Back to skill

Security audit

Business Blueprint Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local blueprint generator, but a crafted blueprint can inject JavaScript into its generated HTML viewer.

Install only if you are comfortable reviewing or fixing the generated viewer before opening blueprints from untrusted sources. Avoid generating/opening HTML viewers for third-party blueprint JSON until entity IDs are validated or escaped correctly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/business_blueprint/assets/viewer.html:431
Finding

Stored HTML Attribute Injection in Generated Blueprint Viewer

Content
View full analysis
${kindLabel(kind)}
${esc(entity.name || entity.id)}
${desc ? `
${esc(desc.substring(0, 80))}
` : ""} ${links ? `
${links}
` : ""} `; } function kindLabel(kind) { const labels = { capability: "Capability", system: "System", actor: "Actor", flowStep: "Flow Step" }; return labels[kind] || kind; } function buildLinksHtml(entity, kind) { const parts = []; if (entity.capabilityIds?.length) parts.push(...entity.capabilityIds.map(id => `${esc(id)}`)); if (entity.supportingSystemIds?.length) parts.push(...entity.supportingSystemIds.map(id => `${esc(id)}`)); if (entity.ownerActorIds?.length) parts.push(...entity.ownerActorIds.map(id => `${esc(id)}`)); return parts.join(""); } function esc(str) { const div = document.createElement("div"); div.textContent = str; return div.innerHTML; } // ── Node selection → detail panel ────────────────────── function selectNode(id) { selectedNodeId = id; document.querySelectorAll(".node-card").forEach(c => c.classList.remove("selected")); document.querySelector(`.node-card[data-id="${id}"]`)?.classList.add("selected"); ``` ### Technical Analysis Blueprint entity identifiers are inserted directly into the `data-id` HTML attribute: ```javascript data-id="${entity.id}" ``` Unlike entity names, descriptions, and related ide ...[truncated 2717 chars]
Remediation
View remediation
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (149)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · REFACTOR_SUMMARY.md (reported line 183)May include surrounding context.

md
- business_blueprint/specs/ → business_blueprint/renderers/ (Python module)
- business_blueprint/specs/*.md → business_blueprint/docs/ (documentation)
- Update import paths in export_drawio.py, export_excalidraw.py
- Update SKILL.md references to docs/

All tests pass (173 passed, 1 skipped)
"

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

If the skill’s effective behavior includes batch filesystem traversal and in-place modification of Python files, that materially expands risk beyond blueprint generation. In a skill already encouraging script execution, undocumented repository-wide refactoring behavior can lead to unintended code modification, supply-chain integrity issues, or corruption of unrelated files if invoked implicitly or by prompt confusion.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prompt instructs the LLM that delete operations are cascading and should also remove relations referencing the deleted entity, but the supplied patcher implementation only deletes the addressed path. This mismatch can leave dangling references and inconsistent blueprint state, which is dangerous because an untrusted LLM can emit diffs that the system assumes are safe and complete, potentially causing broken validation, corrupted artifacts, or downstream processing failures.

Content

No source excerpt is available for this finding.

Unvalidated Output Injection

High
Category
Output Handling
Confidence
85% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · reports/validate.report.md (reported line 142)May include surrounding context.

md
| R73 | block | `scripts/tests/test_exporters.py` | scripts/tests/test_exporters.py: http://www.w3.org |
| R73 | block | `scripts/tests/test_visual_enhancement.py` | scripts/tests/test_visual_enhancement.py: https://fonts |
| R73 | block | `scripts/tests/test_visual_enhancement.py` | scripts/tests/test_visual_enhancement.py: https://fonts |
| R75 | block | `scripts/business_blueprint/tests/test_utils.py` | scripts/business_blueprint/tests/test_utils.py: subprocess.run( |
| R75 | block | `scripts/tests/test_cli_cross_platform.py` | scripts/tests/test_cli_cross_platform.py: subprocess.run( |
| R75 | block | `scripts/tests/test_cli_smoke.py` | scripts/tests/test_cli_smoke.py: subprocess.run( |
| R75 | block | `scripts/tests/test_e2e.py` | scripts/tests/test_e2e.py: subprocess.run( |

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/business_blueprint/prompt_generator.py (reported line 59)May include surrounding context.

python
encoding="utf-8",
    )

    return prompt_path


def _build_content(

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/tests/test_generate.py (reported line 21)May include surrounding context.

python
)
    output = tmp_path / "solution.blueprint.json"

    result = subprocess.run(
        [sys.executable, "-m", "business_blueprint.cli",
         "--plan", str(output), "--from", str(source), "--industry", "retail"],
        cwd=ROOT, capture_output=True, text=True,

Unvalidated Output Injection

High
Category
Output Handling
Confidence
95% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · scripts/tests/test_generate.py (reported line 42)May include surrounding context.

python
def test_plan_requires_source_text(tmp_path: Path) -> None:
    """--plan without --from should fail."""
    output = tmp_path / "solution.blueprint.json"
    result = subprocess.run(
        [sys.executable, "-m", "business_blueprint.cli",
         "--plan", str(output), "--industry", "retail"],
        cwd=ROOT, capture_output=True, text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is written entirely in Chinese and does not indicate that other languages are supported or that Chinese is a required locale for a region-specific purpose. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 53)May include surrounding context.

md
### 3. Silicon-Carbon Collaboration

**Input:** Humans write natural language (requirements, meeting notes, RFPs). AI parses into structured entities (Application Systems, Business Capabilities, Process Flows, Actors) and relations.

**Output:** The viewer is a static HTML page — no build step, no JS framework, works offline. Every node is editable in-place, and edits are logged as a JSON patch trail (`solution.patch.jsonl`) for full traceability.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

该文件是中文 README,且在语言切换处仅标示“English | 简体中文”,当前文档整体以简体中文固定呈现,没有在技能说明中说明用户可自行选择输出语言,或该技能为何必须使用特定语言/区域设置。按规则,未获用户选择或无明确正当理由的语言/locale 强制属于自然语言策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.