Back to skill

Security audit

合同文档转写技能

Security checks for vulnerabilities and agentic risk

Overview

This skill writes local documents and runs a browser screenshot tool, but its main contract-to-spec output is largely hardcoded rather than actually derived from the contract.

Treat this as a Review item before installing. Only run it on non-sensitive copies of contracts, verify the generated DOCX manually, and do not rely on it for client, procurement, or compliance deliverables until it actually parses contract contents, removes hardcoded business data, asks you to confirm input/output paths, and pins Playwright or uses a controlled local dependency.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/generate_spec.py:173
Finding

Unpinned Runtime Package Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_spec.py, lines 173–187
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code

python
def screenshot_html(html_path, output_path):
    """使用 Playwright 截图 HTML"""
    try:
        subprocess.run([
            'npx', 'playwright', 'screenshot',
            '--wait-for-timeout', '2000',
            '--full-page',
            html_path, output_path
        ], check=True, timeout=60)
        return True
    except Exception as e:
        print(f"截图失败:{e}")
        return False

Technical Analysis

The script invokes Playwright through npx without specifying a package version, requiring a lockfile, verifying package integrity, or using --no-install. If Playwright is not already installed locally, npx may resolve, download, and execute a package using the caller's npm registry configuration.

Consequently, the reviewed source code does not fully determine the code that executes at runtime. A compromised public package release, transitive dependency, package registry, registry configuration, or dependency-resolution environment could cause attacker-controlled package lifecycle code or CLI code to run.

The invocation uses an argument array rather than a shell command, so the observed issue is not shell command injection. The risk arises from mutable and insufficiently constrained dependency resolution.

Attack Path

  1. A user invokes the skill to generate a requirements document.
  2. The script reaches screenshot_html().
  3. The host does not have a verified local Playwright executable available to npx, or npm resolution is otherwise influenced by attacker-controlled registry configuration.
  4. npx resolves or downloads the unpinned Playwright package and its dependency tree.
  5. A compromised package lifecycle script or executable runs under the invoking user's account.
  6. The malicious dependency can act with the same filesystem, ...[truncated 553 chars]
Remediation
View remediation

Remediation Suggestions

  1. Declare Playwright at an exact reviewed version in the project's dependency manifest and commit the corresponding lockfile.
  2. Install dependencies during a controlled deployment or build phase rather than downloading packages while processing user documents.
  3. Invoke only the verified project-local executable and disable installation during execution, for example with npx --no-install playwright ....
  4. Enforce lockfile integrity in deployment, such as using npm ci against an approved registry.
  5. Pin and audit transitive dependencies, and enable dependency integrity and vulnerability checks in CI.
  6. Consider using the pinned Python Playwright package and browser binaries installed through a controlled provisioning process.
  7. Run document generation in a sandbox with restricted filesystem and network access to limit the impact of any future dependency compromise.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明的核心能力是“将合同文件转换为需求规格说明书”,并明确包括读取合同提取项目信息、生成系统架构图、生成6个子功能原型图、输出Word文档。实际代码仅在桌面查找以“合同”开头的docx文件,且提取信息时只使用文件名,合同编号、甲乙方、正文分析内容均为硬编码,不能视为真正读取合同并抽取需求。系统架构图确实会生成,但其内容也是固定HTML模板截图。对于6个子功能原型图,代码既未创建这些图,也未调用任何原型生成逻辑;文档中只是条件性插入images字典里的路径,而main只传入了architecture图片。因此,虽然“生成Word文档到桌面”和“生成一个架构图”与声明部分一致,但整体上主能力被明显夸大,且多项关键声明未实现,属于实质性描述与行为不符。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill reads contract contents, but the code only derives a project name from the filename and hardcodes contract metadata. This is dangerous because it can silently generate authoritative-looking documents with fabricated business details, misleading users into trusting false output for contractual or compliance purposes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Most of the generated specification is a fixed budget-management template unrelated to the input contract. In this context, that is dangerous because it produces deceptive, polished output that may be mistaken for contract-derived requirements, leading to incorrect project scope, compliance issues, or business decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims it will generate six sub-function prototype images, but the code only prepares a single architecture screenshot and leaves the six module images absent. This mismatch is dangerous because it misrepresents the skill's capabilities and can cause users to rely on incomplete deliverables in procurement, planning, or client-facing documentation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes capabilities that read files from the user's Desktop, generate artifacts, and execute a Python script, but it does not declare any explicit tool scope or permission boundaries. This creates an over-privilege and transparency problem: an agent may invoke file and shell-like capabilities without clear user-visible constraints, increasing the risk of unintended access to sensitive contract documents or unsafe execution paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs reading contract files from the Desktop and writing a generated Word document back to the Desktop without surfacing any warning about sensitive data handling or file write side effects. Because contracts often contain confidential business and personal data, silent local file access and output creation can expose sensitive information or overwrite user expectations without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

文档规范要求固定使用中文文档结构和中文字体(如宋体),体现出对输出语言/区域格式的强制约束。文件中未说明该技能仅适用于中文合同场景,也未给用户提供语言或本地化选项,属于自然语言层面的语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's natural-language description and all generated document content are fixed in Chinese, with no option for users to select another language or locale. This matches the policy concern for language/locale constraints that are imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill invokes Playwright via npx, which is an external execution capability not obviously necessary for a contract-to-spec conversion skill. In this context, hidden host execution increases risk because it can introduce dependency-fetching, browser automation, and broader system interaction beyond the user's expected operation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
87% confidence
Finding

The script launches an external executable chain (npx -> Playwright) on the host system. Even though arguments are passed as a list rather than a shell string, this still expands the skill's capabilities beyond document generation and can execute whatever npx resolves locally, creating supply-chain and unintended-execution risk.

Content

Scanner excerpt · scripts/generate_spec.py (reported line 176)May include surrounding context.

python
def screenshot_html(html_path, output_path):
    """使用 Playwright 截图 HTML"""
    try:
        subprocess.run([
            'npx', 'playwright', 'screenshot',
            '--wait-for-timeout', '2000',
            '--full-page',

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill performs external process execution through npx playwright without clearly warning the user. In an agent setting, undisclosed subprocess execution is dangerous because it expands the action surface beyond simple document handling and can surprise users with host-level behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script writes HTML/PNG files into the workspace and a final DOCX onto the user's Desktop without prior confirmation. Unprompted file creation/modification is risky in agent skills because it can clutter user space, overwrite expected artifacts, or create trust issues around silent side effects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.