Back to skill

Security audit

GIS_SKILL_V1.0

Security checks for vulnerabilities and agentic risk

Overview

This is a large GIS reference skill, but its default self-evolution system can persist user text, search externally, and rewrite skill files without clear consent or review.

Review before installing. Use this as a read-only GIS reference unless you deliberately want self-updating behavior. Disable self_evolution_enabled, auto_search_enabled, and feedback_detection_enabled by default; require explicit approval before logging user text, searching externally, or changing SKILL.md/reference files; avoid copying the unsafe shell and HTTP credential examples into production.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T02 · Agent Memory Poisoning

Error
Location
feedback/config.json:2
Finding

Persistent Memory Poisoning Through Automatic Feedback-Driven Self-Modification

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
references/37_自进化反馈机制.md:110
Finding

Autonomous External Searches and Session-End State Changes Exceed Least Privilege

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/19_多源数据融合.md:185
Finding

Command Injection Through Shell-Interpolated GIS File Paths and EPSG Values

Content
View full analysis
{dst_path}") return dst_path ``` ### Technical Analysis The code constructs a shell command by interpolating `src_path`, `dst_path`, the source suffix, and `self.target_epsg` into a string and passes the string to `os.system`. `os.system` invokes a command shell. Quoting the paths does not reliably prevent injection because filenames can contain quotation marks or shell metacharacters. The EPSG value is not quoted or validated and is an especially direct injection point if it can be influenced by external input. The code also ignores the process exit status and reports success even when `ogr2ogr` fails. This can conceal exploitation or data-conversion errors. ### Attack Path 1. An attacker controls or influences a source path, destination path, filename, or EPSG value supplied to the converter. 2. The attacker includes shell syntax in the value, such as a quote followed by a command separator and an operating-system command. 3. The application interpolates the value into `cmd`. 4. `os.system` passes the resulting string to the system shell. 5. The shell executes both `ogr2ogr` and the injected command. 6. The code logs the conversion as successful without checking the return code. For example, an unvalidated EPSG string conceptually shaped as `4326 && attacker_command` would append another command on shells where `&&` is a command separator. ### Impact Assessment Injected commands execute with the same privileges as the Python process or Agent following the example. Depend ...[truncated 484 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/16_SuperMap_iDesktopX.md:345
Finding

SuperMap Authentication Example Transmits Credentials and Tokens Insecurely

Content
View full analysis
or URL: ?token= ``` ### Technical Analysis The authentication endpoint uses plaintext HTTP while transmitting a username and password. On any network where traffic can be observed or modified, credentials may be intercepted by a local attacker, compromised router, proxy, wireless adversary, or other on-path party. The example also permits a bearer token in the URL query string. URL tokens commonly leak into: - Reverse-proxy and web-server access logs. - Browser history. - Monitoring and analytics systems. - Referer headers. - Screenshots, copied links, and support tickets. - Intermediate caches and debugging output. The use of an `admin` account in the example increases the potential impact if users reproduce it directly. This network behavior is functionally relevant to documenting the SuperMap API, but the demonstrated transport and token placement are not secure. ### Attack Path 1. A user follows the example against a remote or non-isolated SuperMap server. 2. The username and password are sent over HTTP. 3. An on-path attacker captures the request or modifies the response. 4. Alternatively, the user places the token in the URL and infrastructure records it in logs. 5. The attacker retrieves the credential or bearer token. 6. The attacker authenticates to iServer and invokes the victim's authorized API operations. 7. If the compromised identity is an administrator, the attacker may manage services and access protected GIS resources. ### Impact Assessment Successful exploitation may expose: - Usernames and passwords. - Reusable bear ...[truncated 383 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/21_Python_GIS生态.md:226
Finding

Unpinned Third-Party Package Installation Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (114)

Instruction Override

High
Category
Prompt Injection
Confidence
90% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/13_QGIS.md (reported line 55)May include surrounding context.

text
Settings → Options → General
  → ☑ Override system locale
  → User interface translation: 简体中文
  → 重启 QGIS 生效

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/18_FME_Form与Flow.md (reported line 193)May include surrounding context.

md
# === 仓库管理 ===
GET    /repositories                    # 列出所有仓库
POST   /repositories/{repo}/items       # 上传工作空间
DELETE /repositories/{repo}/items/{ws}  # 删除工作空间

# === 作业管理 ===
POST   /transformations/submit/{repo}/{workspace}  # 提交作业

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/18_FME_Form与Flow.md (reported line 199)May include surrounding context.

md
POST   /transformations/submit/{repo}/{workspace}  # 提交作业
GET    /transformations/jobs/{jobId}              # 查询作业状态
GET    /transformations/jobs/{jobId}/result       # 获取作业结果
DELETE /transformations/jobs/{jobId}              # 取消作业

# === 自动化管理 ===
GET    /automations                    # 列出所有自动化

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/23_WebGIS开发.md (reported line 170)May include surrounding context.

md
<div class="full-screen">
    <div ref="mapContainer" class="map-container"></div>
    
    <!-- 控制面板 -->
    <div class="control-panel">
      <button class="toggle-btn" @click="toggle3D">
        {{ is3D ? '切换到 2D' : '切换到 3D' }}

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/25_三维GIS与数字孪生.md (reported line 550)May include surrounding context.

ContextCapture POS高级参数配置参考:

xml
<!-- ContextCapture Engine POS导入高级参数 -->
<pos_import_settings>
  <!-- 坐标系声明 (必须与POS数据文件一致!) -->
  <coordinate_system>CGCS2000 / 3-degree GK zone 38</coordinate_system>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/25_三维GIS与数字孪生.md (reported line 557)May include surrounding context.

md
<!-- POS数据粗差剔除阈值 -->
  <position_outlier_sigma>3.0</position_outlier_sigma>
  <!-- 含义: 超过N倍标准差的POS点被视为粗差点自动剔除 -->

  <!-- POS权重系数 (相对于影像匹配约束的权重比) -->
  <gps_position_weight>1.0</gps_position_weight>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/26_WorkBuddyGIS_AddIn开发.md (reported line 523)May include surrounding context.

| XAML 绑定诊断 | 编译时绑定检查 | csproj 中添加 <PresentationTraceSources> 启用详细追踪 |

xml
<!-- App.xaml 或 DockPane.xaml 中启用绑定诊断 -->
<Window xmlns:diag="clr-namespace:System.Diagnostics;assembly=WindowsBase"
        diag:PresentationTraceSources.TraceLevel="High">

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/26_WorkBuddyGIS_AddIn开发.md (reported line 719)May include surrounding context.

md
<!-- Config.daml 关键验证点 -->
<insertModule id="WorkBuddyGIS_Module" className="WorkBuddyGIS.WorkBuddyGISModule"
              caption="WorkBuddyGIS" autoInsert="true">
  <!-- 1. id 必须与 Module 类的 [ModuleAttribute("id")] 一致 -->
  <!-- 2. className 必须包含完整命名空间 -->

  <groups>

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill requires automatic logging of users' original statements and related metadata into persistent files, but provides no clear privacy notice, consent flow, retention period, or access controls. In a GIS context, user prompts may contain location, infrastructure, surveying, or client data, so silent retention materially increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/40_OGC国际标准速查手册.md (reported line 274)May include surrounding context.

md
<CRS>EPSG:4326</CRS>
      <CRS>CRS:84</CRS>
      <BoundingBox CRS="EPSG:4326" minx="-124.73" miny="24.96" maxx="-66.97" maxy="49.37"/>
      <!-- ⚠ 注意:1.3.0 下此 BBOX 实际含义是 (lat_min, lon_min, lat_max, lon_max) -->
    </Layer>
  </Capability>
</WMS_Capabilities>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/40_OGC国际标准速查手册.md (reported line 274)May include surrounding context.

md
<CRS>EPSG:4326</CRS>
      <CRS>CRS:84</CRS>
      <BoundingBox CRS="EPSG:4326" minx="-124.73" miny="24.96" maxx="-66.97" maxy="49.37"/>
      <!-- ⚠ 注意:1.3.0 下此 BBOX 实际含义是 (lat_min, lon_min, lat_max, lon_max) -->
    </Layer>
  </Capability>
</WMS_Capabilities>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The example builds a shell command from file paths and format choices, then executes it with subprocess.run(..., shell=True). In an agent or automation setting, if any part of source_path, target_format, or related values is influenced by user input, an attacker could inject shell metacharacters and execute arbitrary commands on the host.

Content

Scanner excerpt · references/45_GIS_Agent技能设计范式.md (reported line 592)May include surrounding context.

md
target_path = src.with_suffix(f".{target_format}")
        cmd = self.CONVERSION_MAP.get(ext, "ogr2ogr -f GPKG {out} {in}").format(
            out=target_path, _in=src)
        result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
        if result.returncode != 0:
            return {"status": "error", "error": result.stderr}
        return {"status": "success", "target": str(target_path),

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation text enumerates a very broad set of common GIS, mapping, data, standards, and tooling terms, making the skill likely to trigger for ordinary domain mentions rather than clear user intent to use this specific skill. Over-broad invocation can hijack routing, cause irrelevant or overly forceful behavior, and increase the chance that embedded operational rules in the skill override normal conversational handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file hard-codes authority source names, rating rules, and user-trigger keywords entirely in Chinese, which indicates the skill behavior is tied to a specific language/locale. There is no accompanying configuration for language selection, opt-in, or documentation that this skill is intentionally restricted to Chinese-speaking users or a China-specific deployment context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The auto-trigger keyword lists contain very broad, common conversational phrases such as '还有呢' and '具体怎么操作', which can cause the self-evolution or feedback pipeline to activate during ordinary user dialogue rather than explicit correction or consented feedback. In this skill, that risk is amplified because auto_search_enabled and self_evolution_enabled are turned on, so accidental activation can drive unneeded searches, knowledge-gap recording, or automatic updates based on ambiguous input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file states that feedback should be automatically appended when keywords are detected, but the trigger criteria are broad and later include common conversational phrases. This can cause routine user messages to be stored as feedback records without clear user intent, creating unnecessary data retention and possible contamination of the skill's self-evolution workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The log schema stores '用户原始表述' and records operational handling, but the file does not provide a clear retention notice, consent mechanism, or deletion policy at the point of collection. Even if intended for internal improvement, storing raw user statements can capture personal or sensitive information and creates privacy and compliance risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger lists include highly common phrases such as '还有' and '具体怎么操作', which are normal in many conversations and not reliable indicators of consent to create a persistent feedback entry. In this skill's self-evolution context, that increases the chance of accidental logging and inappropriate downstream updates or queued searches based on ordinary chat.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

All operational headings, trigger conditions, and maintenance instructions are written exclusively in Chinese, and the file presents no user opt-in or alternative language handling. This can constitute a language/locale policy issue when a skill implicitly forces one language without documenting that the skill is region-specific or offering a choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The maintenance rule says records are automatically appended whenever the user follows up, corrects, or the system cannot answer, but it does not define limits, review requirements, or what data may be stored. This can lead to over-collection of conversational content and persistent memory updates from routine interactions, increasing privacy and integrity risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The automatic trigger table uses broad natural-language cues such as users saying '还有呢/还有别的吗' or any uncertain wording in answers to trigger extra search or verification actions. In an agent setting, these are common conversational phrases and can cause unintended state changes, excessive retrieval, or workflow execution without explicit user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L183 states that filenames should be '100% English + underscore + numbers', which is a natural-language locale restriction. Because the guidance is framed as a universal rule rather than an optional compatibility recommendation with user opt-in, it can violate the policy against forcing a specific language or locale.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file content is entirely written in Chinese and provides no indication that language selection is optional or that the skill is explicitly limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.