Back to skill

Security audit

Business Blueprint Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local business-blueprint generator with disclosed artifact creation and local logs, but users should treat its source install path and retained business inputs carefully.

Install only from a source and commit/release you trust, preferably after verifying a pinned commit or release digest. Run it in a virtual environment or sandbox with only the project files it needs, and remember that generated blueprint, viewer, projection, prompt-audit, and patch-log files may retain confidential meeting notes or RFP content until you delete them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:59
Finding

Unverified installation from a personal source repository

Content
View full analysis

Vulnerability Details

File Location: README.md:59-80; duplicated installation guidance appears in README.zh-CN.md:59-80, with the release URL also documented in evals/skill-eval-implementation-plan.md:211-215
Vulnerability Type: Unverified third-party source and release installation
Risk Level: Medium

Vulnerable Code

markdown
## Install

### Download

Current release: **v0.16.2**

- Release page: <https://github.com/kaisersong/kai-business-blueprint/releases/tag/v0.16.2>
- Direct zip: <https://github.com/kaisersong/kai-business-blueprint/releases/download/v0.16.2/kai-business-blueprint-v0.16.2.zip>

### Claude Code

```bash
git clone https://github.com/kaisersong/kai-business-blueprint ~/.claude/skills/kai-business-blueprint

Then: cd kai-business-blueprint && pip install -e .

OpenClaw

bash
git clone https://github.com/kaisersong/kai-business-blueprint ~/.openclaw/skills/kai-business-blueprint
cd kai-business-blueprint && pip install -e .
text

The evaluation plan separately distributes the same unverified archive:

```markdown
- <https://github.com/kaisersong/kai-business-blueprint/releases/tag/v0.16.2>
- <https://github.com/kaisersong/kai-business-blueprint/releases/download/v0.16.2/kai-business-blueprint-v0.16.2.zip>

Technical Analysis

The installation instructions direct users to clone a repository or download a release archive from an individual GitHub namespace and then install the resulting source in editable mode. No cryptographic checksum, signed release attestation, verified commit identifier, or reproducible-build verification is provided.

A versioned HTTPS GitHub URL protects transport integrity but does not protect against compromise of the publisher account, repository, release artifacts, or tag. A tag can also be moved unless independently pinned and verified. Editable installation additionall ...[truncated 2168 chars]

Remediation
View remediation

Remediation Suggestions

  1. Publish a SHA-256 or stronger digest for every release archive through an independently protected channel.
  2. Sign release artifacts and tags using Sigstore, GitHub artifact attestations, or a protected signing key, and document mandatory verification commands.
  3. Pin clone-based installation to a full reviewed commit SHA rather than relying only on a mutable branch or tag.
  4. Protect release tags against deletion or movement and require reviewed, reproducible release workflows.
  5. Prefer an immutable, verified package distribution with locked dependency hashes if package installation is genuinely required.
  6. Remove pip install -e . from end-user instructions if the bundled scripts can run without installation. Editable installs unnecessarily preserve trust in mutable working-tree content.
  7. Provide verification instructions such as:
bash
sha256sum kai-business-blueprint-v0.16.2.zip
# Compare against the independently published expected digest before extraction.

git clone https://github.com/kaisersong/kai-business-blueprint
cd kai-business-blueprint
git checkout --detach <reviewed-full-commit-sha>
git verify-tag v0.16.2
  1. Apply the same hardened installation guidance consistently in README.md, README.zh-CN.md, and evals/skill-eval-implementation-plan.md.
  2. Advise users to install and run the Skill in a least-privileged virtual environment or sandbox without unnecessary credentials or filesystem access.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (172)

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The design document is written entirely in Chinese while directing agent behavior and workflow, which effectively imposes a language choice without offering user selection or documenting a justified locale restriction. This can violate language/locale policy when the skill is used in multilingual environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The design document is written in Chinese and instructive content appears to assume that language without any opt-in, alternative locale, or region-specific justification. Under the language policy rule, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Unvalidated Output Injection

High
Category
Output Handling
Confidence
85% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · reports/validate.report.md (reported line 142)May include surrounding context.

md
| R73 | block | `scripts/tests/test_exporters.py` | scripts/tests/test_exporters.py: http://www.w3.org |
| R73 | block | `scripts/tests/test_visual_enhancement.py` | scripts/tests/test_visual_enhancement.py: https://fonts |
| R73 | block | `scripts/tests/test_visual_enhancement.py` | scripts/tests/test_visual_enhancement.py: https://fonts |
| R75 | block | `scripts/business_blueprint/tests/test_utils.py` | scripts/business_blueprint/tests/test_utils.py: subprocess.run( |
| R75 | block | `scripts/tests/test_cli_cross_platform.py` | scripts/tests/test_cli_cross_platform.py: subprocess.run( |
| R75 | block | `scripts/tests/test_cli_smoke.py` | scripts/tests/test_cli_smoke.py: subprocess.run( |
| R75 | block | `scripts/tests/test_e2e.py` | scripts/tests/test_e2e.py: subprocess.run( |

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/business_blueprint/prompt_generator.py (reported line 61)May include surrounding context.

python
encoding="utf-8",
    )

    return prompt_path


def _build_content(

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/tests/test_generate.py (reported line 21)May include surrounding context.

python
)
    output = tmp_path / "solution.blueprint.json"

    result = subprocess.run(
        [sys.executable, "-m", "business_blueprint.cli",
         "--plan", str(output), "--from", str(source), "--industry", "retail"],
        cwd=ROOT, capture_output=True, text=True,

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/tests/test_generate.py (reported line 44)May include surrounding context.

python
def test_plan_requires_source_text(tmp_path: Path) -> None:
    """--plan without --from should fail."""
    output = tmp_path / "solution.blueprint.json"
    result = subprocess.run(
        [sys.executable, "-m", "business_blueprint.cli",
         "--plan", str(output), "--industry", "retail"],
        cwd=ROOT, capture_output=True, text=True,

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The README explicitly states that edits are logged to a persistent local file (solution.patch.jsonl), and the tool is designed to ingest potentially sensitive business materials such as meeting notes, RFPs, and requirements. That creates a real confidentiality risk: sensitive content, revisions, and operator actions may remain on disk longer than expected and could be exposed to other local users, backups, or downstream tooling.

Content

Scanner excerpt · README.md (reported line 53)May include surrounding context.

md
### 3. Silicon-Carbon Collaboration

**Input:** Humans write natural language (requirements, meeting notes, RFPs). AI parses into structured entities (Application Systems, Business Capabilities, Process Flows, Actors) and relations.

**Output:** The viewer is a static HTML page — no build step, no JS framework, works offline. Every node is editable in-place, and edits are logged as a JSON patch trail (`solution.patch.jsonl`) for full traceability.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

该文件在语言切换处将当前文档固定为“简体中文”,且全文内容默认以中文提供,没有在文档中说明这是可选语言偏好或仅面向特定区域用户。根据规则,若技能在自然语言层面强制特定语言而未提供用户选择,可构成语言/区域策略违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description lists several trigger phrases in Chinese alongside English phrases, but the skill does not state whether users may invoke it in other languages or that it is intentionally scoped to a Chinese-language workflow. Under the policy, forcing or biasing toward a specific language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON file contains natural-language business requirements entirely in Chinese and presents Chinese-titled views and labels throughout, but it does not indicate that the skill is region-specific or that users can opt into this locale. Under the policy, forcing a specific language without user choice or justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest is a non-region-specific manufacturing blueprint, but the source excerpt and nearly all user-visible names and descriptions are written only in Chinese. That imposes a specific language/locale on downstream users without offering choice or documenting why the locale restriction is required.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The query "帮我画一个微服务架构图" is a broad, everyday request that can plausibly appear in many contexts, so using it as a direct routing trigger risks sending users into kai-business-blueprint when they may have intended another design, diagramming, or reporting workflow. In this file, the expected behavior explicitly binds that generic phrase to a specific skill route, which can cause unintended tool selection and downstream overreach in file reads, template loading, or transformation steps.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The English phrase "Create a strategy canvas showing our competitive advantages" is generic business language and the test expects it to route to kai-business-blueprint instead of another plausible skill such as a report or presentation generator. Because the file codifies this broad trigger without clear routing constraints, normal user requests may be misclassified, leading to unintended skill activation and potentially incorrect data handling or output generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains core operational content in Chinese starting at L011, and the rest of the plan continues primarily in Chinese, without indicating that users may choose their preferred language. The policy for this audit flags natural-language locale constraints when a skill or skill-related document effectively forces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt requires output in Chinese without giving the user any language choice or opt-in, which can override user preferences and reduce usability or accessibility for non-Chinese-speaking users. In a security-sensitive workflow, forced language can also hinder review, auditing, or operator understanding of generated artifacts, increasing the chance of oversight.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prompt is written as a direct instruction in Chinese and does not provide any user opt-in or alternative language handling. Under the language/locale policy rule, forcing a specific language without choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction is written as a direct mandate in Chinese to produce a weekly report, which implies a fixed language/locale for the skill output. There is no indication that the user can choose another language or that the Chinese-only requirement is justified by a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L003 states the document defines the system for agent-generated architecture diagrams and does so entirely in Chinese, effectively imposing a language/locale constraint on the skill's output conventions. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger section uses broad keywords for activating architecture generation without documenting exclusions, scope checks, or confirmation gates. In an agent skill, overly broad triggers can cause unintended activation on unrelated user requests, increasing the chance the model reads auxiliary files, performs file-writing behavior, or overrides the user's intended workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file is predominantly written in Chinese, including section headings and instructions, with no indication that users may choose another language or that the template is intentionally limited to a Chinese-speaking audience. This creates a natural-language policy concern because it implicitly enforces a locale/language without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger condition is broad and based on generic keywords like Lambda, API Gateway, DynamoDB, Serverless, and 无服务器, which can cause this template to activate for many unrelated AWS discussions. That increases the chance of incorrect skill routing or unintended template application, which can mislead downstream outputs and reduce trust in generated architecture artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document states that Claude generates HTML+SVG text and writes it to a file, but it does not require any user-facing notice or consent about filesystem modification. Silent writes are risky in agent workflows because they can surprise users, overwrite expected outputs, or create artifacts in locations the user did not explicitly approve.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The proposed SKILL.md trigger uses broad keywords such as architecture diagram, 架构图, and --export without documented scope limits, confirmation steps, or exclusions. In an agent setting, this can cause the skill to activate on ambiguous requests and perform unintended generation or follow-on actions, especially when paired with later file-writing behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This workflow explicitly directs the agent to generate HTML+SVG and write a {stem}.html file as a follow-up step, again without any warning, consent, or overwrite protections. Because the design assumes the agent will continue operating after tool execution, the risk is heightened: an automatically triggered skill could create files as a side effect of routine export operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The proposed intent-detection logic relies on broad keyword matching to decide whether the skill produces an architecture blueprint, a domain-knowledge graph, or a hybrid output. In an agent setting, ambiguous triggers can cause the wrong processing path to activate, leading to over-collection, misclassification, or unintended inclusion of business-strategy content when the user did not clearly request it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.