Back to skill

Security audit

manual-to-solution操作手册转解决方案

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its setup instructions ask users to install unpinned Python packages into the system Python environment using a protection-bypassing flag.

Review before installing. The document-conversion behavior is coherent, but run any setup in a dedicated virtual environment and avoid the provided --break-system-packages commands unless you intentionally want to modify the host Python environment. Confirm the Chinese-language templates and generated business assumptions fit your use case.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:95
Finding

Unpinned Third-Party Dependencies Installed Outside an Isolated Environment

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:95 and SKILL.md:125
Vulnerability Type: Unsafe dependency installation instructions
Risk Level: Medium

Vulnerable Code

At SKILL.md:95:

bash
pip install matplotlib --break-system-packages -q

At SKILL.md:125:

bash
pip install python-docx --break-system-packages -q

Technical Analysis

The Skill instructs users to install matplotlib and python-docx without pinned versions or cryptographic hashes. Package resolution therefore depends on mutable package-index state and the user's pip configuration at installation time.

The --break-system-packages option bypasses protections intended to prevent pip from modifying an externally managed Python installation. This can overwrite or conflict with operating-system-managed components and expands the consequences of a malicious or incompatible package installation.

No lockfile, hash-verified requirements file, isolated virtual environment, or explicitly approved package index is provided. The named packages are consistent with the scripts' imports, and the project does not itself retrieve a remote payload. Nevertheless, the documented installation process creates a supply-chain exposure because downloaded package artifacts and their installation behavior are not reproducibly constrained.

Attack Path

  1. A user follows the prerequisite instructions in SKILL.md.
  2. Pip resolves an unspecified current version using the user's configured package index or mirror.
  3. An attacker compromises the configured index, mirror, package release, or dependency-resolution environment.
  4. Pip downloads and installs the attacker-controlled artifact.
  5. Package installation behavior executes with the privileges of the user running pip.
  6. The project scripts subsequently import the installed dependency, allowing malicious import-time behavior to execute again.
  7. Because `--break-system-pac ...[truncated 856 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --break-system-packages and install dependencies inside a dedicated virtual environment:
    bash
    python3 -m venv .venv
    . .venv/bin/activate
    python -m pip install --upgrade pip
    
  2. Pin reviewed dependency versions in a requirements file:
    text
    matplotlib==REVIEWED_VERSION
    python-docx==REVIEWED_VERSION
    
  3. Generate and enforce cryptographic hashes:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  4. Include hashes for all transitive dependencies, preferably using a reproducible dependency-management tool.
  5. Use an explicitly approved package index or internal artifact repository rather than relying on arbitrary user-level pip configuration.
  6. Add automated dependency vulnerability, provenance, and license scanning to the release process.
  7. Run installation and document generation as a non-privileged account with minimal filesystem and network access.
  8. Document the supported Python and dependency versions and test updates before changing the pinned set.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes file reads and shell commands but does not declare any tool scope or permissions boundaries. In an agent environment, undeclared capabilities increase the chance of over-privileged execution, making it harder to enforce least privilege and easier for modified or future versions of the skill to run unintended commands.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed triggers include generic phrases such as "方案建议书 / solution proposal", "解决方案文档 / solution document", and "rewrite proposal", which are broad enough to match many ordinary document-authoring requests unrelated to converting manuals. The description does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation directs the agent/user to run package-installation and system-inspection shell commands, including pip install with --break-system-packages and font enumeration. Even if intended for setup, these commands modify the host environment and expand the skill's operational reach beyond simple document conversion, creating supply-chain, environment-integrity, and policy-bypass risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The document states that Chinese fonts should be present and positions English only as a fallback, implying a default Chinese-language output path rather than offering a user language choice. This can violate language/locale policy where users should be able to opt into a preferred language unless the constraint is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/generate_diagrams.py (reported line 157)May include surrounding context.

python
# 自动检测
        import subprocess
        try:
            result = subprocess.run(['fc-list', ':lang=zh'], capture_output=True, text=True)
            if 'Noto Sans CJK' in result.stdout:
                plt.rcParams['font.sans-serif'] = ['Noto Sans CJK SC']
            elif 'WenQuanYi' in result.stdout:

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructions and structure guidance solely in Chinese, which can constitute a language/locale policy issue when no user opt-in or justification is provided. The file does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains user-facing documentation and CLI help text only in Chinese, including the module docstring and usage examples. Under the stated policy, forcing a specific language without offering a choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s docstring, CLI description, and help text are presented entirely in Chinese, and the script is explicitly configured around Chinese fonts and Chinese output labels. Because the file does not offer a user language/locale choice or explain that it is intentionally region-specific, this is a natural-language locale policy concern under the stated rules.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill's stated purpose is converting manuals into solution proposals and generating supporting diagrams. While creating PNG diagrams is aligned with that purpose, invoking the external fc-list command via subprocess.run introduces process-execution capability that is not clearly justified by the manifest, especially since it is only used for optional font detection.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.