Back to skill

Security audit

Heat Exchanger

Security checks for vulnerabilities and agentic risk

Overview

This skill performs a coherent heat-exchanger CAD workflow, but it sends potentially sensitive engineering parameters to a third-party service and creates unauthenticated guest links without enough user-facing consent or access warnings.

Review before installing. This skill may send proprietary CAD or engineering inputs to jixietools.com and create a guest link/code that could expose job status or generated files to anyone who receives it. Use only with data you are comfortable sharing with that service, and prefer an implementation that serializes JSON safely instead of inserting user input into shell commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:78
Finding

Shell Command Injection Through Unsafely Interpolated User Input

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出换热器产品

  1. 用 curl 获取换热器列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出换热器产品

  1. 用 curl 获取换热器列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回结构:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough that ordinary user requests about heat exchangers may automatically invoke this skill and start a workflow that sends user-provided engineering parameters to an external service. In this skill’s context, accidental invocation matters because later steps create guest-access production sheets without authentication, so over-triggering increases the chance of unintended data disclosure and external transmission.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L014 明确写明“换热器分类 ID: 35”,但 L031 的实际请求却使用 category_id=8。这会让技能文档声明的目标对象与实际执行的产品列表来源产生直接矛盾,属于文档与执行步骤相互冲突。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This step transmits user-related input to an external service to obtain dropdown options, and the skill does not frame this as a consented data transfer. Although the specific example posts an empty value, the broader mechanism normalizes sending potentially sensitive design parameters off-platform, making the external transmission itself the security concern in this context.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

  • 有 options_source 的参数(下拉选项类型): 先进行一次预计算获取 dropdown 选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"有选项的参数名": ""}}'
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to collect detailed design parameters and POST them to a third-party service, but it does not require informing the user or obtaining consent before transmission. Engineering specifications can be commercially sensitive, so silent transfer to an external endpoint creates a real confidentiality and privacy risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The incremental update flow sends modified design parameters plus a persistent filename token to an external service. That combination can expose proprietary engineering data and ties multiple revisions to the same externally managed artifact, increasing confidentiality risk if the third-party service or token handling is weak.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill creates and uses a guest-access production sheet and shareable URL/code without authentication, but does not warn the user that anyone with the link or code may be able to view the job status and resulting files. In context, this is more dangerous because the generated artifacts are CAD/design outputs that may contain proprietary engineering details.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction "用中文与用户对话" forces a specific language for the interaction. This is a natural-language policy concern because it does not offer the user a language choice or document a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.