Back to skill

Security audit

Ruitian Html

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese HTML document template generator with disclosed CDN dependencies and no hidden local access or persistence.

Install only if a Chinese enterprise-style HTML report template fits your workflow. For sensitive documents or offline use, replace the jsDelivr Bootstrap links with reviewed local copies or SRI-protected resources.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
template.html:393
Finding

Third-Party CDN Resources Loaded Without Subresource Integrity

Content
View full analysis
``` ```html ``` ### Technical Analysis The generated HTML loads Bootstrap CSS, Bootstrap Icons, and executable Bootstrap JavaScript directly from jsDelivr. Although explicit package versions are used, the elements do not include Subresource Integrity (`integrity`) metadata. The document also does not define a restrictive Content Security Policy. Version pinning prevents routine upgrades from silently changing the requested package version, but it does not cryptographically verify the bytes returned to the browser. If the CDN, its delivery infrastructure, or the hosted artifact were compromised, altered JavaScript could execute whenever a generated document is opened while online. The remote stylesheet and icon resources also create supply-chain and availability dependencies. They can affect document presentation and cause the viewer's browser to disclose normal request metadata, including its IP address and user-agent string, to the external CDN. ### Attack Path 1. An attacker compromises the CDN delivery path, hosted artifact, or another component capable of changing the response for the pinned Bootstrap URL. 2. A user generates or copies a document based on `template.html`. 3. The user opens the generated HTML document while connected to the Internet. 4. The browser downloads `bootstrap.bundle.min.js` from jsDelivr without validating an expected cryptographic diges ...[truncated 1298 chars]
Remediation
View remediation
``` Replace the placeholder values only with hashes calculated or published for the exact referenced resources. 3. **Remove unnecessary executable dependencies** - The template does not visibly depend on Bootstrap JavaScript interactions. - If no dropdown, modal, collapse, tooltip, or similar component is required, remove the external script entirely. 4. **Deploy a restrictive Content Security Policy** - When documents are served over HTTP, define a CSP that limits scripts, styles, images, and network destinations to explicitly approved sources. - Avoid allowing `unsafe-inline` for scripts. - Where practical, move inline CSS to a local stylesheet so `style-src` can also be hardened. 5. **Support genuinely offline output** - Bundle all required fonts, icons, stylesheets, and scripts locally. - Document the reviewed dependency versions and establish a controlled process for future dependency updates. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger phrases include broad, natural-language expressions such as '生成 HTML 文档' and '企业文档风格', which can cause the skill to activate in contexts the user did not specifically intend. In an agent setting, overly generic triggers increase the chance of misrouting tasks, unexpected behavior, or accidental application of this skill to unrelated requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML root sets lang="zh-CN", and the visible template text throughout the file is Chinese-only, indicating the skill output is designed to force a specific language/locale. Under the policy, locale constraints should either provide user opt-in/choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 适用于所有文件类型。示例模板将 <html lang="zh-CN"> 固定为中文环境,且文档整体未说明这是可配置项或仅适用于中文输出场景,可能构成未获用户选择的语言/地区约束。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown content, including the title, examples, and customization table, is entirely in Chinese and does not indicate that the skill supports other languages or that Chinese is required for a justified regional use case. This can violate language/locale policy by implicitly forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.