Back to skill

Security audit

词霸每日一句

Security checks for vulnerabilities and agentic risk

Overview

The skill generally matches its card-generation purpose, but its renderer can be steered to fetch arbitrary URLs from the user’s environment.

Install only if you are comfortable with the renderer making outbound web requests from your environment. Use the default Iciba endpoint, avoid untrusted --api-url or --input-json values, run it in a network-restricted sandbox when possible, and prefer pinned dependency versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_iciba_card.py:157
Finding

Unrestricted outbound URL fetching enables server-side request forgery

Content
View full analysis
dict: req = Request(url, headers={"User-Agent": "Mozilla/5.0"}) with urlopen(req, timeout=timeout) as response: return json.loads(response.read().decode("utf-8")) ``` ```python def load_data(args: argparse.Namespace) -> dict: data = dict(FALLBACK_DATA) if args.input_json: input_path = Path(args.input_json) live = json.loads(input_path.read_text(encoding="utf-8")) data.update({k: v for k, v in live.items() if v not in (None, "")}) data["_data_source"] = f"input_json:{input_path.name}" return data try: live = fetch_json(args.api_url) if not isinstance(live, dict): raise ValueError("api did not return a JSON object") data.update({k: v for k, v in live.items() if v not in (None, "")}) data["_data_source"] = "live_api" except Exception as exc: data["_data_source"] = f"fallback_data:{exc.__class__.__name__}" return data ``` ```python def picture_candidates(data: dict) -> list[tuple[str, str]]: candidates: list[tuple[str, str]] = [] for key in ("picture", "picture2", "picture3", "picture4"): value = data.get(key) if isinstance(value, str) and value.startswith("http") and all(value != url for _, url in candidates): candidates.append((key, value)) return candidates def download_image_to_png(url: str, path: Path, timeout: int = 30) -> bool: req = Request(url, headers={"User-Agent": "Mozilla/5.0"}) try: with urlopen(req, timeout=timeout) as response: raw = response.read() image = Image.open(BytesIO(raw)). ...[truncated 3065 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned third-party dependencies create supply-chain and reproducibility risk

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill directs the agent to perform network access, read local template/script files, and write generated HTML/PNG/JSON outputs, but it declares no explicit tool scope or permission boundaries. In an agent environment, this can lead to over-broad tool use, making it easier for the skill to access the network or filesystem in ways the operator did not intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML sets lang="zh-CN" and presents the title, QR instructions, and alt/title text in Chinese throughout the template. Under the policy rule, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
98% confidence
Finding

The dependency 'pillow' is unpinned, so installs may resolve to different versions over time, including versions with known vulnerabilities or breaking changes. In this skill, Pillow processes/generated images, which makes dependency drift more relevant because image libraries have a long history of parser and resource-consumption bugs.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pillow
qrcode
playwright

Unverifiable Dependency: pillow has 16 known advisory(ies) (CVE-2016-2533 (Pillow buffer overflow in ImagingPcdDecode); CVE-2023-50447 (Arbitrary Code Execution in Pillow); CVE-2021-27922 (Pillow Uncontrolled Resource Consumption) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
97% confidence
Finding

Pillow has multiple known advisories, and because the manifest does not pin a version, there is no way to verify whether the deployed version is affected. This is more concerning in a card-generation skill because image-processing libraries often handle attacker-influenced content and have historically had denial-of-service and occasional code-execution flaws.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency 'qrcode' is unpinned, which makes builds non-reproducible and increases supply-chain risk if a bad or incompatible release is published. While this package is lower risk than a complex parser/runtime dependency, leaving it unpinned still weakens version control and reviewability.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
pillow
qrcode
playwright

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The dependency 'playwright' is unpinned, allowing arbitrary future versions to be installed with potentially different security properties. In this skill context, Playwright is used for HTML rendering, and browser automation components can materially expand attack surface through bundled browsers, network access, and complex content handling.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
pillow
qrcode
playwright

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML declares lang="zh-CN" and presents visible UI text in Chinese throughout the template, such as the title and QR instruction text. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation when no language selection or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.