T09 · Insecure Skill Coding Practices
- Location
SKILL.md:85- Finding
Shell Command Injection Through Unsafe JSON Interpolation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its CAD-generation purpose, but it submits design data to a third-party service and gives unsafe shell-command patterns for untrusted values.
Review before installing. Use this only if you are comfortable sending clutch design parameters to jixietools.com and receiving a guest access link. Agents should implement the API calls with a structured HTTP client or JSON serializer, not by interpolating raw user input or returned filenames into shell commands.
SKILL.md:85Shell Command Injection Through Unsafe JSON Interpolation
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
用户选择后,获取该产品的参数定义:
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool
返回结构:
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
The skill instructs the agent to automatically create a guest production sheet and disclose a publicly accessible tracking URL without first obtaining explicit user consent for external submission. This can cause user-supplied design parameters or business-sensitive manufacturing data to be transmitted to a third-party service and exposed via bearer-style guest links, creating confidentiality and privacy risks.
L003 将“做一个离合器”列为触发语,这种表述较口语化且缺少上下文约束,可能与普通对话或非 CAD 制图请求重叠。该描述也未提供排除条件或更明确的触发边界,容易造成意外调用。
This step sends user-influenced parameter data to an external API to obtain dropdown options before the user is clearly warned that their data will leave the local system. Even though the transmitted value may initially be blank, the workflow normalizes unsolicited third-party transmission of task context and can expand to sensitive engineering inputs in practice.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"有选项的参数名": ""}}'
The incremental modification step repeatedly transmits changed parameters plus a persistent filename token to an external backend. Because the filename ties the session to a server-side Excel/job state, these requests may expose sensitive engineering values and enable continued manipulation of a remotely stored artifact without explicit, per-stage user consent.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
L213 明确规定“用中文与用户对话”,属于固定语言要求,但文档没有提供用户选择语言的选项,也未说明该限制是出于区域合规或产品范围需要。根据语言/区域政策,这种无选择的强制语言约束应视为自然语言策略违规。
No suspicious patterns detected.