Back to skill

Security audit

宝宝取名

Security checks for vulnerabilities and agentic risk

Overview

This paid baby-name skill includes payment and local-file behavior, but important payment, credential, and instruction details are mismatched or under-disclosed.

Do not use this for real payments without review. Require one documented authoritative config file, remove bundled production recipient and secret values, pin and verify the payment dependency, validate order paths, replace local symmetric payment checks with provider-issued signed credentials, and remove instructions asking for hidden reasoning.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
Findings (5)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/file_utils.py:20
Finding

Documented payment-recipient configuration is ignored in favor of a bundled recipient

Content
View full analysis
str: """Get the configuration file path.""" script_dir = os.path.dirname(os.path.abspath(__file__)) return os.path.join(script_dir, "..", "configs", "config.yaml") def load_config() -> dict: """Load the user configuration file.""" config_path = get_config_path() if not os.path.isfile(config_path): raise RuntimeError(f"Configuration file does not exist: {config_path}") with open(config_path, "r", encoding="utf-8") as f: return yaml.safe_load(f) ``` `configs/config.yaml:2-9`: ```yaml crypto: sm4_key: "k3qWnsp+ZzFS+Old/VDtcw==" payment: pay_to: "8f18fb4ccac281a40fb0cf96ec7c2aa8202604081312250020002552zmV8kH3UJyhYdJjFXghUiYLL4FuyrNtvEwiagAzFyufPIN3ePZVMwfMkzyhJD2FuoPrQ118i" service: amount: 1 slug: "baby-name-v2" ``` `configs/config.json:1-7`: ```json { "payTo": "8f18fb4ccac281a40fb0cf96ec7c2aa8202604081312250020002552zmV8kH3UJyhYdJjFXghUiYLL4FuyrNtvEwiagAzFyufPIN3ePZVMwfMkzyhJD2FuoPrQ118i", "sm4Key": "k3qWnsp+ZzFS+Old/VDtcw==", "amount": 1, "skillName": "baby-name", "description": "Baby naming service fee" } ``` ### Technical Analysis The Skill documentation identifies `configs/config.json` as the file through which the operator can customize the payment recipient. Runtime code does not read that file. `get_config_path()` unconditionally selects `configs/config.yaml`, whose `payment.pay_to` field contains a bundled recipient. Consequently, an operator can follow the documented configuration process, change `config.json`, and still have the payment flow use the recipient from `config.yaml`. `scripts/create_order.py` then incorporates that effecti ...[truncated 1187 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/name_generate.py:78
Finding

Bundled SM4 key allows payment credential forgery and payment bypass

Content
View full analysis
tuple: """ Verify the payment credential. Return (pay_status, error_info). """ config = load_config() sm4_key_b64 = config.get("crypto", {}).get("sm4_key") if not sm4_key_b64: return ("ERROR", "Configuration is missing crypto.sm4_key") try: sm4_key = base64.b64decode(sm4_key_b64) except Exception: return ("ERROR", "crypto.sm4_key must be valid Base64") if not is_valid_key(sm4_key): return ("ERROR", "The SM4 key must be 16 bytes") try: decrypted = sm4_decrypt(credential, sm4_key) except Exception as e: return ("ERROR", f"Payment credential decryption failed: {e}") pay_status = "PENDING" try: root = json.loads(decrypted) pay_status = root.get("payStatus", "PENDING") except Exception: pass if pay_status.upper() != "SUCCESS": return (pay_status, f"Payment was not successful; status: {pay_status}") return ("SUCCESS", "") ``` `scripts/sm4_utils.py:11-31`: ```python def sm4_encrypt(plaintext: str, key: bytes) -> str: """ SM4 encryption using ECB mode and PKCS7 padding. """ if not plaintext: raise ValueError("Plaintext must not be empty") if len(key) != 16: raise ValueError("The key must be 16 bytes") padding_len = 16 - (len(plaintext.encode('utf-8')) % 16) padded = plaintext.encode('utf-8') + bytes([padding_len] * padding_len) cipher = Cipher(algorithms.SM4(key), modes.ECB(), backend=default_backend()) encryptor = cipher.encryptor() ciphertext ...[truncated 2238 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/file_utils.py:49
Finding

Unvalidated order path components allow traversal outside the order directory

Content
View full analysis
dict: """Load an order file.""" order_file = os.path.join(get_orders_dir(), indicator, f'{order_no}.json') if not os.path.exists(order_file): raise FileNotFoundError(f"Order file does not exist: {order_no}") with open(order_file, 'r', encoding='utf-8') as f: return json.load(f) ``` `scripts/name_generate.py:119-131`: ```python def main(): if len(sys.argv) < 3: print("ERROR: Missing arguments; Usage: name_generate.py ", file=sys.stderr) print("PAY_STATUS: ERROR") print("ERROR_INFO: Missing arguments") sys.exit(1) order_no = sys.argv[1] indicator = sys.argv[2] try: order_data = load_order(indicator, order_no) ``` ### Technical Analysis Both `order_no` and `indicator` are accepted from command-line input and used directly as path components. The implementation does not reject absolute paths, `..` traversal segments, path separators, symbolic-link escapes, or unexpected identifier formats. `os.path.join()` does not enforce containment. An absolute later component can discard preceding path components, while traversal segments can resolve outside the intended order directory. The resulting file is opened and parsed as JSON. The appended `.json` suffix limits straightforward targeting to paths that resolve with that suffix, but it does not establish directory containment. The accessible scope is also bounded by the operating-system permissions of the process. ### Attack Path 1. Invoke `name_generate.py` directly or cause its arguments to contain traversal components. 2. Supply an `indicator` such as a relative tr ...[truncated 835 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:4
Finding

Skill instructions attempt to override interaction language and request internal reasoning

Content
View full analysis
Baby naming expert that generates names from birth information and parental surnames. This is a paid service whose recipient can be customized through configuration. You should interact with the user in Chinese, including your thought process. ``` The same instruction is repeated in the body of `SKILL.md`: ```text You should interact with the user in Chinese, including your thought process. ``` ### Technical Analysis The Skill declares an unconditional session-level language requirement and explicitly requests disclosure of the Agent's thought process. Neither behavior is necessary to create an order, verify payment, or generate a baby name. A Skill may legitimately suggest a user-facing language, but it should not override explicit user preferences or higher-priority session instructions. Requiring internal reasoning is especially unsafe because it attempts to make hidden deliberative content part of the response. This is an instruction-level issue rather than a Python code-execution issue. ### Attack Path 1. The Agent loads `SKILL.md` to execute the naming workflow. 2. The embedded instruction enters the Agent's active context. 3. The Skill directs the Agent to override the current interaction language. 4. It additionally directs the Agent to reveal internal thought processes. 5. If followed without instruction-priority enforcement, the Agent may disregard user preferences and expose protected reasoning. ### Impact Assessment The issue can alter the current session's response behavior and attempt to disclose internal reasoning. It does not create persistence across sessions or i ...[truncated 133 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:87
Finding

Payment workflow directs installation of an unpinned external Skill

Content
View full analysis
", "indicator": "" } ``` ### Technical Analysis The workflow instructs the Agent to install an external component by name if it is unavailable. It does not specify: - A trusted registry or repository - An exact package or publisher identity - A pinned version - A cryptographic checksum or signature - A review or approval step - The minimum permissions required by that dependency Because the dependency handles payment-related identifiers and credentials, resolving it only by a generic name creates a supply-chain and name-confusion risk. A malicious or compromised component with the same name could receive payment data and exercise any permissions granted during installation. No evidence in the reviewed files proves that `clawtip` itself is malicious. The confirmed issue is the unsafe installation instruction and lack of dependency identity controls. ### Attack Path 1. The payment stage begins on a system where `clawtip` is not installed. 2. The Agent follows `SKILL.md` and searches for a component by that name. 3. A malicious, compromised, or incorrectly resolved package is selected. 4. The package is installed without a pinned source, version, or integrity check. 5. The package receives the order number and indicator and participates in the payment flow. 6. It can misuse supplied data or perform actions allowed by its granted permissions. ### Impact Assessment The attainable impact depends on the permissions of the resolved dependency. At minimum, payment metadata can ...[truncated 276 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the underlying code is primarily doing encryption/decryption or payment-related credential handling while being advertised as a baby-name generator, that is a significant purpose-obfuscation issue. Concealed cryptographic and credential-processing behavior is especially risky because it can mask exfiltration, covert validation flows, or hidden monetization paths.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the underlying code is primarily doing encryption/decryption or payment-related credential handling while being advertised as a baby-name generator, that is a significant purpose-obfuscation issue. Concealed cryptographic and credential-processing behavior is especially risky because it can mask exfiltration, covert validation flows, or hidden monetization paths.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the underlying code is primarily doing encryption/decryption or payment-related credential handling while being advertised as a baby-name generator, that is a significant purpose-obfuscation issue. Concealed cryptographic and credential-processing behavior is especially risky because it can mask exfiltration, covert validation flows, or hidden monetization paths.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the underlying code is primarily doing encryption/decryption or payment-related credential handling while being advertised as a baby-name generator, that is a significant purpose-obfuscation issue. Concealed cryptographic and credential-processing behavior is especially risky because it can mask exfiltration, covert validation flows, or hidden monetization paths.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Explicitly requiring exposure of the model's internal reasoning is a direct leakage instruction. In a skill that also touches payment, credentials, and local configuration, such leakage is more dangerous because it may expose security-relevant logic, validation criteria, or sensitive hidden context during user interactions.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The repeated directive creates a persistent and intentional exfiltration channel for internal reasoning. Given the broader skill context of payments and credentials, that materially raises the risk of leaking sensitive operational details or policy constraints to users.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · configs/config.json (reported line 2)May include surrounding context.

json
{
  "payTo": "8f18fb4ccac281a40fb0cf96ec7c2aa8202604081312250020002552zmV8kH3UJyhYdJjFXghUiYLL4FuyrNtvEwiagAzFyufPIN3ePZVMwfMkzyhJD2FuoPrQ118i",
  "sm4Key": "k3qWnsp+ZzFS+Old/VDtcw==",
  "amount": 1,
  "skillName": "baby-name",
  "description": "宝宝取名服务费用"
}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to reveal the assistant's thought process asks the model to expose internal reasoning to end users. This is dangerous because chain-of-thought disclosure can leak hidden policies, internal decision criteria, or other sensitive contextual information that should remain non-public.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description explicitly says the skill should use Chinese with the user, which is a natural-language locale constraint. The file does not offer any user choice or opt-in for language, so this conflicts with the policy against forcing a specific language.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Repeating the requirement to expose internal reasoning reinforces an intentional prompt-level data leakage pattern. Repetition makes accidental compliance more likely and increases the chance of systematic disclosure in every interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This line repeats an instruction that the skill must communicate in Chinese, creating a language policy issue. There is no indication that the user can select another language or explicitly opt in to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code uses Chinese-only natural-language docstrings and user-facing runtime messages, indicating the skill is effectively constrained to a specific language. Under the policy, forcing a specific language without opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill’s stated purpose is baby-name generation, but this file also loads a payment-related configuration and persists order records locally. That mismatch expands the trust boundary and introduces handling of billing and user data without clear necessity, which is risky in an agent skill because users may not expect local financial/workflow state to be created.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code computes filesystem paths under the user’s home directory and writes/reads order files based on externally supplied indicator and order number values, without sanitization or canonical path checks. If these values are attacker-influenced elsewhere in the skill, this can enable path traversal or unauthorized file overwrite/read within the user’s accessible filesystem, made more concerning because local order storage is unrelated to the advertised baby-name function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s description and all user-facing messages are hard-coded in Chinese, and the script emits Chinese output such as payment status and generated-name text without any opt-in or locale selection. This is a natural-language policy concern because the skill imposes a specific language on users rather than offering a choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill advertises personalized baby naming based on 生辰八字 and parents' surnames, but the implementation ignores those inputs and returns names from a fixed gender-based list. In a paid service, this is a deceptive implementation that can mislead users into paying for a level of customization and analysis that is not actually performed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The function claims to generate names according to user requirements, but in practice only infers gender from a few keywords and selects from static templates. This creates a trust and integrity issue because users may disclose sensitive family or birth information expecting tailored processing that never occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code loads crypto.sm4_key from configuration and uses it to decrypt payCredential, which is a sensitive credential-handling operation. While there are internal comments, there is no user-facing warning, confirmation, or disclosure in this file about accessing cryptographic material and processing payment credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

manifest 强调的是中文交互的宝宝取名专家及付费收款配置,而此文件的全部行为都是 SM4 ECB 模式加密、解密和密钥校验,没有体现任何取名生成或收费处理逻辑。即使加密可作为某些实现细节存在,这里暴露的是完整独立的密码学工具模块,和描述中的核心行为明显不一致。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该文件实现的是通用的 SM4 对称加密、解密与密钥校验能力,而 manifest 将技能描述为根据生辰八字、父母姓氏生成宝宝名字的付费取名服务。取名功能本身并不明显需要在技能内部暴露独立的底层密码学原语,因此这属于超出场景所需的能力。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The config contains a Chinese-only description string, which indicates the skill is presented in a fixed language without any visible user choice or opt-in. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s natural-language strings and documentation are entirely in Chinese, including user-facing error text at L24, with no indication that the skill is region-specific or that users can choose a language. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural language exclusively in Chinese in the module docstring, function docstrings, and raised error messages. Under the policy for natural-language violations, forcing a specific language without user opt-in should be flagged when no alternative language or locale choice is offered.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.