN`, also prints the complete secret to the terminal. It may consequently be captured in terminal scrollback, screen recordings, support logs, or automated agent transcripts. Using an environment variable for a single process is a conventional credential-transfer mechanism. The vulnerability is the recommendation to persist the raw token in a general-purpose shell configuration file and print it in full. ### Attack Path 1. A user follows the setup instructions and appends the PAT to `~/.bashrc`. 2. The plaintext token remains on disk across reboots and Skill sessions. 3. Another process, extension, agent, backup job, or user with read access to the account's files reads `~/.bashrc`. 4. The token is extracted and replayed against the iWiki MCP endpoint. 5. The attacker performs any iWiki operation authorized by the PAT until the credential expires or is revoked. A secondary path is disclosure through `echo $TAI_PAT_TOK ...[truncated 616 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned Runtime and Browser Dependencies Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (90)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a PRD generator, but its instructions also include broader remote iWiki/MCP operations and publishing behavior. That mismatch can mislead users about what the skill will do, increasing the risk of unintended network actions and content publication under over-broad trust assumptions.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
- `{PRD_DIR}` = PRD输出根目录(= `{WORKSPACE}/.codebuddy/docs/prd`)
- `{PORT}` = PRD预览服务端口(默认8888,如被占用自动+1,详见 Step 5 端口检测逻辑)

<!-- 内置脚本版本:gen_flowmap.py v5.0 / publish_to_iwiki.py v1.2 / connect_mcp.py -->

## 内置依赖

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
- `{PRD_DIR}` = PRD输出根目录(= `{WORKSPACE}/.codebuddy/docs/prd`)
- `{PORT}` = PRD预览服务端口(默认8888,如被占用自动+1,详见 Step 5 端口检测逻辑)

<!-- 内置脚本版本:gen_flowmap.py v5.0 / publish_to_iwiki.py v1.2 / connect_mcp.py -->

## 内置依赖

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

Appending an export command to ~/.bashrc persists a credential in the user's shell profile, increasing the blast radius if the account or home directory is later compromised. While this is framed as setup guidance rather than an active payload, persistence of long-lived tokens in profile files is risky and can normalize insecure secret handling.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
_TOKEN`
   - 非空 → ✅ iWiki 发布就绪
   - 为空 → 输出以下引导(**不阻断 PRD 生成**):
     ```
     ⚠️ 未检测到 iWiki 发布配置。如需使用「发布到iWiki」功能,请完成以下一次性配置:
     1. 登录 太湖个人令牌 https://tai.it.woa.com/user/pat
     2. 创建 API Token,选择「iWiki官方MCP」权限
     3. 配置环境变量:echo 'export TAI_PAT_TOKEN="你的token"' >> ~/.bashrc && source ~/.bashrc
     
     💡 不配置 Token 不影响 PRD 生成和原型预览,仅影响 iWiki 发布功能。
     ```

> **预计生成耗时提示**:环境检测通过后,在 Step 1 确认单用户回复"确认"时,根据页面数量动态计算预估耗时并输出提示:
> - **耗时公式**:`基础2分钟 + 页面数 × 1.2分钟`(例如:3个页面≈6分钟,8个页面≈12分钟)
> - **输出格式**:"🚀 开始生成,预计耗时约 {N} 分钟({页面数}个页面),请稍候..."
> - 如果页

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
| 注释类型 | 格式 | 处理方式 |
|---------|------|---------|
| **AI指引** | `<!-- AI_INSTRUCTION: xxx -->` | 仅供AI参考,**生成最终PRD时删除**,不出现在产出物中 |
| **截图占位** | `<!-- SCREENSHOT_PLACEHOLDER: ![xxx](images/xxx.png) -->` | Step 5 截图完成后,用 `replace_in_file` 将整行注释**替换为**注释内的 `![xxx](images/xxx.png)` |

**硬规则**:最终PRD文档中不允许出现任何 `AI_INSTRUCTION` 或 `SCREENSHOT_PLACEHOLDER` 注释。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
| 注释类型 | 格式 | 处理方式 |
|---------|------|---------|
| **AI指引** | `<!-- AI_INSTRUCTION: xxx -->` | 仅供AI参考,**生成最终PRD时删除**,不出现在产出物中 |
| **截图占位** | `<!-- SCREENSHOT_PLACEHOLDER: ![xxx](images/xxx.png) -->` | Step 5 截图完成后,用 `replace_in_file` 将整行注释**替换为**注释内的 `![xxx](images/xxx.png)` |

**硬规则**:最终PRD文档中不允许出现任何 `AI_INSTRUCTION` 或 `SCREENSHOT_PLACEHOLDER` 注释。

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
...
     
     #### 3.x.6 页面交互说明 — {页面B名称}
     <!-- SCREENSHOT_PLACEHOLDER: ![{页面B}](images/{页面B}.png) -->
     | 元素 | 类型 | 说明 |
     ...
     ```

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
...
     
     #### 3.x.6 页面交互说明 — {页面B名称}
     <!-- SCREENSHOT_PLACEHOLDER: ![{页面B}](images/{页面B}.png) -->
     | 元素 | 类型 | 说明 |
     ...
     ```

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 432)May include surrounding context.

text
9. **截图回填PRD文档(关键步骤 — 批量化执行)**:截图完成后,**批量**将截图插入PRD文档对应位置:
   - **批量回填策略**:先用 `grep -n 'SCREENSHOT_PLACEHOLDER' {PRD文件}` 一次列出所有待替换行,然后集中执行 `replace_in_file`(多个相邻占位符合并为一次调用),减少逐个替换的调用开销
   - **页面截图**:用 `replace_in_file` 将每个模块中的 `<!-- SCREENSHOT_PLACEHOLDER: ![{页面名}](images/{页面名}.png) -->` 替换为 `![{页面名}](images/{页面名}.png)`
   - **页面流程图**:用 `replace_in_file` 将 3.0 章节中的 `<!-- SCREENSHOT_PLACEHOLDER: ![整体页面流程图](images/page-flow-map.png) -->` 替换为 `![整体页面流程图](images/page-flow-map.png)`
   - **必须使用 Markdown `![]()` 语法**,禁止使用 HTML `<img>` 标签

Static analysis

No suspicious patterns detected.