Back to skill

Security audit

Transmission

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to support a real transmission drawing workflow, but it sends design inputs to an external unauthenticated service and uses shell API examples that need careful review before installation.

Install only if you are comfortable sending transmission design inputs to jixietools.com and creating unauthenticated guest production records there. Prefer using a structured HTTP client or safely serialized request body instead of direct shell interpolation, and require explicit user confirmation before the first external request and before creating a production sheet.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:68
Finding

Shell Command Injection Through Unsafe JSON Interpolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 68-72, 77-81, and 92-96
Vulnerability Type: Shell command injection caused by unsafe interpolation of dynamic data
Risk Level: High

Vulnerable Code

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"参数名": ""}}'
bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"参数1": "值1", "参数2": "值2"}}'
bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"修改的参数": "新值"}, "filename": "保存的filename"}'

Technical Analysis

The Skill instructs an agent to construct JSON request bodies inside single-quoted shell arguments. The parameter names, parameter values, and saved filename are dynamic values derived from API responses or user input.

If the agent implements these templates through direct textual substitution, a value containing a single quote can terminate the shell's quoted argument. The remainder of the value can then be interpreted as shell syntax rather than JSON data. JSON escaping alone is insufficient because shell parsing occurs before curl receives the argument.

For example, substituting a value shaped like '; id; # could transform the intended request into multiple shell commands. The original curl request may fail due to malformed JSON, but the injected command can still execute.

The Skill includes free-form inputs such as tire specifications, so the workflow cannot safely assume that all values are numeric. The same weakness applies to initial calculations, incremental modifications, and option-precalculation requests.

Attack Path

  1. An attacker supplies a crafted transmission parameter value containing a single quote followed b ...[truncated 1355 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not perform textual interpolation of user-controlled or API-derived values inside shell commands.
  2. Prefer a structured HTTP library such as Python's urllib.request or a vetted HTTP client. Construct request bodies as native objects and serialize them with json.dumps.
  3. If curl must be retained, generate the body with a JSON-aware tool and pass it through standard input or a temporary file created with restrictive permissions. For example, use jq --arg for every dynamic string and curl --data-binary @-.
  4. Pass dynamic values through environment variables or positional arguments rather than embedding them into executable shell source.
  5. Validate each field according to the API schema:
    • Accept only finite numeric values for numeric engineering parameters.
    • Restrict option fields to values returned by the API.
    • Apply explicit length and character limits to free-form fields such as tire specifications.
    • Validate PRODUCT_ID as an integer.
    • Treat filename as opaque data and never as executable syntax.
  6. Avoid invoking a shell where it is not necessary. Supplying an argument array directly to a process API prevents shell metacharacters from being interpreted.
  7. Add tests containing single quotes, command separators, newlines, command substitutions, and malformed JSON to verify that all values remain data rather than executable syntax.
  8. Run the Skill's network operations under a least-privileged account with restricted filesystem access and narrowly scoped outbound network permissions to reduce impact if request construction is compromised.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Step 1: 列出产品

用 curl 获取变速器列表:

bash
curl -s "https://jixietools.com/api/v1/products?category_id=39" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Step 1: 列出产品

用 curl 获取变速器列表:

bash
curl -s "https://jixietools.com/api/v1/products?category_id=39" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回包含 input_params、output_params、debug_params、coefficient_params 四类参数。

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very generic terms like “变速器” and “transmission”, which can cause the skill to activate on ordinary conversation or unrelated requests. That increases the chance the agent will unexpectedly steer users into a workflow that sends data to an external service and creates artifacts without clear intent confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs collection of detailed engineering parameters and transmission of them to a third-party API, while also creating a production sheet, but it does not warn users or obtain informed consent. Because the workflow is explicitly unauthenticated and external, users may unknowingly disclose proprietary design or operational data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill sends user-provided engineering inputs to an external API endpoint for calculation, including iterative updates tied to a persistent filename. In this context, the transmitted data may include proprietary design parameters, and the skill normalizes repeated disclosure to an unauthenticated third-party service without trust boundaries or minimization.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction "用中文与用户对话" mandates a specific language for all interactions. This is a locale/language policy issue because the file does not offer the user a language choice or document a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.