Back to skill

Security audit

Tank

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward tank CAD workflow that uses a disclosed external API, but users should know their engineering inputs and generated sheet link leave the local environment.

Install only if you are comfortable sending tank design parameters to jixietools.com and receiving an unauthenticated guest link for the generated production sheet. Avoid entering proprietary or confidential engineering data unless that external service is approved for your use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Step 1: 列出产品

用 curl 获取储罐列表:

bash
curl -s "https://jixietools.com/api/v1/products?category_id=9" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Step 1: 列出产品

用 curl 获取储罐列表:

bash
curl -s "https://jixietools.com/api/v1/products?category_id=9" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回包含 input_params、output_params、debug_params、coefficient_params 四类参数。

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill can create guest production sheets without authentication and returns a public guest code/URL, but it does not warn the user that this may create an externally accessible artifact. If the link is guessed, leaked, logged, or shared inadvertently, sensitive design specifications and output files could be exposed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list includes broad everyday terms like 'tank' and '做一个储罐', which can cause the skill to activate in contexts where the user did not clearly intend to send engineering data to this external workflow. That increases the chance of unintended data collection and transmission to the third-party API.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs collection of detailed user-provided design parameters and later submission to a remote API, but it does not warn the user beforehand that their data will be transmitted off-platform. This undermines informed consent and can expose proprietary engineering or process data to a third party.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This step explicitly sends user-supplied engineering parameters to an external service during calculate/pre-calculate operations. In this skill's context, those values may include proprietary design, process, or operational data, so the transmission is security-relevant even if intended functionality depends on it.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction “用中文与用户对话” imposes a specific language requirement unconditionally. This is a natural-language policy issue because it does not offer the user a language choice or require opt-in before enforcing the locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.