Back to skill

Security audit

Driveshaft

Security checks for vulnerabilities and agentic risk

Overview

The skill’s CAD workflow is mostly coherent, but it needs review because its shell command templates can be unsafe with user-supplied values and it creates no-login guest links for design outputs.

Install only if you are comfortable sending driveshaft design parameters to jixietools.com and sharing bearer-style guest links carefully. Agents should avoid literal shell interpolation for the shown curl examples; use structured JSON serialization or a shell-free HTTP client before submitting user-entered values.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:89
Finding

Shell Command Injection in Initial Calculation Request

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 89–92
Vulnerability Type: Shell command injection through unsafe JSON construction
Risk Level: High

Vulnerable Code

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"参数名1": "值1", "参数名2": "值2", ...}}'

Technical Analysis

The Skill directs the agent to collect parameter values from the user and insert them into JSON enclosed in a single-quoted shell argument. It does not require JSON serialization, shell escaping, input validation, or use of a shell-free HTTP client.

A user-provided value containing a single quote can terminate the -d argument. Subsequent shell metacharacters can then be interpreted as commands rather than request data. For example, a value following the schematic form '; id; # could close the quoted argument, run a local command, and comment out the remainder.

Exploitation depends on an implementing agent substituting values directly into this documented shell template, but that is precisely the workflow the Skill prescribes.

Attack Path

  1. The Skill asks the user for a product parameter.
  2. The attacker supplies a value containing a single quote followed by shell syntax.
  3. The agent directly substitutes that value into the documented curl -d '...' command.
  4. The single quote terminates the intended JSON shell argument.
  5. The shell parses the remaining attacker-controlled text as one or more local commands.
  6. Those commands execute with the operating-system privileges of the agent process.

Impact Assessment

Successful exploitation permits arbitrary command execution within the agent's local security context. The attacker could read files accessible to the agent, alter project or user files, access environment variables, invoke installed tools, make additional network requests, or establish further com ...[truncated 286 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not interpolate parameter names or values into shell command strings.
  • Prefer an HTTP library that accepts a structured object and serializes it through a JSON API, such as Python requests.post(url, json=payload).
  • If curl is required, construct the request body with a JSON serializer such as jq -n --arg, save it to a securely created file, and submit it using --data-binary @file.
  • Pass commands as argument arrays without invoking a shell.
  • Validate each value against the parameter schema returned by the service, including expected type, range, length, and enumerated options.
  • Treat validation as defense in depth; do not rely on character filtering as a replacement for safe serialization and shell avoidance.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:146
Finding

Shell Command Injection in Incremental Calculation Request

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 146–149
Vulnerability Type: Shell command injection through unsafe interpolation of modified values and filenames
Risk Level: High

Vulnerable Code

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'

Technical Analysis

The incremental-update workflow places a user-selected parameter name, a user-supplied replacement value, and a previously returned filename inside a single-quoted shell argument. None of these dynamic fields is safely serialized or escaped.

A malicious replacement value containing ' can escape the quoted JSON data and introduce shell syntax. Parameter names and the remote filename also cross trust boundaries and could create the same condition if a compromised or malicious API response supplies unexpected characters.

Because this operation occurs after a legitimate calculation session has begun, an attacker can defer the injection until the modification phase, where dynamic values are explicitly expected.

Attack Path

  1. The user completes the initial parameter collection and calculation.
  2. When asked whether a parameter needs modification, the attacker supplies a replacement value containing a quote-breaking sequence and shell command.
  3. The agent inserts the value directly into the incremental curl template.
  4. The injected single quote closes the JSON shell argument.
  5. The local shell executes the appended command using the agent process's permissions.
  6. Alternatively, a compromised API could return a malicious filename or parameter name that reaches the same command-construction sink.

Impact Assessment

Exploitation can produce arbitrary local command execution under the agent account. Accessible files, environment data, local tools, and network capabilities ...[truncated 211 chars]

Remediation
View remediation

Remediation Suggestions

  • Build the incremental payload as a native object and serialize it with a trusted JSON library.
  • Send the request through an HTTP client API without shell evaluation.
  • Validate filename against a strict server-defined format before reuse, while still serializing it safely.
  • Restrict modifiable parameter names to the exact keys received in a validated product schema.
  • Enforce expected types, ranges, lengths, and option sets for replacement values.
  • If external command execution cannot be avoided, use an argument-vector API and a securely generated JSON file rather than constructing a command string.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:77
Finding

Shell Command Injection Through Dynamic Dropdown Parameter Name

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 77–80
Vulnerability Type: Shell command injection through an untrusted API-derived parameter name
Risk Level: Medium

Vulnerable Code

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"有选项的参数名": ""}}'

Technical Analysis

The parameter name inserted into this request is derived from the product structure returned by the external API. The Skill instructs the agent to place that dynamic name directly inside a single-quoted JSON shell argument without safe serialization.

If the service or its returned product data is compromised, a parameter name containing a single quote and shell metacharacters can terminate the data argument and inject a local command. HTTPS protects data in transit but does not make application-level response content safe for shell interpolation.

The risk is lower than direct user-value injection because exploitation requires control of, or malicious data from, the API response.

Attack Path

  1. The agent retrieves a product definition from the external service.
  2. A compromised service or product record returns a crafted dropdown parameter name.
  3. The agent substitutes that name into the documented pre-calculation shell command.
  4. Quote-breaking content terminates the intended JSON argument.
  5. The shell interprets the remaining parameter-name content as a local command.
  6. The command runs with the permissions of the agent process.

Impact Assessment

A compromised API response could be converted from passive data into arbitrary local command execution. This could expose or modify resources available to the agent, including files, environment variables, installed tools, and outbound network access. No independent privilege-escalation mechanism is present, so the scope remains limited to the agent's existing perm ...[truncated 8 chars]

Remediation
View remediation

Remediation Suggestions

  • Treat all API response fields as untrusted data.
  • Serialize dynamic parameter names with a proper JSON library rather than embedding them into shell text.
  • Prefer a shell-free HTTP client and pass the payload as a structured object.
  • Validate returned parameter names against a conservative schema and reject control characters, unexpected lengths, and keys not associated with the selected product.
  • Pin the expected API origin and retain TLS certificate validation, but do not treat transport security as a substitute for safe data handling.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出万向传动轴产品

  1. 用 curl 获取万向传动轴列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出万向传动轴产品

  1. 用 curl 获取万向传动轴列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回结构:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Although the static pattern name is imprecise, this step shows the agent reusing a bare filename token to mutate server-side state in an existing Excel-backed workflow. If that filename acts as the sole capability for locating and updating another user's calculation context, predictable or leaked filenames could enable unauthorized modification or cross-user data tampering.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly relies on unauthenticated creation and retrieval of production sheets and instructs the agent to expose guest-access links and guest codes without any privacy warning or minimization guidance. Anyone who obtains the link or code may be able to view manufacturing details, design artifacts, or order status, so the workflow creates an access-control and information-disclosure risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

  • 有 options_source 的参数(下拉选项类型): 先进行一次预计算获取 dropdown 选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"有选项的参数名": ""}}'
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction '用中文与用户对话' forces a specific language for all interactions. This is a natural-language policy issue because the file does not provide user opt-in, language choice, or a documented reason that the skill must be Chinese-only.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states '万向传动轴分类 ID: 34' at L014, but the very first product-listing step uses category_id=8 at L031. This is an active contradiction in the skill instructions about which category the assistant should query, and could cause the skill to retrieve products outside the documented driveshaft category.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.