Back to skill

Security audit

人生岔路模拟栈

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Chinese life-choice report generator, but its bundled validation scripts can automatically read private report files outside the skill folder.

Review before installing. Use it only if you want a Chinese-language personal decision report generator, disable implicit invocation if your host allows it, and avoid running the bundled package validators in a workspace that contains private final-review reports until external-report validation is made explicit and opt-in.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/validate_html_first_skill.py:439
Finding

Validators Read Potentially Sensitive Life Reports Outside the Skill Directory

Content
View full analysis

Vulnerability Details

File Locations:

  • scripts/validate_html_first_skill.py:439-480
  • scripts/validate_magic_score.py:10-31
  • scripts/validate_magic_score.py:373-381
  • Automatically invoked through scripts/validate_skill_package.py:324-334

Vulnerability Type: Excessive filesystem read scope and undeclared cross-project data access
Risk Level: Medium

Vulnerable Code

scripts/validate_html_first_skill.py:439-480:

python
def validate_rendered_html(errors: list[str]) -> None:
    html_paths = sorted((ROOT.parents[1] / "final-review").glob("life-fork-*-user-report-*/report.html"))
    if not html_paths:
        return
    for path in html_paths:
        validate_html_document(path, path.read_text(encoding="utf-8"), errors)


def load_renderer():
    renderer_path = ROOT / "scripts" / "render_html_report.py"
    spec = importlib.util.spec_from_file_location("life_fork_render_html_report", renderer_path)
    if spec is None or spec.loader is None:
        raise RuntimeError(f"Unable to load renderer: {renderer_path}")
    module = importlib.util.module_from_spec(spec)
    spec.loader.exec_module(module)
    return module


def validate_fresh_rendered_html(errors: list[str]) -> None:
    package_fixtures = [
        ROOT / "examples" / "html-render-fixture.md",
    ]
    report_paths = [
        path
        for path in package_fixtures
        if path.is_file()
    ] + sorted((ROOT.parents[1] / "final-review").glob("life-fork-*-user-report-*/report.md"))
    if not report_paths:
        fail("missing markdown render fixture for fresh HTML validation", errors)
        return
    renderer = load_renderer()
    for path in report_paths:
        markdown_text = path.read_text(encoding="utf-8")
        title = renderer.infer_title(markdown_text, path.stem)
        rendered = renderer.build_html(markdown_text, title)
        validate_html_document(f"{path} 
...[truncated 4646 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic discovery of workspace-level reports from the default validators.
  2. Restrict normal package validation to fixtures stored under the resolved Skill root.
  3. Add an explicit optional argument, such as --final-review-dir, when external reports genuinely need validation.
  4. Require affirmative user selection of that option; do not derive the external directory through ROOT.parents.
  5. Resolve the supplied directory and validate that it is the exact user-authorized location before reading files.
  6. Separate package tests from private-report tests so validate_skill_package.py invokes only package-contained regression tests by default.
  7. Avoid including report content in error messages; report only the file path, failed rule, and non-sensitive metadata.
  8. Document the precise files and data categories read whenever external-report validation is enabled.
  9. Add a regression test confirming that default validation performs no reads outside the Skill root.
  10. Apply the same change consistently to both validate_html_first_skill.py and validate_magic_score.py.

A safer interface would resemble:

python
def external_report_paths(final_review_dir: Path | None) -> list[Path]:
    if final_review_dir is None:
        return []

    authorized = final_review_dir.expanduser().resolve()
    if not authorized.is_dir():
        raise ValueError("The explicitly supplied final-review directory is invalid")

    return sorted(
        authorized.glob("life-fork-*-user-report-*/report.md")
    )

The package validator should omit this option by default and use only examples/html-render-fixture.md.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bundling repository/package validation, filesystem scanning, subprocess-driven validators, and zip integrity checks inside a user-facing life-simulation skill expands the operational surface well beyond its stated purpose. If invoked in a privileged environment, those hidden maintenance behaviors could inspect unrelated local files or execute local commands under the guise of ordinary conversational assistance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Bundling repository/package validation, filesystem scanning, subprocess-driven validators, and zip integrity checks inside a user-facing life-simulation skill expands the operational surface well beyond its stated purpose. If invoked in a privileged environment, those hidden maintenance behaviors could inspect unrelated local files or execute local commands under the guise of ordinary conversational assistance.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Bundling repository/package validation, filesystem scanning, subprocess-driven validators, and zip integrity checks inside a user-facing life-simulation skill expands the operational surface well beyond its stated purpose. If invoked in a privileged environment, those hidden maintenance behaviors could inspect unrelated local files or execute local commands under the guise of ordinary conversational assistance.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/render_html_report.py (reported line 2915)May include surrounding context.

python
��份报告不能替你决定什么", "安全边界"]),
            "这份报告只帮你复盘和校准判断。它不会替你做搬迁、离职、婚恋、投资、医疗或法律决定。",
        ),
    ]
    details = [render_detail(title, content, intro) for title, content, intro in items]
    return '<section class="folded" id="details">' + "\n".join(item for item in details if item) + "<!-- developer quality record kept in source markdown -->" + "</section>"


def build_html(markdown_text: str, title: str) -> str:
    markdown_text = strip_internal_calibration(markdown_text)
    markdown_text = strip_developer_internal_sections(markdown_text)
    body_source = re.sub(r"^#\s+.+\n+", "", markdown_text, count=1)
    cover_fields, report_body_source = extract_cover_fields(body_source)
    verdict = cover_fields.get("判词") or cover_fields.get("命中句") or cover_fields.get("核心判断") or title
    hero_explain = cover_fields.get("看清") or cover_fields.get("核心判�

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire README is written as if the skill is to be used in Chinese, and all invocation examples and usage instructions are exclusively Chinese. Under the policy, language-specific behavior should either offer a user choice or clearly justify the locale constraint; neither is stated here.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill references file reads, file writes, shell execution, and script-based validation/rendering, but it does not declare any explicit tool scope or allowed-tools policy. That creates an unnecessary privilege boundary gap: a host may expose broad capabilities to a skill whose manifest does not clearly constrain when filesystem or shell access is permitted.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The mode B triggers include broad phrases such as “重大选择前帮我做压力测试” and “帮我看几个选项的好情况和坏情况,” which can match ordinary conversational requests outside a clearly bounded skill context. The file does not provide exclusion conditions or negative examples to clarify when these phrases should or should not invoke this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Mode C includes generic triggers like “帮我分析这个决策 bug” and “为什么我总在同一个地方卡住,” which are broad enough to overlap with many everyday requests about work, study, or debugging. Without tighter scoping language or negative examples, these triggers could cause unintended invocation of this specific skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The display name, description, and default prompt are all written in Chinese and direct generation of a Chinese user report, but the file provides no indication that this locale is optional or region-specific. That creates a natural-language policy concern because the skill appears to impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The default prompt is a fully formed natural-language invocation that eagerly instructs the system to use the skill and generate an HTML report without requiring a narrow trigger or explicit user confirmation. In environments with implicit invocation enabled, this increases the chance the skill is activated unintentionally or on weak semantic matches, which can cause unexpected tool execution and user-facing output generation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire skill file is written only in Chinese, including headings, instructions, and disclaimers, with no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy, a fixed language/locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file presents all user-facing prompts, instructions, and report content exclusively in Chinese. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains all user-facing descriptions, examples, and instructions in Chinese, and nowhere indicates that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains a natural-language instruction to '先跑中材料版本', which mandates a Chinese-language/material version. The file does not indicate any user choice, opt-in, or justified locale restriction, so it conflicts with the policy against forcing a specific language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown skill specifies all operating instructions, role definitions, and outputs in Chinese, which effectively forces a specific language for use. The file does not mention user opt-in, alternative language support, or a region-specific justification for this locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains instructional content exclusively in Chinese, aside from the bilingual title, and does not indicate that users may choose their preferred language. Under the policy rule for natural-language violations, forcing a specific language without opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The routing rules use broad trigger phrases like '如果当年…' and similar life-counterfactual prompts to force users into the Life Fork main flow without clear exclusions, tie-breakers, or consent checks. In an agent setting, this can cause prompt hijacking at the workflow level: unrelated or mixed-intent user requests may be redirected into a prescribed analysis path, producing incorrect handling, suppressing safer/default behavior, or causing the agent to ignore the user’s actual task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill file is written as mandatory Chinese-language operating instructions and does not indicate that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s operational instructions and examples are entirely in Chinese, which effectively forces a specific language for use of the skill. The policy allows fixed language only when the skill offers user opt-in or clearly documents a justified locale restriction, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s operational instructions and required output format are written entirely in Chinese and prescribe Chinese response content such as '人生原型' and '判词'. This imposes a specific language/locale on the skill behavior without offering the user a language choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document is written entirely in Chinese and all required output templates are specified in Chinese, effectively constraining the skill's behavior to a specific language. There is no indication that users may choose another language, nor any justification that the skill is intended only for a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s instructional content and examples are entirely in Chinese, which can impose a language requirement on users without any opt-in or alternative locale support. Under the policy, forcing a specific language is a natural-language policy violation unless the constraint is explicitly offered as a choice or justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The rubric content is written entirely in Chinese, including instructions and scoring output labels, and does not indicate that users may choose another language. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The onboarding flow explicitly asks for sensitive life details such as family relationships, health/energy status, finances, and potentially immigration or identity-related constraints, but the user-facing prompts shown here do not include any privacy notice, minimization guidance, retention statement, or caution against oversharing. In a conversational skill, this can lead users to disclose more sensitive personal data than necessary without informed consent or clear handling expectations, increasing privacy and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file is entirely written in Chinese and prescribes output behavior without any visible language choice, fallback, or opt-in. In a multi-user agent skill, this can exclude or mislead users who do not read Chinese, causing incorrect use of the rubric and reducing transparency about how outputs are evaluated or rewritten.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/validate_html_first_skill.py:453