Back to skill

Security audit

Suspension

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed suspension CAD workflow for JixieTools, but it sends user design parameters to an external guest production service.

Install only if you are comfortable sending suspension design inputs to jixietools.com and receiving a no-login guest link for the resulting production sheet. Avoid entering proprietary or confidential engineering data unless that external workflow is acceptable for your project.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Step 1: 列出产品

用 curl 获取悬架列表:

bash
curl -s "https://jixietools.com/api/v1/products?category_id=26" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Step 1: 列出产品

用 curl 获取悬架列表:

bash
curl -s "https://jixietools.com/api/v1/products?category_id=26" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回包含 input_params、output_params、debug_params、coefficient_params 四类参数。

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use this skill when the user says "悬架", "生成悬架图纸", "做一个悬架", or "suspension". At least "悬架", "做一个悬架", and "suspension" are broad phrases that could appear in normal conversation without a clear intent to invoke this specific CAD-generation workflow, and the file provides no exclusion conditions or negative examples.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill collects detailed user-supplied engineering/design parameters and sends them to a third-party API, then creates a production sheet, all without warning the user or obtaining consent. This creates a real confidentiality and privacy risk because proprietary design data may be transmitted externally and persisted under a guest workflow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

The skill explicitly instructs transmitting user-provided suspension parameters to an external service for pre-calculation and later full calculation. In this context, the data is likely commercially sensitive engineering input, so external transmission without trust validation, consent, or minimization exposes proprietary information and may leak project details.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction "用中文与用户对话" forces a specific language for all interactions. The file does not provide an opt-in, fallback, or justification that this is a region-specific or compliance-bound tool, so it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.