Back to skill

Security audit

Distillation

Security checks for vulnerabilities and agentic risk

Overview

Review before installing: the skill uses an external CAD service and has inconsistent product-category instructions that could send design details into the wrong workflow.

Install only if you are comfortable sending CAD/design parameters to jixietools.com and receiving unauthenticated guest links for generated results. Before use, the publisher should fix the category mismatch, add explicit privacy/link-sharing warnings, and replace shell interpolation examples with a safe structured HTTP implementation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:75
Finding

Potential Shell Command Injection Through Unsafe JSON Payload Construction

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:75-78, SKILL.md:88-91, and SKILL.md:135-139
Vulnerability Type: Shell command injection caused by unsafe interpolation into shell and JSON contexts
Risk Level: Medium

Vulnerable Code

SKILL.md:75-78:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"有选项的参数名": ""}}'

SKILL.md:88-91:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"参数名1": "值1", "参数名2": "值2", ...}}'

SKILL.md:135-139:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'

Technical Analysis

The Skill instructs an Agent to collect parameter names and values and place them into JSON request bodies embedded inside single-quoted shell arguments. It does not require safe JSON serialization, shell escaping, argument-array execution, or validation of the substituted values.

JSON escaping alone is not sufficient when a command is interpreted by a shell. If an implementation performs direct textual substitution, a single quote in an attacker-controlled value can terminate the shell argument. The remaining input can then introduce shell operators and commands. Conversely, manual shell escaping without proper JSON serialization can produce malformed or semantically altered JSON.

The commands are documentation templates rather than directly executable project code, so exploitability depends on how the consuming Agent materializes and executes them. An Agent that constructs a shell command string by replacing the placeholders is vulnerable. An implementation that passes arguments without a shell and serializes the payload using a JSON ...[truncated 1962 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not construct shell command strings by interpolating user-controlled parameter names, values, filenames, product identifiers, or guest codes.
  2. Prefer a structured HTTP client that accepts native objects and performs JSON serialization automatically. For example, use Python with requests or urllib.request and pass a dictionary to the JSON encoder.
  3. If curl is required, generate the request body with a trusted JSON serializer and place it in a securely created temporary file. Submit it with --data-binary @file and remove the file after use.
  4. Invoke subprocesses with an argument array and with shell interpretation disabled. Avoid shell=True, bash -c, sh -c, eval, and equivalent command-string execution.
  5. Validate product identifiers against the product list returned by the API. Treat filenames and guest codes as opaque server-issued values and reject values outside their documented format before using them in URLs or commands.
  6. Apply type, length, and range validation to user-entered engineering parameters. Validation should supplement, not replace, context-appropriate serialization.
  7. Update the Skill instructions to explicitly prohibit direct placeholder substitution into shell commands and provide a safe reference implementation.
  8. Run the Agent with minimum filesystem and network privileges so that any command-injection defect has limited impact.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims to generate distillation-tower CAD drawings but instructs the agent to query category_id=8 while separately declaring distillation category ID 33, then shows gear-reducer examples unrelated to the stated purpose. This mismatch can cause the agent to operate on the wrong product class, collect incorrect parameters, and generate or expose unintended downstream artifacts, making the workflow unsafe and unreliable.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出精馏塔产品

  1. 用 curl 获取精馏塔列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出精馏塔产品

  1. 用 curl 获取精馏塔列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回结构:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says to use this skill when the user says phrases like "精馏塔" or "做一个精馏塔", which are broad natural expressions that could appear in ordinary discussion rather than an explicit request to generate CAD drawings. It also does not provide limiting conditions or negative examples to distinguish casual mention from intentional invocation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The skill instructs the agent to transmit user-supplied parameter data to an external third-party API in order to derive dropdown values, without any consent boundary or data-minimization guidance. Even though only one parameter is shown in the example, this still establishes an external data flow that may leak sensitive design intent or proprietary engineering inputs.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

  • 有 options_source 的参数(下拉选项类型): 先进行一次预计算获取 dropdown 选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"有选项的参数名": ""}}'
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The incremental update step sends modified parameters plus a persistent filename token to an external service, creating a continuing external data flow tied to a server-side workbook/session. If users adjust sensitive engineering, pricing, or design variables, those values are repeatedly disclosed to the third party and linked across requests.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill creates a guest-access production sheet and exposes a bearer-style URL/code without warning the user that anyone with the link may view the production status and resulting files. Because the workflow is explicitly unauthenticated, omission of a warning increases the risk of unintended sharing and disclosure of potentially sensitive design outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction "用中文与用户对话" mandates a specific language for all interactions. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific; this file provides no opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.