Back to skill

Security audit

"运营-产品协同加速套件。解决运营与产品之间的信息不对称、需求扯皮、效果归因等痛点。用于:(1) 运营需求翻译为产品语言;(2) 效果归因框架生成;(3) 优先级智能计算;(4) 验收标准自动生成;(5) 数据口径对齐;(6) 协同文档生成。触发词:运营需求、产品协同、效果归因、需求扯皮、数据口径、验收标准、优先级评估。"

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language ops/product documentation skill with no executable or hidden behavior, though its broad triggers and sample SQL deserve care.

Install this only if you want a Chinese-language workflow assistant for operations and product collaboration. Prefer explicit slash-command use because the trigger phrases are broad, and do not copy the illustrative SQL patterns into production without converting them to parameterized queries.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:430
Finding

SQL Injection Through Direct String Interpolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 430–449
Vulnerability Type: SQL injection
Risk Level: Medium

Vulnerable Code

python
# DAU query
def get_dau(date):
    query = """
    SELECT COUNT(DISTINCT user_id) 
    FROM user_behavior 
    WHERE event_date = '{date}'
    AND event_type IN ('view', 'search', 'add_cart', 'order')
    """
    return execute_query(query)

# GMV query
def get_gmv(start_date, end_date):
    query = """
    SELECT SUM(order_amount)
    FROM orders
    WHERE order_status IN ('paid', 'shipped', 'completed')
    AND payment_status = 'success'
    AND order_date BETWEEN '{start_date}' AND '{end_date}'
    """
    return execute_query(query)

Technical Analysis

The example constructs SQL statements by directly interpolating the date, start_date, and end_date arguments into query text. No parameter binding, strict date parsing, or allowlist validation is shown.

If an application copies this implementation and passes attacker-controlled values to these functions, crafted input can terminate the intended string literal and append SQL syntax. The resulting statement is then passed to execute_query() under the application's database identity.

The exact exploit syntax and whether stacked statements are possible depend on the database engine, driver, and execute_query() implementation. Even where multiple statements are disabled, an attacker may still be able to modify predicates, bypass intended date constraints, or extract data through union-, error-, or time-based techniques.

Attack Path

  1. An application adopts the documented query implementation.
  2. A date argument becomes controllable through an API parameter, form field, generated Agent input, or another untrusted source.
  3. An attacker supplies a value containing a quote and additional SQL syntax.
  4. Direct interpolation incorporates that syntax into the SQL statement.
  5. execute_query() submits the modified query to the datab ...[truncated 798 chars]
Remediation
View remediation

Remediation Suggestions

Use database-driver parameter binding instead of inserting values into SQL text:

python
def get_dau(date):
    query = """
    SELECT COUNT(DISTINCT user_id)
    FROM user_behavior
    WHERE event_date = %s
      AND event_type IN ('view', 'search', 'add_cart', 'order')
    """
    return execute_query(query, (date,))


def get_gmv(start_date, end_date):
    query = """
    SELECT SUM(order_amount)
    FROM orders
    WHERE order_status IN ('paid', 'shipped', 'completed')
      AND payment_status = 'success'
      AND order_date BETWEEN %s AND %s
    """
    return execute_query(query, (start_date, end_date))

The placeholder syntax must be adapted to the actual database driver, such as ?, %s, $1, or named placeholders.

Additional hardening should include:

  1. Parse all incoming dates into strict date or datetime objects before database use.
  2. Reject malformed values rather than attempting to sanitize SQL fragments.
  3. Ensure execute_query() accepts query parameters separately and never performs string formatting internally.
  4. Run queries through a least-privileged, preferably read-only database account.
  5. Disable stacked statements and unnecessary database capabilities where supported.
  6. Add tests containing quotes, SQL metacharacters, comments, and malformed dates to verify that inputs remain data rather than executable SQL.
  7. Clearly label documentation snippets as secure production patterns so generated implementations do not reproduce unsafe interpolation.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains broad business phrases like '运营需求', '产品协同', and '验收标准' that are likely to appear in normal conversation, increasing the chance the skill activates unintentionally. This can cause the agent to inject lengthy workflow behavior or business-document generation into unrelated chats, creating prompt-scope confusion and reducing user control over when the skill runs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing instructions and examples exclusively in Chinese, including the title, usage guidance, and feature descriptions. Under the language/locale policy rule, forcing a specific language without user opt-in can be a policy concern when no alternative language option or explicit locale justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language instructions, examples, and metadata are entirely Chinese, which effectively imposes a language choice on users. There is no note that the skill is China-region-specific or that users may opt into another language, so this can violate language/locale choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This manifest contains user-facing natural-language descriptions and comments exclusively in Chinese, but it does not document that the skill is intended only for Chinese-speaking users or a China-specific context. Under the language/locale policy, forcing a specific language without opt-in or documented justification can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON manifest-like file uses Chinese text for the project and requirement names, but provides no indication that the skill is region-specific or that users can opt into the language. Under the natural-language policy rule, forcing a specific language without documented choice or justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file consists entirely of Chinese-language instructions and content, beginning with the title on L001 and continuing throughout the document. Under the policy rule for natural-language violations, forcing a specific language without user opt-in or a documented justification can be considered a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese and does not indicate that language selection is optional or that the content is intentionally limited to a Chinese-speaking or region-specific audience. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.