Back to skill

Security audit

Vehicle

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent vehicle-design purpose, but it sends user design data to an external service, creates guest-accessible links, and uses shell command templates that need review before installation.

Review this skill before installing. Use it only if you are comfortable sending vehicle design inputs to jixietools.com and receiving a guest-accessible production-sheet link. If installed, require explicit confirmation before each network call, avoid submitting confidential designs, and have the agent build JSON with a safe HTTP client or serializer rather than literal shell string substitution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:63
Finding

Shell Command Injection Through Unsafe JSON Interpolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 63–67, 75–78, 90–93, and 99–102
Vulnerability Type: Shell command injection caused by unsafe interpolation of untrusted values
Risk Level: High

Vulnerable Code

Lines 63–67:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"参数名": ""}}'

Lines 75–78:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"参数1": "值1", "参数2": "值2"}}'

Lines 90–93:

bash
curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
  -H "Content-Type: application/json" \
  -d '{"inputs": {"修改的参数": "新值"}, "filename": "保存的filename"}'

Lines 99–102:

bash
curl -s -X POST "https://jixietools.com/api/v1/production_sheets/guest_create" \
  -H "Content-Type: application/json" \
  -d '{"product_id": PRODUCT_ID, "ref": "保存的filename"}'

Technical Analysis

The skill instructs an agent to construct shell commands by replacing placeholders with parameter names, user-provided values, product identifiers, and an API-provided filename. These values are placed directly inside single-quoted JSON passed to curl -d.

The instructions do not require JSON serialization, shell-safe argument construction, identifier validation, or rejection of shell metacharacters. If an agent performs literal textual substitution, a value containing a single quote can terminate the shell string. Subsequent shell syntax can then be interpreted as a local command rather than as JSON data.

Both user input and remote API responses must be treated as untrusted. In particular, the incremental-calculation and production-sheet commands reuse a remotely supplied filename, creating an additional injection path if the external service or its response is comprom ...[truncated 1725 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace shell command templates with a typed HTTP client that accepts URL, headers, and JSON objects as separate structured values.
  2. Serialize request bodies with a standard JSON library rather than manually embedding values into quoted shell strings.
  3. If shell-based examples must be retained, construct payloads with jq --arg or jq --argjson, write the result to a safely created temporary file, and submit it using curl --data-binary @file.
  4. Pass shell arguments as an argument array without invoking sh -c, bash -c, eval, or equivalent string-evaluation mechanisms.
  5. Validate PRODUCT_ID as an integer before placing it in a URL or JSON document.
  6. Validate API-provided filenames and references against a strict allowlist appropriate to the documented server format. Do not interpret them as paths or shell syntax.
  7. Treat all user values and remote responses as untrusted, including parameter names, option values, filenames, guest codes, and returned URLs.
  8. Run the skill with least privilege, a restricted filesystem view, minimal environment variables, and network access limited to the required API host.
  9. Add adversarial tests covering quotes, backslashes, newlines, command substitutions, shell separators, and malformed JSON.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using the single English word "vehicle" as a trigger is especially unsafe because it is extremely generic and likely to match benign conversation unrelated to this tool. In this skill, accidental activation is more dangerous because the workflow leads to external API calls and creation of publicly accessible guest production-sheet links.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Step 1: 列出产品

用 curl 获取车辆工程总体设计列表:

bash
curl -s "https://jixietools.com/api/v1/products?category_id=30" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

Step 1: 列出产品

用 curl 获取车辆工程总体设计列表:

bash
curl -s "https://jixietools.com/api/v1/products?category_id=30" | python3 -m json.tool

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

用户选择后,获取该产品的参数定义:

bash
curl -s "https://jixietools.com/api/v1/products/PRODUCT_ID/start" | python3 -m json.tool

返回包含 input_params、output_params、debug_params、coefficient_params 四类参数。

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Using the single English word "vehicle" as a trigger is especially unsafe because it is extremely generic and likely to match benign conversation unrelated to this tool. In this skill, accidental activation is more dangerous because the workflow leads to external API calls and creation of publicly accessible guest production-sheet links.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs collection of user-supplied engineering parameters and transmission of them to a third-party service, then creates a guest-accessible production-sheet link, but it does not clearly warn the user about either action. This creates a privacy and consent problem because users may not realize their inputs and generated references are being sent off-platform and exposed via unauthenticated URLs.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill directs the agent to POST collected user inputs to an external domain for calculation. External transmission is security-relevant here because the transmitted fields can include project-specific engineering data, and the skill does not include minimization, consent, or trust-boundary warnings.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

  • 无 options_source 的参数:直接提示输入数值
  • 有 options_source 的参数:先预计算获取下拉选项:
    bash
    curl -s -X POST "https://jixietools.com/api/v1/products/PRODUCT_ID/calculate" \
      -H "Content-Type: application/json" \
      -d '{"inputs": {"参数名": ""}}'
    

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

L122 明确规定“用中文与用户对话”,属于语言策略上的硬性限制,但文档未提供用户选择、自动协商或适用范围说明。若面向通用用户,这会构成未经用户选择的语言/locale 限制。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.