T09 · Insecure Skill Coding Practices
- Location
SKILL.md:78- Finding
Shell Command Injection Through Unsafely Interpolated User Input
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill performs a coherent heat-exchanger CAD workflow, but it sends potentially sensitive engineering parameters to a third-party service and creates unauthenticated guest links without enough user-facing consent or access warnings.
Review before installing. This skill may send proprietary CAD or engineering inputs to jixietools.com and create a guest link/code that could expose job status or generated files to anyone who receives it. Use only with data you are comfortable sharing with that service, and prefer an implementation that serializes JSON safely instead of inserting user input into shell commands.
SKILL.md:78Shell Command Injection Through Unsafely Interpolated User Input
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
用户选择后,获取该产品的参数定义:
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool
返回结构:
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
The trigger phrases are broad enough that ordinary user requests about heat exchangers may automatically invoke this skill and start a workflow that sends user-provided engineering parameters to an external service. In this skill’s context, accidental invocation matters because later steps create guest-access production sheets without authentication, so over-triggering increases the chance of unintended data disclosure and external transmission.
L014 明确写明“换热器分类 ID: 35”,但 L031 的实际请求却使用 category_id=8。这会让技能文档声明的目标对象与实际执行的产品列表来源产生直接矛盾,属于文档与执行步骤相互冲突。
This step transmits user-related input to an external service to obtain dropdown options, and the skill does not frame this as a consented data transfer. Although the specific example posts an empty value, the broader mechanism normalizes sending potentially sensitive design parameters off-platform, making the external transmission itself the security concern in this context.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"有选项的参数名": ""}}'
The skill instructs the agent to collect detailed design parameters and POST them to a third-party service, but it does not require informing the user or obtaining consent before transmission. Engineering specifications can be commercially sensitive, so silent transfer to an external endpoint creates a real confidentiality and privacy risk.
The incremental update flow sends modified design parameters plus a persistent filename token to an external service. That combination can expose proprietary engineering data and ties multiple revisions to the same externally managed artifact, increasing confidentiality risk if the third-party service or token handling is weak.
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
-H "Content-Type: application/json" \
-d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
The skill creates and uses a guest-access production sheet and shareable URL/code without authentication, but does not warn the user that anyone with the link or code may be able to view the job status and resulting files. In context, this is more dangerous because the generated artifacts are CAD/design outputs that may contain proprietary engineering details.
The instruction "用中文与用户对话" forces a specific language for the interaction. This is a natural-language policy concern because it does not offer the user a language choice or document a justified region-specific requirement.
No suspicious patterns detected.