Back to skill

Security audit

Openapi Contract Driven

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent, but it needs Review because its included OpenAPI-to-TypeScript generator can embed untrusted API-spec text into executable frontend code.

Review before installing in repositories where OpenAPI specs may come from pull requests, shared contract repos, vendors, or other semi-trusted sources. Pin the npm dependency and CI actions, review changes to OpenAPI YAML like source code, and harden or replace generate-api-client.sh before using generated clients in production.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/generate-api-client.sh:57
Finding

OpenAPI Input Can Inject Executable TypeScript into the Generated API Client

Content
View full analysis
/dev/null | \ sed 's/.*title:[[:space:]]*"\([^"]*\)".*/\1/;s/.*title:[[:space:]]*'\''\([^'\'']*\)'\''.*/\1/;s/.*title:[[:space:]]*\(.*\)/\1/' | \ sed 's/[[:space:]]*$//') if [ -z "$PROJECT_TITLE" ]; then PROJECT_TITLE="$(basename "$YAML_FILE" .yaml)" fi cat << END_HEADER /** * ⚠️ 本文件由 OpenAPI 契约自动生成,前端 agent 禁止手改。 * 新增端点流程:改 standards/{project}-openapi.yaml → 重新运行 generate-api-client.sh → 两端同步。 * * 项目: ${PROJECT_TITLE} * 生成时间: $(date '+%Y-%m-%d %H:%M:%S') * 源文件: ${YAML_FILE} * 生成命令: * bash references/generate-api-client.sh ${YAML_FILE} */ ``` Additional OpenAPI-derived fields are directly concatenated into TypeScript: ```awk # New group if (group != prev_group) { if (prev_group != "") printf "};\n\n" printf "export const %s = {\n", group prev_group = group } # JSDoc comment if (summary != "") printf " /** %s */\n", summary if (sig_parts != "") { printf " %s: (%s) =>\n request<%s>(%s),\n", op_id, sig_parts, resp_type, req_args } else { printf " %s: () =>\n request<%s>(%s),\n", op_id, resp_type, req_args } ``` ### Technical Analysis The generator treats the OpenAPI document as trusted source code rather than untrusted structured data. The project title, tags, operation IDs, summaries, paths, schema names, response types, and parameter names are incorporated into generated TypeScript through shell heredocs and `awk` formatting. No contextual escaping or strict identifier validation is applied: - Comment content is not protected against `*/` comment termination. - TypeScript identifiers are not restricted to valid identifier syntax. - Path and request strings are placed inside ...[truncated 2351 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/migration-guide.md:252
Finding

Unpinned Third-Party Packages and GitHub Actions Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
# v4.x.x ``` 7. Add an explicit minimal workflow permission block, for example: ```yaml permissions: contents: read ``` 8. Avoid exposing repository secrets to jobs that only perform static OpenAPI validation. 9. Periodically update pinned versions through reviewed dependency-update pull requests. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
references/agent-templates/frontend-agent.md:27
Finding

Bearer Tokens May Be Exposed Through Local Storage and Unrestricted API Origin Configuration

Content
View full analysis
localStorage.getItem('token'), }); ``` The client accepts an unrestricted base URL and attaches the token to every generated request: ```typescript let _baseUrl = ''; let _getToken: () => string | null = () => null; export function configureApiClient(opts: { baseUrl: string; getToken: () => string | null }) { _baseUrl = opts.baseUrl; _getToken = opts.getToken; } async function request(method: string, path: string, body?: unknown, params?: Record): Promise { const url = new URL(`${_baseUrl}${path}`); if (params) Object.entries(params).forEach(([k, v]) => { if (v !== undefined) url.searchParams.set(k, v); }); const headers: Record = { 'Content-Type': 'application/json' }; const token = _getToken(); if (token) headers['Authorization'] = `Bearer ${token}`; const res = await fetch(url.toString(), { method, headers, body: body ? JSON.stringify(body) : undefined }); ``` The migration guide repeats the storage recommendation: ```text | `getToken()` | Obtain JWT | Read from `localStorage` or `useAuth()` | ``` ### Technical Analysis Tokens stored in `localStorage` are accessible to JavaScript executing under the application's origin. Consequently, any successful cross-site scripting vulnerability or compromised frontend dependency can read and export the token. The API client also treats `baseUrl` as trusted configuration and ...[truncated 2107 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The prominent tagline is written in Chinese, and the README overall does not indicate that language is selectable or that Chinese is required for a justified region-specific purpose. This creates a natural-language policy concern because the skill presentation implicitly favors a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file is entirely written as a mandatory instruction set in Chinese and does not indicate that language choice is optional or user-selectable. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill guidance is written in Chinese and does not indicate that language selection is optional or constrained by a documented regional requirement. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire coordinator template is written in Chinese and gives operational instructions only in that language, with no indication that users may choose another language or that the skill is limited to a Chinese-speaking environment. This constitutes a natural-language locale policy concern because it effectively enforces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document is written entirely in Chinese and provides mandatory instructions without offering any language choice or opt-in. Under the policy provided, forcing a specific language is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire skill file is written in Chinese and presents mandatory operational instructions and output expectations without indicating that language selection is optional. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions in the generated file are written entirely in Chinese and explicitly direct frontend agents not to modify the file, but they do not offer any language choice or explain a required locale scope. This creates a language/locale policy concern because the skill content effectively assumes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script’s header comments, usage text, and operational messaging are written exclusively in Chinese, and the same language is used throughout user-facing output. For a general-purpose validation script, that imposes a specific language on users without opt-in or a documented region-specific justification, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The guide instructs users to run npx openapi-typescript without pinning a specific package version. This can cause builds to pull an unexpected or newly compromised version at execution time, reducing reproducibility and creating a supply-chain exposure in developer or CI environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

This is a second instance of the same supply-chain pattern: invoking npx openapi-typescript without an exact version allows remote package resolution at runtime. In a workflow guide aimed at standardizing team and CI behavior, this can propagate insecure, non-reproducible commands across many repositories.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language template content is written as mandatory project guidance in Chinese, stating this file is the sole API contract and must be followed, without indicating that language choice is optional. Under the policy rule, forcing a specific language or locale without user opt-in is a reportable natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file presents core skill description content in Chinese alongside English, including the 'NOT for' constraint, but does not state any user language preference or provide an explicit language-selection option. This can create a language/locale policy issue if users are expected to consume instructions in a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This YAML file contains natural-language instructions, comments, and user-facing step names entirely in Chinese, which imposes a specific language on users without opt-in. The policy allows locale constraints only when explicitly justified or when users are given a choice, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese and does not indicate that other languages are available or that Chinese is a documented requirement. Under the natural-language policy rules, forcing a specific language without user opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.