Back to skill

Security audit

Shi Gou

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent security scanner, but its sanitizing feature can expose the secrets it claims to remove.

Review before installing if you plan to use command sanitization: the current output can still include original secrets in removed_patterns, so do not log or share sanitizer results until that is fixed. The scanner examples and dangerous command strings are expected detection content, not evidence that the skill executes those commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/security-check.js:128
Finding

Sensitive Values Exposed in Sanitization Results

Content
View full analysis

Vulnerability Details

File Location: scripts/security-check.js, lines 128–145
Vulnerability Type: Plaintext sensitive-data exposure
Risk Level: Medium

js
for (const { pattern, replacement } of SENSITIVE_PATTERNS) {
  const matches = sanitized.match(pattern)
  if (matches) {
    for (const match of matches) {
      removed.push({ original: match, pattern: pattern.toString() })
    }
    sanitized = sanitized.replace(pattern, replacement)
  }
}

return {
  original_length: command.length,
  sanitized,
  removed_patterns: removed.map(r => r.original),
}

Technical Analysis

The sanitization function correctly replaces recognized sensitive values in the sanitized string, but it also stores every original match in the removed array. The returned removed_patterns property then exposes those original values verbatim.

This defeats the purpose of sanitization because the resulting object still contains the API keys, bearer tokens, passwords, internal network addresses, or user paths that were supposed to be removed. When invoked through the command-line interface, the complete object is serialized to JSON and printed to standard output, where it may be captured by terminal history, application logs, CI/CD logs, chat records, or monitoring systems.

Attack Path

  1. A user or calling system passes a command containing a supported sensitive value to sanitizeCommand.
  2. A configured regular expression identifies the sensitive substring.
  3. The function stores the unredacted match in removed.
  4. The command text is redacted, creating the appearance of successful sanitization.
  5. The function copies the original value into removed_patterns.
  6. The caller records, shares, or logs the returned object under the assumption that it contains no sensitive data.
  7. Anyone with access to that output can recover the original matched credential or other sensitive value.

Impa

...[truncated 696 chars]

Remediation
View remediation

Remediation Suggestions

  1. Never retain or return the original matched values. Record only non-sensitive metadata, such as a stable pattern identifier and the number of replacements.

  2. Replace removed_patterns: removed.map(r => r.original) with a structure that cannot reveal input content, for example:

    js
    const removed = []
    
    for (const { pattern, replacement, id = 'sensitive_value' } of SENSITIVE_PATTERNS) {
      const matches = sanitized.match(pattern)
      if (matches) {
        removed.push({
          pattern: id,
          count: matches.length,
        })
        sanitized = sanitized.replace(pattern, replacement)
      }
    }
    
    return {
      original_length: command.length,
      sanitized,
      removed_patterns: removed,
    }
    
  3. Assign explicit, non-sensitive identifiers to each configured pattern, such as api_key, bearer_token, or password.

  4. Minimize the lifetime of raw command data and avoid copying sensitive substrings into intermediate arrays.

  5. Add automated tests that insert representative secrets and assert that none of them appears anywhere in the serialized return object.

  6. Document that callers must avoid logging raw function inputs and should restrict access to existing logs that may contain prior unredacted results.

  7. Review and rotate any real credentials that may already have been processed and subsequently stored in output logs.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

md
## 检测能力

### 提示词注入
- `ignore previous instructions`
- `disregard your instructions`
- `you are now a different`
- `<|im_start|>` 等特殊Token

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · README.md (reported line 56)May include surrounding context.

md
## 检测能力

### 提示词注入
- `ignore previous instructions`
- `disregard your instructions`
- `you are now a different`
- `<|im_start|>` 等特殊Token

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 231)May include surrounding context.

md
## 检测能力

### 提示词注入
- `ignore previous instructions`
- `disregard your instructions`
- `you are now a different`
- `<|im_start|>` 等特殊Token

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 237)May include surrounding context.

md
## 检测能力

### 提示词注入
- `ignore previous instructions`
- `disregard your instructions`
- `you are now a different`
- `<|im_start|>` 等特殊Token

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · scripts/security-check.js (reported line 40)May include surrounding context.

js
## 检测能力

### 提示词注入
- `ignore previous instructions`
- `disregard your instructions`
- `you are now a different`
- `<|im_start|>` 等特殊Token

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · scripts/security-check.js (reported line 35)May include surrounding context.

js
'rm -rf', 'del /f /s /q', 'format', 'dd if=',
  'drop table', 'delete from', 'truncate', 'alter table',
  'eval(', 'exec(', 'system(', 'shell_exec(',
  '--no-sandbox', '--privileged', 'chmod 777',
]

// 提示词注入模式

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/security-check.js (reported line 35)May include surrounding context.

js
'rm -rf', 'del /f /s /q', 'format', 'dd if=',
  'drop table', 'delete from', 'truncate', 'alter table',
  'eval(', 'exec(', 'system(', 'shell_exec(',
  '--no-sandbox', '--privileged', 'chmod 777',
]

// 提示词注入模式

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill description is written in Chinese and provides no indication that other languages are supported or that Chinese is an intentional, region-specific requirement. Under the policy, language constraints should either be optional for the user or explicitly justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase '扫描' is overly broad and can cause this security skill to activate on generic requests such as document scanning, QR scanning, or broad analysis tasks. Over-broad invocation increases the chance of unintended routing, context capture, and interference with normal workflows, especially because this is a security-themed skill that may inspect or transform sensitive content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The triggers '脱敏' and '敏感信息' are too vague and likely to match many unrelated user requests, causing sanitize_command to run outside its intended scope. In security contexts, unintended sanitization can alter evidence, hide important details, or mishandle user data by transforming content that was not meant to be processed by this skill.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/security-check.js (reported line 35)May include surrounding context.

js
'rm -rf', 'del /f /s /q', 'format', 'dd if=',
  'drop table', 'delete from', 'truncate', 'alter table',
  'eval(', 'exec(', 'system(', 'shell_exec(',
  '--no-sandbox', '--privileged', 'chmod 777',
]

// 提示词注入模式

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language strings for summaries, recommendations, comments, and CLI usage that are exclusively in Chinese. Because the skill does not offer a language/locale option or document a justified region-specific constraint, it violates the language/locale policy criterion for natural-language content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes this skill as responsible for security defense and anomaly detection, specifically detecting prompt injection, path traversal, and dangerous commands. However, the file also provides a separate sanitization capability and a report-generation function, which are additional operational behaviors not reflected in the stated description.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/security-check.js:34

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:62

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
README.md:29

Prompt-injection style instruction pattern detected.

Warn
Code
suspicious.prompt_injection_instructions
Location
SKILL.md:231