Back to skill

Security audit

AGI数字伙伴

Security checks for vulnerabilities and agentic risk

Overview

This skill is a broadly triggered AGI companion that also exposes powerful local filesystem, process, environment, and shell-command capabilities without tight scoping or approval gates.

Install only if you intentionally want this skill to act as a local system tool. Treat it as capable of reading, changing, or deleting files, exposing environment secrets, killing processes, and running shell commands. Use it in a disposable or sandboxed workspace unless you can add strict path limits, command allowlists, and explicit approval for destructive actions.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The exec.run path executes attacker-controlled input via sh -c or cmd /C, which enables arbitrary shell command execution. The blacklist-based _is_dangerous filter is incomplete and easily bypassed with alternate syntax, encoding, indirection, separators, or benign-looking commands that still exfiltrate data or modify the system.

Content

Scanner excerpt · scripts/busybox_fallback.py (reported line 377)May include surrounding context.

python
shell = "cmd" if os.name == "nt" else "sh"
    flag = "/C" if os.name == "nt" else "-c"
    try:
        cp = subprocess.run(
            [shell, flag, cmd],
            capture_output=True, timeout=timeout,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

The code builds a Python program as a string and executes it in a child interpreter via python -c. Although subprocess.run is invoked without shell=True, the executed script embeds attacker-influenced values (base_dir, module_name, symbol names, probe function and arguments) and then imports and calls a dynamically loaded extension. This creates a code-execution pathway and expands the attack surface to arbitrary native-module loading and execution in a subprocess.

Content

Scanner excerpt · scripts/c_ext_loader.py (reported line 96)May include surrounding context.

python
kw=pkwargs,
    )
    try:
        proc = subprocess.run(
            [sys.executable, "-c", script],
            capture_output=True,
            timeout=15,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
86% confidence
Finding

This code routes toolnode execution through subprocess using user-influenced params serialized into a child process invocation that exposes powerful fs/sys/proc/exec capabilities. Even though shell=True is not used, this still creates a high-risk execution boundary because the skill context is a general-purpose agent tool runner, and unsafe downstream operations can be triggered through this interface if the called backend is insufficiently constrained.

Content

Scanner excerpt · scripts/perception_node.py (reported line 896)May include surrounding context.

python
# —— 子进程调用:spawn 失败/超时视为能力层崩溃,转保命层 ——
        try:
            proc = subprocess.run(cmd, capture_output=True, timeout=120)
        except (subprocess.TimeoutExpired, OSError) as e:
            logger.warning("[toolnode] capability layer crashed (%s: %s), falling back to BusyBox (trace=%s)",
                           type(e).__name__, e, trace_id)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

This path executes a user-supplied command with shell=True, which enables arbitrary command execution through the skill interface. The blacklist is incomplete and easily bypassed, so an attacker can run destructive commands, exfiltrate data, or establish persistence using syntax not matched by the patterns.

Content

Scanner excerpt · scripts/toolnode.py (reported line 531)May include surrounding context.

python
timeout = params.get("timeout", 60)
        cwd = params.get("cwd")
        try:
            proc = subprocess.run(cmd, shell=True, capture_output=True,
                                   timeout=timeout, cwd=cwd)
            stdout = _decode(proc.stdout)
            stderr = _decode(proc.stderr)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
87% confidence
Finding

This capability allows callers to terminate arbitrary processes via taskkill/os.kill with no authorization checks or target restrictions. In an agent skill that can be triggered broadly, this creates a denial-of-service primitive against local services, security tools, or other user processes.

Content

Scanner excerpt · scripts/toolnode.py (reported line 505)May include surrounding context.

python
sig = params.get("signal", 15)
        try:
            if sys.platform.startswith("win"):
                subprocess.run(["taskkill", "/PID", str(pid), "/F"], capture_output=True, timeout=10)
            else:
                os.kill(pid, sig)
            return {"pid": pid, "killed": True}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill exposes shell execution, file read/write, and environment access while declaring no permissions, which breaks least-privilege expectations and hides its true attack surface from reviewers and users. In a skill that can be triggered by 'any user question,' these capabilities materially increase the risk of unauthorized command execution, data exfiltration, or filesystem tampering if the implementation follows this specification.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented purpose presents the skill as a general conversational/AGI companion, but the behavior includes broad operational powers: filesystem manipulation, process inspection/termination, system information collection, and command execution. That mismatch is dangerous because it can socially legitimize a highly privileged agent under an innocuous description, especially when the skill states that any user query can trigger it, expanding the chance of unintended or abusive invocation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This example performs outbound HTTP requests to a caller-supplied server_url without any validation, allowlisting, or transport-security constraints. In a real implementation, that can enable SSRF-style access to internal services or unintended data egress to attacker-controlled endpoints, especially because this skill is centered on dynamic tool discovery and external integration.

Content

Scanner excerpt · _deprecated_backup/tool_use_spec.md (reported line 1438)May include surrounding context.

md
async def register_server(self, server_url: str):
        """注册 MCP Server"""
        # 连接服务器
        response = await requests.post(
            f"{server_url}/tools/list",
            json={}
        )

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This code sends tool invocation data to whatever server_url was previously registered, creating a second-stage egress path for parameters and potentially sensitive workflow context. If an attacker can influence server registration or tool routing, they can exfiltrate data or pivot requests into internal network targets via the MCP call endpoint.

Content

Scanner excerpt · _deprecated_backup/tool_use_spec.md (reported line 1461)May include surrounding context.

md
server_url = self.servers[tool_name]
        
        response = await requests.post(
            f"{server_url}/tools/call",
            json={
                "name": tool_name,

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
98% confidence
Finding

The sys.env operation exposes environment variable values on demand and enumerates environment keys. In practice, environment variables frequently contain API keys, tokens, secrets, proxy credentials, and internal configuration, so this is a direct secret-disclosure mechanism.

Content

Scanner excerpt · scripts/toolnode.py (reported line 431)May include surrounding context.

python
if op == "env":
        key = params.get("key")
        if key:
            return {"key": key, "value": os.environ.get(key)}
        return {"count": len(os.environ), "sample_keys": list(os.environ.keys())[:20]}
    if op == "all":
        return {

Unvalidated Output Injection

High
Category
Output Handling
Confidence
97% confidence
Finding

This code captures and returns stdout/stderr from arbitrary commands launched from user input, which can expose sensitive local data or terminal-control content to upstream components. In combination with generic shell execution, it becomes a powerful exfiltration primitive and amplifies the severity of the command-execution issue.

Content

Scanner excerpt · scripts/busybox_fallback.py (reported line 377)May include surrounding context.

python
shell = "cmd" if os.name == "nt" else "sh"
    flag = "/C" if os.name == "nt" else "-c"
    try:
        cp = subprocess.run(
            [shell, flag, cmd],
            capture_output=True, timeout=timeout,
        )

Unvalidated Output Injection

High
Category
Output Handling
Confidence
81% confidence
Finding

This is a true issue because untrusted data is interpolated into a Python code string that is later executed by sys.executable -c. The use of {...!r} reduces trivial string-breaking injection, but it does not eliminate the core risk: attacker-controlled values can still drive dangerous behavior inside the generated program, including importing this loader from a manipulated sys.path, loading arbitrary .so/.pyd files from attacker-controlled locations, and invoking chosen exported functions.

Content

Scanner excerpt · scripts/c_ext_loader.py (reported line 96)May include surrounding context.

python
kw=pkwargs,
    )
    try:
        proc = subprocess.run(
            [sys.executable, "-c", script],
            capture_output=True,
            timeout=15,

Unvalidated Output Injection

High
Category
Output Handling
Confidence
82% confidence
Finding

The subprocess output is parsed as trusted JSON and then normalized/returned without authenticity checks, while the child process itself is a broad capability broker. In an agent skill that can be triggered by arbitrary user questions, a compromised or replaced toolnode binary/script could inject attacker-controlled structured results that influence higher-level agent behavior or conceal malicious activity.

Content

Scanner excerpt · scripts/perception_node.py (reported line 896)May include surrounding context.

python
# —— 子进程调用:spawn 失败/超时视为能力层崩溃,转保命层 ——
        try:
            proc = subprocess.run(cmd, capture_output=True, timeout=120)
        except (subprocess.TimeoutExpired, OSError) as e:
            logger.warning("[toolnode] capability layer crashed (%s: %s), falling back to BusyBox (trace=%s)",
                           type(e).__name__, e, trace_id)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
97% confidence
Finding

The command output itself is not the primary issue; the dangerous part is that arbitrary shell execution is exposed and both stdout/stderr are returned to the caller. This can facilitate data exfiltration by allowing attackers to read sensitive files or system state and have the results sent back through the tool response.

Content

Scanner excerpt · scripts/toolnode.py (reported line 531)May include surrounding context.

python
timeout = params.get("timeout", 60)
        cwd = params.get("cwd")
        try:
            proc = subprocess.run(cmd, shell=True, capture_output=True,
                                   timeout=timeout, cwd=cwd)
            stdout = _decode(proc.stdout)
            stderr = _decode(proc.stderr)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The presence of 'rm -rf /' inside a toolnode binary that also contains usage strings for command execution indicates the binary is designed to process potentially attacker-controlled command strings. Even though the binary appears to include blocking logic, blacklist-driven detection around catastrophic shell patterns is not a reliable security boundary for a user-triggerable skill.

Content

Scanner excerpt · scripts/toolnode (reported line 1222)May include surrounding context.

text
��������k�����������0�
��������l�����������H�
��������m�����������P�
��������n�����������X�
��������o�����������`�
��������p�����������h�
��������q�����������p�

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The presence of 'rm -rf /' inside a toolnode binary that also contains usage strings for command execution indicates the binary is designed to process potentially attacker-controlled command strings. Even though the binary appears to include blocking logic, blacklist-driven detection around catastrophic shell patterns is not a reliable security boundary for a user-triggerable skill.

Content

Scanner excerpt · scripts/toolnode (reported line 1222)May include surrounding context.

text
��������k�����������0�
��������l�����������H�
��������m�����������P�
��������n�����������X�
��������o�����������`�
��������p�����������h�
��������q�����������p�

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The binary contains command fragments like 'dd if=/dev/' near other destructive-pattern strings, implying command execution and danger-pattern screening are implemented in-process. In a skill that can be triggered broadly by user questions, any shell-capable backend materially increases risk because an attacker may find alternate destructive syntax not covered by the embedded patterns.

Content

Scanner excerpt · scripts/toolnode (reported line 1246)May include surrounding context.

text
���������������������
���������������������
���������������������
�������������������� �
��������������������(�
��������������������0�
��������������������8�

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a textbook tool-parameter-abuse issue: the skill accepts an arbitrary command parameter and forwards it to the system shell. Because the skill is described as broadly triggerable for general user questions, the context makes this more dangerous, turning the agent into a general-purpose local command runner with minimal safeguards.

Content

Scanner excerpt · scripts/toolnode.py (reported line 531)May include surrounding context.

python
timeout = params.get("timeout", 60)
        cwd = params.get("cwd")
        try:
            proc = subprocess.run(cmd, shell=True, capture_output=True,
                                   timeout=timeout, cwd=cwd)
            stdout = _decode(proc.stdout)
            stderr = _decode(proc.stderr)

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/c_ext_loader.py:137

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/perception_node.py:244