Back to skill

Security audit

Server Test Converter

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated purpose, but it turns command text into runnable tests with unsafe code generation and weak execution safeguards.

Install only for a controlled test environment with trusted txt files and trusted filenames. Review generated pytest files before running them, avoid local shell execution of untrusted commands, and add allowlists or blocking for destructive commands before using this on real hosts or devices.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
convert_commands.py:74
Finding

Arbitrary Python Code Injection in Generated Pytest Modules

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The example uses subprocess.run(cmd, shell=True) on a command string that would plausibly originate from txt files being converted into tests. This enables shell injection and arbitrary command execution if any command content is attacker-controlled or insufficiently reviewed, and the surrounding skill context explicitly encourages executing converted commands on local or remote systems.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

方式三: 本地执行

import subprocess def send_a_cmd(cmd, target): result = subprocess.run(cmd, shell=True, capture_output=True) return result.stdout

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger matches broad phrases like server testing or NIC testing, which can cause the skill to activate in conversations that are not actually requesting file conversion. In that context, the skill could steer the agent toward generating or handling command-execution-related artifacts without clear user intent, increasing the chance of unsafe or unintended use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill provides examples for SSH and local shell command execution, including directly executing user-supplied commands, but does not warn that these commands may be untrusted and dangerous. Because the skill converts command files into runnable tests, it normalizes arbitrary command execution on hosts or test servers, which materially increases the risk of destructive or unauthorized actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generator turns untrusted text lines directly into executable pytest code that will run commands on host or R5 targets, with only minimal filtering and logging. In this skill's context, the input files are effectively code-like command sources for server environments, so a malicious or mistaken txt entry could trigger destructive operations, service disruption, or unauthorized system changes when the generated tests are executed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language interface text is entirely Chinese and does not indicate that users may interact in other languages or that the skill is intentionally limited to a Chinese-speaking environment. This can constitute a language-policy issue when a specific language is implicitly forced without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language docstrings and comments are written in Chinese, which imposes a specific language context for users and maintainers. The file does not indicate that this is a region-specific tool or provide any opt-in or alternative language support.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.