Back to skill

Security audit

Auto Coding V3

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate autonomous coding skill, but some safety controls are advertised more strongly than the code guarantees and it writes persistent local workflow files based on the chosen project path.

Review this before installing if you rely on its advertised guardrails: enable and verify the discipline/scorecard mode if you want those checks, run it only on a project directory you explicitly choose, keep .auto-coding/ and /tmp/auto-coding-projects out of version control, and do not enable external notifications or background scheduling unless you intentionally opt in.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Note
Location
dependency_manager.py:27
Finding

Caller-Controlled Project Directory Enables Writes Outside the Intended Workspace

Content
View full analysis

Vulnerability Details

File Location: dependency_manager.py:27-42, with the corresponding graph write at dependency_manager.py:94-101
Vulnerability Type: Unrestricted filesystem path and symlink following
Risk Level: Low

Vulnerable Code

python
def __init__(self, project_dir: str):
    self.project_dir = Path(project_dir)
    self.dependency_file = self.project_dir / "dependency_graph.json"
    self._lock_path = self.project_dir / ".dependency_lock"

@contextmanager
def _file_lock(self):
    """File lock context manager"""
    self.project_dir.mkdir(parents=True, exist_ok=True)
    with open(self._lock_path, 'w') as lock_file:
        try:
            fcntl.flock(lock_file.fileno(), fcntl.LOCK_EX)
            yield
        finally:
            fcntl.flock(lock_file.fileno(), fcntl.LOCK_UN)

The dependency graph is subsequently written using the path derived from the same unrestricted directory:

python
def _save_dependency_graph(self, data: Dict):
    """Save dependency graph to file"""
    with self._file_lock():
        try:
            with open(self.dependency_file, 'w', encoding='utf-8') as f:
                json.dump(data, f, indent=2, ensure_ascii=False)
            logger.debug("Dependency graph saved to file")
        except Exception as e:
            logger.error(f"Failed to save dependency graph: {e}")

Technical Analysis

The constructor accepts project_dir and converts it directly to a Path without resolving it against an approved workspace root. The implementation then creates the supplied directory and opens .dependency_lock and dependency_graph.json in write mode.

No validation establishes that:

  • The resolved project directory is beneath an authorized workspace.
  • The directory or its parent components are not symbolic links.
  • .dependency_lock and dependency_graph.json are regular files rather than symbolic links. ...[truncated 2610 chars]
Remediation
View remediation

Remediation Suggestions

  1. Define an explicit trusted workspace root and resolve both it and the requested project path before performing filesystem operations:

    python
    workspace_root = Path(allowed_workspace).resolve(strict=True)
    project_dir = Path(project_dir).resolve(strict=False)
    
    if project_dir != workspace_root and workspace_root not in project_dir.parents:
        raise ValueError("Project directory is outside the authorized workspace")
    
  2. Reject absolute paths when the interface is intended to accept only workspace-relative project names.

  3. Inspect existing path components with lstat() and reject symbolic links. Repeat security-sensitive validation immediately before writing to reduce time-of-check/time-of-use exposure.

  4. Open lock and data files with flags that refuse symbolic links where supported, such as os.open() with O_NOFOLLOW. Verify with fstat() that the opened object is a regular file.

  5. Write the graph atomically:

    • Create a temporary file in the validated destination directory.
    • Set restrictive permissions such as 0600.
    • Flush and call fsync().
    • Replace the destination with os.replace() only after validation.
  6. Centralize workspace confinement and safe-file-opening logic so that dependency, state, task, logging, and workflow components apply the same policy.

  7. Run the workflow under a dedicated least-privileged account or isolated container whose filesystem access is limited to the authorized workspace.

  8. Add tests covering absolute paths, .. traversal, symlinked parent directories, symlinked destination files, and replacement of paths during write operations.

Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (128)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This finding suggests some features may exist only conditionally or as configurable options rather than default guaranteed controls, despite being marketed as core behavior. Optional or dynamic safeguards should not be described as always-on security properties because users may rely on them when they are disabled.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · approval_rules.py (reported line 86)May include surrounding context.

python
"""解析规则数据"""
        auto = data.get("auto_approve", {})
        req = data.get("require_approval", {})
        return RuleSet(
            auto_approve_edit=auto.get("edit", DEFAULT_RULES.auto_approve_edit),
            auto_approve_run=auto.get("run", DEFAULT_RULES.auto_approve_run),
            auto_approve_create=auto.get("create", DEFAULT_RULES.auto_approve_create),

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · approval_rules.py (reported line 255)May include surrounding context.

python
def should_notify_on_complete(self) -> bool:
        """任务完成时是否需要通知"""
        rules = self._load_rules()
        return rules.notify_on_complete

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · workers/base_worker.py (reported line 237)May include surrounding context.

python
prompt += "3. 保持 ✅ 值得肯定的部分不变\n"
        prompt += "4. 按 编码纪律:极简、手术刀修改、不加额外功能\n"
        
        return prompt

    def format_for_human(self, review_result: ReviewResult) -> str:
        """格式化审查结果为人类可读报告"""

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · workers/reviewer_worker.py (reported line 167)May include surrounding context.

python
prompt += "3. 保持 ✅ 值得肯定的部分不变\n"
        prompt += "4. 按 编码纪律:极简、手术刀修改、不加额外功能\n"
        
        return prompt

    def format_for_human(self, review_result: ReviewResult) -> str:
        """格式化审查结果为人类可读报告"""

Static analysis

No suspicious patterns detected.