Back to skill

Security audit

CAD 图纸识图与证据提取

Security checks for vulnerabilities and agentic risk

Overview

This CAD-reading skill is coherent and locally focused, with disclosed file parsing, output, dependency installation, caching, and resource-limit behavior.

Install only if you are comfortable with local CAD/PDF files being parsed and derivative reports or caches being written. Prefer the full package or the documented GitHub release source for dependencies, keep custom rule directories trusted, and use explicit cache/output directories for sensitive projects.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (213)

Dangerous chain: eval() wrapping compile

Critical
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The code evaluates rule formulas from JSON files using eval(compile(...)) after only a partial AST allowlist check. Although builtins is removed and names are constrained, this still creates a code-execution surface on untrusted or tampered rule content and relies on a brittle custom sandbox that may be bypassed now or in future edits. In a local CAD-processing skill that loads all JSON rules from a directory, this is especially risky because attackers who can modify rule files can influence execution during analysis.

Content

Scanner excerpt · scripts/cad_interpret.py (reported line 252)May include surrounding context.

python
raise ValueError(f"公式使用了未知变量:{node.id}")
    ns = dict(namespace)
    ns.update(_SAFE_FUNCS)
    return eval(compile(tree, "<rule>", "eval"), {"__builtins__": {}}, ns)


def apply_rule(rule: dict[str, Any], member: dict[str, Any], profile: dict[str, list[str]],

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Resource watchdog logic that can forcibly kill processes with SIGKILL is more than a documentation mismatch because it can affect availability and interfere with shared environments if not tightly scoped. In an automation platform, self-termination or aggressive process control can become dangerous if it targets the wrong process group or is triggered by attacker-supplied inputs that induce resource spikes.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/cad_interpret.py:252