Back to skill

Security audit

Sensitive Info Protection

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly aligned with detecting sensitive data, but it under-discloses risky browser automation that can expose or submit sensitive content.

Review before installing. The detector itself is local and coherent, but avoid enabling the browser interaction helper unless you accept that it watches chat DOM content, injects controls, and can submit messages through broad UI selectors. Do not scan real secrets unless you are comfortable with detected values appearing verbatim in output, logs, chat history, and page globals. Load only trusted custom rule files.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T07 · Tool Hijacking and Spoofing

Warning
Location
assets/sensitive-interaction.js:76
Finding

Untrusted Chat Content Can Spoof Sensitive-Data Controls and Trigger Message Submission

Content
View full analysis
{ const sendButton = document.querySelector('button[type="submit"], [class*="send"], [part*="send"]'); if (sendButton) { sendButton.click(); } }, 100); } } ``` ```javascript // 自动检测:当新消息包含敏感检测结果时注入按钮 function observeNewMessages() { const observer = new MutationObserver((mutations) => { mutations.forEach(mutation => { if (mutation.addedNodes.length) { mutation.addedNodes.forEach(node => { if (node.nodeType === Node.ELEMENT_NODE) { // 检查节点和所有子节点内容 let content = node.textContent || ''; if (!content.includes('## 检测结果') || !content.includes('## 操作选项')) { // 检查 shadow DOM if (node.shadowRoot) { content = node.shadowRoot.textContent || ''; } } if (content.includes('## 检测结果') && content.includes('## 操作选项')) { // 保存最后敏感内容供编辑使用 const match = content.match(/原文: `(.*?)`/); if (match) { window.lastSensitiveContent = match[1]; } // 注入按钮到当前节点 injectSensitiveButtons(node, content); } } }); } }); }); ``` ### Technical Analysis The mutation observer treats any rendered eleme ...[truncated 2106 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/models.py:66
Finding

Detected Secrets Are Reproduced Verbatim and Stored in a Global Browser Property

Content
View full analysis
str: """Format result as markdown for display""" if not self.has_sensitive: return "No sensitive information detected." output = ["## 检测结果"] for i, det in enumerate(self.detections, 1): output.append(f"- 敏感类型: {det.rule.name}") output.append(f"- 位置: {det.start}:{det.end}") output.append(f"- 原文: `{det.text}`") output.append(f"- 敏感度: {det.rule.sensitivity}") if det.rule.description: output.append(f"- 描述: {det.rule.description}") if i < len(self.detections): output.append("") ``` ```javascript if (content.includes('## 检测结果') && content.includes('## 操作选项')) { // 保存最后敏感内容供编辑使用 const match = content.match(/原文: `(.*?)`/); if (match) { window.lastSensitiveContent = match[1]; } // 注入按钮到当前节点 injectSensitiveButtons(node, content); } ``` ### Technical Analysis The detector identifies sensitive material but then includes the complete matched value in its Markdown output. Rendering or logging this result duplicates the sensitive value into the chat transcript, terminal output, application logs, browser DOM, and any other system that records detector responses. The browser helper compounds the exposure by extracting the displayed value and assigning it to `window.lastSensitiveContent`. Properties on `window` are accessible to other scripts executing in the same page context, including unrelated application components and potentially browser extensions or injected third-party scripts. The value is not cleared after use and has no explicit lifetime. This behavior conflicts with the purpose of a sensitive-information protection component because a successful detection creates ...[truncated 1185 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/models.py:18
Finding

Unrestricted Custom Regular Expressions Can Cause CPU Exhaustion

Content
View full analysis
None: """Compile the regex pattern""" if self.compiled is None: self.compiled = re.compile(self.pattern) def match(self, text: str) -> List[re.Match]: """Find all matches in text""" if not self.enabled: return [] if self.compiled is None: self.compile() return list(self.compiled.finditer(text)) ``` ```python def load_config(self, config_path: str) -> None: """Load rules from configuration file""" with open(config_path, 'r', encoding='utf-8') as f: if config_path.endswith('.json'): rules_data = json.load(f) else: raise ValueError("Only JSON configuration is supported currently") for rule_data in rules_data: rule = DetectionRule(**rule_data) rule.compile() self.rules.append(rule) # Re-sort by priority self.rules.sort(key=lambda x: -x.priority) ``` ### Technical Analysis Custom configuration files can supply arbitrary regular expressions. These expressions are compiled and evaluated using Python's backtracking `re` engine without pattern validation, execution timeout, input-size limit, process isolation, or complexity restrictions. A custom expression containing nested or ambiguous quantifiers can exhibit catastrophic backtracking when applied to a carefully chosen non-matching string. Because `finditer` executes synchronously in the calling process, excessive backtracking can block the CLI or the host agent process. Exploitation requires the attacker to influence a loaded rule file or persuade a user or integrator to install an unsafe custom rule. The built-in rules reviewed during this audit do not establish a confirmed catastrophic-backtracking payload by ...[truncated 836 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This is a serious description-to-behavior mismatch: the skill claims to protect sensitive data, but the reported behavior includes DOM monitoring, UI injection, reading and manipulating chat controls, auto-submission, and storing original sensitive content. In context, that creates a strong risk of covert data interception or exfiltration under the guise of a safety tool, making the mismatch more dangerous than in a non-security-sensitive skill.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
## Default Sensitive Types

Built-in detection for the following types:
- `api_key` - API keys, access tokens, authentication credentials
- `credit_card` - Credit card numbers
- `id_card` - National ID card numbers (Chinese)
- `phone` - Mobile phone numbers (Chinese)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/default_rules.json (reported line 7)May include surrounding context.

json
"name": "api_key",
    "pattern": "(sk|pk|tk|token|key|access)[_-]?[0-9a-zA-Z]{20,}",
    "sensitivity": "high",
    "description": "API Key or Access Token",
    "priority": 10
  },
  {

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/default_rules.json (reported line 70)May include surrounding context.

json
"name": "api_key",
    "pattern": "(sk|pk|tk|token|key|access)[_-]?[0-9a-zA-Z]{20,}",
    "sensitivity": "high",
    "description": "API Key or Access Token",
    "priority": 10
  },
  {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill advertises file-based configuration loading and external rule imports but does not declare any explicit tool scope or permissions. In a skill ecosystem, undeclared file-read capability weakens least-privilege controls and can enable access to local files beyond what users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented detection result and action prompt are presented only in Chinese, which suggests the skill may require or default to a specific language for user-facing interaction. The file does not indicate that users can choose their preferred language or that the Chinese-only output is limited to a justified region-specific use case.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This helper does more than passive detection: it programmatically writes into the chat input, dispatches an input event, and clicks the send button. In a sensitive-data protection context, automation that can submit content on the user's behalf is risky because it can release blocked content or send unintended commands with minimal user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code can cause content to be sent by simulating UI interaction after populating the input box, but the disclosure and warning model is weak in this implementation. Because it relies on generic selectors and auto-click behavior, users may not understand that pressing these injected controls will immediately submit text, including potentially sensitive or modified content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code extracts detected sensitive text from rendered content and stores it in the global variable window.lastSensitiveContent. Any other script running in the page context can read or overwrite that value, which expands exposure of the very data this skill is supposed to protect and creates unnecessary cross-component data leakage risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JSON file defines natural-language/config behavior that specifically targets Chinese national ID card numbers and Chinese mobile phone numbers. Because the file provides no accompanying justification, scope restriction, or user opt-in for this locale-specific focus, it can violate the policy against forcing a specific language or locale without clear documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown formatter returns all user-visible headings and action options in Chinese only. This imposes a specific language on users without opt-in, which matches the language/locale policy violation criteria for natural-language content in code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Natural-language strings and comments indicate the component is designed around Chinese-language interaction, including button labels and prompts, but the file does not offer any user opt-in or locale selection. Under the stated policy, forcing a specific language without user choice is a locale-policy concern unless the restriction is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.