Security checks for vulnerabilities and agentic risk
Overview
This is a real allocation/reporting skill, but its generated HTML report has review-worthy script execution risks from unescaped labels and CDN-loaded JavaScript.
Review before installing. Keep confirmation enabled, avoid --always unless this is a trusted local workflow, avoid untrusted custom label text, and use --no-open or --no-html for sensitive data until label escaping, exact pinned local dependencies or SRI, and hard input limits are added.
Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)
T09 · Insecure Skill Coding Practices
Error
Location
scripts/visualizer.py:54
Finding
HTML and JavaScript Injection Through User-Controlled Report Labels
Content
View full analysis
...
{"".join(f"" for t in range(T))}
{obj_name}ID
{slot_name}{t+1}
覆盖率
Remediation
View remediation
T03 · Remote Payload Retrieval and Execution
Warning
Location
scripts/visualizer.py:152
Finding
Automatic Execution of Mutable CDN-Hosted JavaScript
Content
View full analysis
```
The generated report is then opened automatically by default:
```python
def _open_html(outdir, args):
if not args.no_html and not args.no_open:
try:
import webbrowser
html_path = outdir / "allocation_result.html"
if html_path.exists():
webbrowser.open(html_path.resolve().as_uri())
print(f" 🌐 已在浏览器中打开可视化报告")
except Exception:
pass
```
### Technical Analysis
The generated HTML executes JavaScript retrieved at report-viewing time rather than code fully contained in the audited package.
The Chart.js URL uses the mutable major-version selector `@4`, rather than an exact package version. Its effective content can therefore change after the Skill has been reviewed. Plotly is pinned to a more precise version, but both resources are loaded without Subresource Integrity attributes. Consequently, the browser has no cryptographic verification that downloaded content matches an audited artifact.
The report is automatically opened unless the user supplies `--no-open`. Opening it triggers external network requests and execution of the returned scripts. This also contradicts the generator's description of the HTML output as fully self-contained.
The issue does not establish that either CDN resource is currently malicious. The risk is that a CDN compromise, package publication compromise, mutable-version change, or upstream supply-chain incident could alter code executed by
...[truncated 1433 chars]
Remediation
View remediation
T09 · Insecure Skill Coding Practices
Warning
Location
scripts/main.py:624
Finding
Unbounded Allocation Parameters Permit Local Resource Exhaustion
Content
View full analysis
1]
if not dup_options:
continue
worst = max(dup_options, key=lambda x: freq[x])
for t in range(T):
if slots[t] != worst:
continue
used_in_t: dict[int, int] = defaultdict(int)
for o in objects:
if t < len(o["slots"]):
used_in_t[o["slots"][t]] += 1
```
### Technical Analysis
The documentation recommends limits such as `N <= 1000`, `T <= 52`, and `K <= 20`, but the CLI does not enforce them. Values parsed from `--input` can therefore be arbitrarily large.
Memory consumption grows substantially with `N × T` because the implementation stores:
- One object record for every object.
- One assignment per object p
...[truncated 1817 chars]
The documented purpose emphasizes allocation logic, but the detected behavior suggests the skill mainly consumes preexisting results and generates HTML/file outputs, including CDN-loaded resources. This mismatch is dangerous because reviewers and users may authorize the skill for a benign planning task while it performs materially different actions such as writing files and pulling external dependencies.
Content
No source excerpt is available for this finding.
Ae1
High
Category
analysis-evasion
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected
Content
Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.
The same --no-confirm flag can be abused as a tool-parameter shortcut to suppress user review and push through actions the user did not fully inspect. In a skill with output generation and possible file writes, bypassing confirmation materially increases the risk of unauthorized or surprising side effects.
Content
Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.
--no-confirm and especially persistent --always reduce resistance to parameter abuse by allowing unreviewed execution of user- or agent-supplied inputs. In contexts where this skill is chained into automation, an attacker or faulty upstream component could alter allocation parameters, mode, or repeat ratios without the human checkpoint that the confirmation table is meant to provide.
Content
Scanner excerpt · references/usage.md (reported line 17)May include surrounding context.
The skill advertises low sensitivity and no explicit tool scope, yet the package structure and documented outputs imply file read/write behavior. Missing a declared permission boundary makes it easier for an agent platform to invoke the skill with broader capabilities than users expect, weakening least-privilege guarantees.
Content
No source excerpt is available for this finding.
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding
Broad trigger terms like generic words for allocation or coverage can cause unintended invocation in unrelated conversations. In an agent setting, accidental activation increases the chance of unnecessary file creation, autonomous processing, or external-resource-backed outputs without clear user intent.
Content
No source excerpt is available for this finding.
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding
The skill mentions CSV export and HTML visualization with CDN-hosted libraries but does not prominently warn that it may create files or load third-party resources. This can expose user data in generated artifacts and introduce privacy, integrity, or network-policy risks when the HTML is opened.
Content
No source excerpt is available for this finding.
Autonomous Decision Making
Medium
Category
Excessive Agency
Confidence
72% confidence
Finding
A documented --no-confirm mode enables the workflow to proceed without an interactive confirmation step. While convenient, this reduces a safety checkpoint that would otherwise help prevent unintended execution, especially when outputs include file generation or other side effects.
Content
Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.
The documentation promotes a persistent confirmation bypass (--always) and one-shot bypass (--no-confirm) without warning that future executions may run non-interactively with changed parameters or unintended inputs. In agent or automated contexts, disabling confirmation removes a safety checkpoint and can make misuse, accidental execution, or unsafe batch actions easier.
Content
No source excerpt is available for this finding.
Intent-Code Divergence
Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding
Line L032 states that N/K/T '不会自动推断或编造' and that execution is impossible unless missing values are supplemented via menu option 9. However, earlier command examples at L009-L014 explicitly show a single free-text --input string being '自动解析' into N, T, K, and ratios, which contradicts the blanket claim that these values are not automatically inferred.
Content
No source excerpt is available for this finding.
Context-Inappropriate Capability
Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding
The page imports executable JavaScript from third-party CDNs at runtime, which creates a supply-chain and integrity risk. If the CDN, package, or network path is compromised, arbitrary code would run in the context of the local report despite the file otherwise appearing static.
Content
No source excerpt is available for this finding.
Intent-Code Divergence
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
The footer states the report is 'pure static HTML, no server needed', but the page depends on remote CDN scripts to function. This is misleading and can cause users to trust the file as fully offline/safe when it still executes third-party code over the network.
Content
No source excerpt is available for this finding.
Context Window Stuffing
Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
Content
Scanner excerpt · scripts/allocation_result.html (reported line 238)May include surrounding context.
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
Content
Scanner excerpt · scripts/allocation_result.html (reported line 238)May include surrounding context.
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
Content
Scanner excerpt · scripts/allocation_result.html (reported line 238)May include surrounding context.
This code file contains natural-language strings and documentation that present the CLI entirely in Chinese, including the main docstring and interactive prompts. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.
Content
No source excerpt is available for this finding.
Intent-Code Divergence
Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding
The top-level documentation states that every run generates allocation_result.md, allocation_result.csv, and allocation_result.html. In actual execution, CSV generation is deferred to _ask_csv and only occurs if the user answers "y"; in several paths it is not written at all. This is an active contradiction between documentation and behavior, not merely omitted detail.
Content
No source excerpt is available for this finding.
Description-Behavior Mismatch
Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding
The generated HTML loads Chart.js and Plotly from public CDNs, which extends a local allocation visualizer into one that performs external network fetches at view time. This creates a supply-chain and privacy risk because opening the report contacts third parties and executes remotely served JavaScript that could change independently of the skill author’s code.