Back to skill

Security audit

安装工程算量

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated local DWG quantity-reporting purpose, but it under-discloses automatic execution of a validator found through environment/local skill paths.

Install only if you trust the local cad-file-reader skill and any CAD_SKILL_DIR path in your environment. Treat --cad-measurement as capable of launching cad-file-reader's cad_validate.sh, and run it only on intended local files in a controlled workspace. Review output paths because JSON/XLSX files are written locally and may overwrite existing files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (14)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese, starting with the title at L01, with no indication that language selection is optional or that the skill is region-specific. Under the policy rule for natural-language violations, forcing a specific language without opt-in is a reportable locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README’s instructional content and usage guidance are entirely in Chinese, which effectively forces a specific language for users without stating that the skill is region- or language-specific. Under the policy, a skill should not impose a locale/language constraint unless it is explicitly justified or offers user choice.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documentation includes executable shell commands and references to scripts that read DWG/JSON files and generate XLSX output, but it does not declare any explicit tool restrictions such as allowed-tools or permissions. In an agent setting, this creates unnecessary capability ambiguity: a host may permit shell, file reads, writes, or environment access broader than intended, increasing the risk of unintended file access or command execution if the skill is invoked on untrusted inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This JSON file’s purpose and all operational guidance are written only in Chinese, which effectively constrains use to a specific language/locale. The file does not indicate any user choice, opt-in, or documented justification for restricting the skill to Chinese-language operation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains user-facing natural-language content almost entirely in Chinese, including the module docstring, worksheet labels, status messages, and argparse help text. That effectively constrains the skill's interface to a specific language without any visible opt-in or alternative locale selection, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code performs environment-based discovery of another skill directory and executes its script, which is behavior outside the manifest's described extraction/reporting role. Hidden cross-skill execution reduces transparency and can enable privilege/trust-boundary violations if the discovered dependency is swapped or poisoned.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's stated purpose is quantity extraction and reporting, but it also invokes an external shell validator script. That expands the attack surface beyond expected data processing behavior and makes the skill more dangerous because untrusted input handling now includes execution of external code paths unrelated to core functionality.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The code executes an external program via subprocess using a path derived from environment-controlled discovery logic. Although it passes an argument list rather than a shell string, it still allows execution of an attacker-selected script or binary if CAD_SKILL_DIR or the discovered directory is manipulated, which is arbitrary code execution in the context of the running user.

Content

Scanner excerpt · scripts/mep_plan.py (reported line 816)May include surrounding context.

python
if not validator.exists():
        return {}
    try:
        r = subprocess.run([str(validator), path], capture_output=True, text=True, timeout=180)
    except Exception as exc:
        return {"ok": False, "errors": [f"{type(exc).__name__}: {exc}"]}
    errors = []

Tainted flow: 'validator' from os.environ.get (line 812, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
98% confidence
Finding

There is a tainted flow from os.environ.get("CAD_SKILL_DIR") into subprocess.run through path construction, enabling environment-based control over what executable is launched. In agent or CI contexts, environment variables are often easier to influence than code, so this creates a practical arbitrary-command execution vector despite not invoking a shell.

Content

Scanner excerpt · scripts/mep_plan.py (reported line 816)May include surrounding context.

python
if not validator.exists():
        return {}
    try:
        r = subprocess.run([str(validator), path], capture_output=True, text=True, timeout=180)
    except Exception as exc:
        return {"ok": False, "errors": [f"{type(exc).__name__}: {exc}"]}
    errors = []

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language fields throughout the JSON are written entirely in Chinese, and there is no indication that users may select another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON file includes natural-language values in Chinese for the riser example name and note. Because the file provides no indication that the skill is region-specific or that users can choose their language/locale, it may impose a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The script creates and saves an .xlsx file to a user-supplied path via wb.save(out). While it prints the path after saving, there is no prior confirmation, warning comment, or help text about the file-write side effect or possible overwrite behavior of the chosen output path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The CLI does not clearly disclose that providing --cad-measurement may trigger execution of an external validator script discovered from the environment or local skill directories. Lack of disclosure is not the root issue, but in this case it compounds the hidden execution behavior and makes risky side effects harder for users to evaluate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The module docstring is written entirely in Chinese and provides the usage instruction only in that language. For a general-purpose test script, this can amount to a language/locale policy issue because it does not offer an alternative language or indicate that the script is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.