Back to skill

Security audit

Brake

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real brake CAD workflow, but it uses raw shell commands with user-supplied values and sends design parameters to a third-party service, so it should be reviewed before installation.

Install only if you are comfortable sending brake design parameters to jixietools.com. Use a native HTTP client or safely constructed argument arrays rather than interpolating user input into shell commands, and treat the generated guest links and filename handles as sensitive workflow references.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:204
Finding

Forced Third-Party Promotion and Repeated External Redirection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:89
Finding

Shell Command Injection Through Unsafe JSON Interpolation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出制动器产品

  1. 用 curl 获取制动器列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出制动器产品

  1. 用 curl 获取制动器列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回结构:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

L003 列出的触发语中,“做一个制动器”属于自然日常表达,缺少对使用场景、平台上下文或操作边界的限定,容易与普通聊天需求重叠。该描述也未提供排除条件或负例,无法清晰区分何时应激活该 skill、何时不应激活。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill instructs the agent to transmit user-supplied or workflow-derived parameter data to an external domain during pre-calculation to fetch dropdown options. Any external transmission of user-controlled design inputs to a third-party service can expose proprietary engineering requirements or sensitive business data, especially because the skill normalizes sending data off-platform as part of routine interaction.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

  • 有 options_source 的参数(下拉选项类型): 先进行一次预计算获取 dropdown 选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"有选项的参数名": ""}}'
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The incremental update flow sends modified parameters plus a persistent filename token to an external service. This increases exposure because the filename acts as a workflow handle linking all prior calculations, so repeated external submissions can reveal iterative design changes and may allow unintended correlation or tampering if the reference is guessable or reused insecurely.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

L213 明确要求“用中文与用户对话”,属于语言/locale 强制策略。文件中未见用户可选择其他语言的选项,也未说明该限制是基于合规或地区专用场景所必需,因此符合自然语言政策违规条件。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.