Back to skill

Security audit

Clutch

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its CAD-generation purpose, but it submits design data to a third-party service and gives unsafe shell-command patterns for untrusted values.

Review before installing. Use this only if you are comfortable sending clutch design parameters to jixietools.com and receiving a guest access link. Agents should implement the API calls with a structured HTTP client or JSON serializer, not by interpolating raw user input or returned filenames into shell commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:85
Finding

Shell Command Injection Through Unsafe JSON Interpolation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出离合器产品

  1. 用 curl 获取离合器列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出离合器产品

  1. 用 curl 获取离合器列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回结构:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to automatically create a guest production sheet and disclose a publicly accessible tracking URL without first obtaining explicit user consent for external submission. This can cause user-supplied design parameters or business-sensitive manufacturing data to be transmitted to a third-party service and exposed via bearer-style guest links, creating confidentiality and privacy risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L003 将“做一个离合器”列为触发语,这种表述较口语化且缺少上下文约束,可能与普通对话或非 CAD 制图请求重叠。该描述也未提供排除条件或更明确的触发边界,容易造成意外调用。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This step sends user-influenced parameter data to an external API to obtain dropdown options before the user is clearly warned that their data will leave the local system. Even though the transmitted value may initially be blank, the workflow normalizes unsolicited third-party transmission of task context and can expand to sensitive engineering inputs in practice.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

  • 有 options_source 的参数(下拉选项类型): 先进行一次预计算获取 dropdown 选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"有选项的参数名": ""}}'
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The incremental modification step repeatedly transmits changed parameters plus a persistent filename token to an external backend. Because the filename ties the session to a server-side Excel/job state, these requests may expose sensitive engineering values and enable continued manipulation of a remotely stored artifact without explicit, per-stage user consent.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

L213 明确规定“用中文与用户对话”,属于固定语言要求,但文档没有提供用户选择语言的选项,也未说明该限制是出于区域合规或产品范围需要。根据语言/区域政策,这种无选择的强制语言约束应视为自然语言策略违规。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.