Back to skill

Security audit

Chat Record Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated purpose, but it contains an unsafe output-file bug and uses an unpinned npm dependency from a shared temporary path.

Review before installing. Use this only in a contained workspace, pin and install xlsx through a project lockfile, avoid the shared /tmp dependency path, always pass explicit safe output filenames, and do not run the scripts with elevated privileges.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_group_def.js:111
Finding

Incorrect Argument Parsing Can Overwrite the Node.js Executable

Content
View full analysis
Remediation
View remediation
= 0 && !process.argv[outputIndex + 1]) { throw new Error('The --output option requires a file path.'); } const outPath = outputIndex >= 0 ? process.argv[outputIndex + 1] : 'group_def.json'; fs.writeFileSync(outPath, JSON.stringify(output, null, 2), { encoding: 'utf8', flag: 'wx', }); ``` Additional hardening should include: 1. Use a maintained command-line parser with required-value validation. 2. Reject values beginning with `--` when they occur where an output path is expected. 3. Resolve the path and verify that it is within an approved output directory when arbitrary destinations are unnecessary. 4. Use the exclusive-create flag (`wx`) by default to prevent silently overwriting existing files. 5. Require an explicit overwrite option if replacement of an existing file is necessary. 6. Add tests covering an absent `--output`, a missing value, duplicate options, and protected or existing destinations. 7. Avoid running the generator with elevated privileges. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:94
Finding

Unpinned Runtime Dependency Installation Creates a Mutable Supply-Chain Boundary

Content
View full analysis
Remediation
View remediation
``` 2. Commit a `package.json` and lockfile to the project, then install with: ```bash npm ci ``` 3. Where compatible, disable package lifecycle scripts: ```bash npm ci --ignore-scripts ``` 4. Verify lockfile integrity and package provenance in CI before execution. 5. Use a project-owned dependency directory rather than a predictable shared directory under `/tmp`. 6. Ensure the dependency directory is created with restrictive permissions and is not writable by other users. 7. Replace the hard-coded absolute import with the pinned project dependency: ```javascript const XLSX = require('xlsx'); ``` 8. Run dependency vulnerability and license scanning against the locked dependency graph. 9. Execute document generation in a least-privileged environment with restricted filesystem and network access. ]]>
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明的核心能力是生成完整的模拟微信群聊 Excel 数据集,但这段代码仅输出 group_def.json,属于上游配置/定义数据生成脚本。虽然它为后续 Excel 生成准备了成员和时间等基础信息,并且使用了 Excel serial 时间格式,但并未执行声明中的主要任务:创建 .xlsx 文件、构建多个工作表、填充聊天记录。因此描述与该代码块实际行为存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
收集所有子 Agent 结果后,运行 `scripts/write_xlsx.js` 写入文件。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill metadata, examples, and prompt template consistently prescribe Chinese group names, Chinese speaker labels, and Chinese message content. This creates a language/locale constraint without any explicit opt-in or justification that the skill is region-specific, which matches the policy category for forced language or locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all instructions, field descriptions, and examples exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file includes a complete Node.js example that reads and writes output.xlsx, which can modify local user data. The surrounding documentation does not include any warning about file overwrite risk, backup recommendations, or confirming the target path before saving.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.