Back to skill

Security audit

Dwg To Dxf Converter

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its converter lookup can run an unverified executable from the system PATH and its activation instructions are broad for a local-execution workflow.

Review before installing. Use this only in a controlled environment, preferably with a verified ODA File Converter at a fixed trusted path, and avoid letting it auto-run on untrusted DWG files or ambiguous DWG-processing requests. The artifact does not show exfiltration or persistence, but the PATH-based executable lookup should be fixed or constrained.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/dwg_to_dxf.py:35
Finding

Untrusted ODA Converter Resolution Through the Process PATH

Content
View full analysis

Vulnerability Details

File Location: scripts/dwg_to_dxf.py, lines 35–36 and 90–98
Vulnerability Type: Executable search-path hijacking
Risk Level: Medium

Vulnerable Code

python
# 3. 尝试从系统环境变量查找
found = shutil.which("ODAFileConverter.exe") or shutil.which("ODAFileConverter")
return found

The resolved path is subsequently executed:

python
result = subprocess.run(
    cmd, 
    capture_output=True, 
    text=True, 
    check=True,
    creationflags=creation_flags,
    timeout=180
)

Technical Analysis

If the converter is unavailable at the bundled path and fixed system installation paths, find_oda_engine() searches the process PATH for an executable named ODAFileConverter.exe or ODAFileConverter. The returned executable is trusted and launched without validating its cryptographic hash, publisher signature, ownership, or filesystem permissions.

The audited project does not include the declared tools/oda/ODAFileConverter.exe, making fallback resolution relevant. Although subprocess.run() correctly receives an argument list and does not introduce shell-command injection, that protection does not prevent executable search-path hijacking.

An attacker must already be able to influence the Agent process environment or write a matching executable into a directory searched before the legitimate converter. Under those conditions, a malicious binary can impersonate ODA File Converter and execute attacker-controlled logic when conversion is requested.

Attack Path

  1. The trusted converter is absent from tools/oda/ and the fixed installation locations.
  2. An attacker places a malicious executable named ODAFileConverter.exe or ODAFileConverter in a writable directory.
  3. The attacker causes that directory to appear in the Agent process PATH, ahead of any legitimate converter location.
  4. A user or workflow invokes scripts/dwg_to_dxf.py for a DWG conversion.
  5. shutil.which() resolves the attacker-control ...[truncated 626 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the PATH-based fallback and require either the bundled converter or an explicitly configured absolute executable path.
  2. Before execution, validate the converter using a pinned cryptographic hash or an expected Authenticode publisher and certificate chain.
  3. Reject relative paths and confirm that the resolved path is a regular file in an administrator-controlled directory.
  4. Verify that the executable and its parent directories are not writable by untrusted users.
  5. Launch the converter under a dedicated least-privileged account or sandbox with access limited to the required input, temporary, and output directories.
  6. Fail closed with a clear installation error when no verified converter is available.
  7. If PATH discovery must remain for compatibility, restrict discovery to an explicit allowlist of trusted directories and perform integrity verification before every launch.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill instructs the agent to invoke a local Python script and a bundled converter, which implies shell execution and filesystem access, yet the manifest declares no explicit tool scope or permission boundaries. In an agent environment, this can lead to over-privileged execution, making unintended file access, file creation, or command invocation more likely if the skill is triggered on untrusted inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
74% confidence
Finding

The skill content is entirely in Chinese and does not indicate that users may choose another language or locale. Under the policy, fixed language behavior without opt-in can be a natural-language policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad and mandatory, covering generic phrases like DWG processing and any workflow receiving a .dwg file. This increases the chance of unintended activation on loosely related requests or untrusted files, which is especially risky because the skill performs local code execution and file operations.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/dwg_to_dxf.py (reported line 93)May include surrounding context.

python
# 开启创建标志以在 Windows 后台静默运行,不弹出窗口 
            creation_flags = 0x08000000 if os.name == 'nt' else 0 # CREATE_NO_WINDOW
            
            result = subprocess.run(
                cmd, 
                capture_output=True, 
                text=True,

Static analysis

No suspicious patterns detected.