Back to skill

Security audit

Hydraulic System

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent CAD-generation purpose, but its instructions encourage executing shell commands built from user and API-provided values, which creates a real command-injection risk.

Review before installing. The service integration itself is expected, but this skill should be revised to use a structured HTTP client or safely serialized payloads instead of shell templates, and users should avoid entering confidential engineering data unless they are comfortable sending it to jixietools.com.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:91
Finding

Shell Command Injection Through Initial Calculation Parameters

Content
View full analysis
/tmp/agent_identity ; # ``` could transform the intended `curl` invocation into a sequence that executes `id` locally and comments out the remainder of the generated command. Parameter names obtained from the remote API may create the same problem if they are interpolated without serialization. JSON escaping alone is insufficient if JSON is subsequently embedded in a shell command; both JSON and shell parsing boundaries must be handled safely. The flagged uses of `curl | python3 -m json.tool` do not execute downloaded code. They pass API responses to Python's JSON formatter and therefore do not constitute remote payload retrieval and execution. The confirmed issue is the unsafe construction of request commands. ### Attack Path 1. The Skill requests an input parameter from the user. 2. An attacker supplies a value containing a single quote followed by shell metacharacters and a command. 3. The Agent substitutes that value into the documented `curl -d '...'` template. 4. The injected quote terminates the JSON shell argument. 5. The local shell interprets the attacker's remaining ...[truncated 760 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:137
Finding

Shell Command Injection Through Incremental Calculation Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出液压与气动系统产品

  1. 用 curl 获取液压与气动系统列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出液压与气动系统产品

  1. 用 curl 获取液压与气动系统列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回结构:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Although the rule name says 'external script fetching,' this line really represents direct external POSTing of user-controlled data and a state token to a third-party service via shell command examples. In skill context, that is dangerous because it encourages unrestricted off-platform transmission and normalizes passing sensitive workflow identifiers through ad hoc client-side calls.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The skill instructs the agent to send user-influenced parameter data to an external third-party API to precompute dropdown options. Even though the sample uses an empty value, the surrounding workflow is designed to transmit product context and later user-supplied engineering inputs off-platform, creating a real external data exposure channel without any authentication, minimization, or explicit consent safeguards.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

  • 有 options_source 的参数(下拉选项类型): 先进行一次预计算获取 dropdown 选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"有选项的参数名": ""}}'
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This step directs the agent to transmit modified user parameters plus a persistent filename token to an external service for incremental recalculation. Because the filename acts as a workflow handle to prior server-side state, exposing it alongside user-supplied design values increases the risk of unauthorized access to prior calculations, cross-session mix-ups, or leakage of sensitive engineering/project data to a third party.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction '用中文与用户对话' mandates a specific language for all interactions. The policy allows locale or language constraints only when the user is given a choice or the restriction is clearly justified as region-specific; this file does not provide such opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation states the hydraulic/pneumatic system category ID is 18 at L014, but the actual Step 1 listing command uses category_id=8 at L031. This is an active contradiction in the skill instructions that could cause the agent to fetch the wrong product set, diverging from the documented intent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.