Back to skill

Security audit

Jack

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed CAD workflow, but it creates persistent guest production sheets on an external service and uses unsafe shell-style API templates that deserve review before installation.

Review this skill before installing. Only use it if you are comfortable sending jack design parameters to jixietools.com and having the service create a guest production sheet/link. Prefer an implementation that uses a structured HTTP client instead of shell command templates, and require explicit confirmation before creating the guest production sheet.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:79
Finding

Unsafe Shell Command Construction Allows Command Injection

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 79–81, 91–93, 131–133, and 144–146
Vulnerability Type: Shell command injection through unsafe interpolation into JSON and command-line arguments
Risk Level: Medium

Vulnerable Code

Lines 79–81:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"有选项的参数名": ""}}'

Lines 91–93:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"参数名1": "值1", "参数名2": "值2", ...}}'

Lines 131–133:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'

Lines 144–146:

bash
curl -s -X POST "https://jixietools.com/api/v1/production_sheets/guest_create" \
  -H "Content-Type: application/json" \
  -d '{"product_id": PRODUCT_ID, "ref": "保存的filename"}'

Technical Analysis

The Skill instructs an agent to construct shell commands by inserting parameter names, parameter values, product identifiers, and API-returned filenames directly into quoted command strings. Several of these values originate from users or from an external API and must therefore be considered untrusted.

The JSON body is enclosed in a shell single-quoted argument. If an inserted value contains a single quote, it can terminate that argument. Shell metacharacters following the quote may then be interpreted as additional commands. JSON escaping alone is insufficient because shell parsing occurs before curl receives the request.

The vulnerability becomes exploitable when an agent follows these templates through textual interpolation and executes the resulting command using a shell. The Markdown file does not itself execute commands, but its ...[truncated 2012 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace shell command templates with a structured HTTP client that accepts the URL, headers, and JSON body as separate typed values.
  2. Serialize request bodies using a standard JSON library rather than manually concatenating JSON strings.
  3. If curl must be used, generate the request body with a JSON serializer and invoke curl without a shell, passing each argument separately through a process API.
  4. Never interpolate user-controlled or API-controlled values into command text, including parameter names, parameter values, product IDs, filenames, and guest codes.
  5. Validate PRODUCT_ID as an integer and constrain API-returned identifiers such as filename and guest_code to documented character sets and maximum lengths.
  6. Treat all remote API fields as untrusted, even when returned by the expected HTTPS origin.
  7. Run network operations in a restricted environment with minimal filesystem access, no unnecessary credentials, and no elevated privileges.
  8. Add tests containing quotes, backslashes, newlines, command separators, and shell substitution syntax to verify that inputs remain data and cannot alter command structure.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出千斤顶产品

  1. 用 curl 获取千斤顶列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

Step 1: 列出千斤顶产品

  1. 用 curl 获取千斤顶列表:
    bash
    curl -s "https://jixietools.com/api/v1/products?category_id=8" | python3 -m json.tool
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回结构:

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase set includes very broad terms such as 'jack', which are highly ambiguous and can match ordinary conversation unrelated to mechanical jacks. Because the skill can send data to an external API and create guest production orders, accidental activation materially increases the chance of unintended external actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill sends user-supplied or workflow-derived parameter data to an external domain for pre-calculation of dropdown options. Any external transmission of design or manufacturing parameters can expose sensitive business information, and the skill provides no consent boundary, data minimization statement, or trust validation for the remote service.

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

  • 有 options_source 的参数(下拉选项类型): 先进行一次预计算获取 dropdown 选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"有选项的参数名": ""}}'
    

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The incremental update flow repeatedly transmits changed parameters and a persistent filename token to the external API. That filename acts as a workflow handle linking all edits to the same server-side artifact, so leakage or unintended transmission can expose or alter an in-progress design session on the third-party service.

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

  1. 收集要修改的参数名和新值
  2. 构建增量请求:只包含变化的参数 + filename:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"修改的参数名": "新值"}, "filename": "之前保存的filename"}'
    

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a CAD drawing generator, but it instructs the agent to create guest production orders, monitor their status, and direct the user to purchase-oriented flows. This expands the skill from informational/design assistance into real-world transaction initiation without clearly disclosing that broader capability in the manifest, increasing the chance of unintended order creation and user surprise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented workflow goes beyond generating drawings and includes creating manufacturing orders and nudging the user toward downstream purchasing actions. This is risky because a user invoking a design tool may not expect operational actions that persist on an external service and could trigger business workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

交互规则明确要求“用中文与用户对话”,属于语言/locale 的硬性约束,但文档中没有提供用户选择语言的机制,也没有说明这是特定区域合规或业务必需。根据规则,这构成自然语言层面的语言政策问题。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The top-level documentation frames the skill as a CAD assistant, while the body implements a production-order assistant workflow. This mismatch weakens user understanding of what the skill will do and can lead to overbroad invocation of actions that affect external systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.