Back to skill

Security audit

Chat Record Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended to generate synthetic WeChat-style Excel chat records, but its helper scripts use unsafe local dependency and output-path handling that could execute or overwrite unintended files.

Review before installing. Use a project-owned, pinned xlsx dependency instead of /tmp/xlsxparse, and do not run the scripts with elevated privileges. The generate_group_def.js output argument bug should be fixed before normal use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_group_def.js:109
Finding

Unsafe Command-Line Parsing May Overwrite the Node.js Executable

Content
View full analysis
Remediation
View remediation
= 0 && !process.argv[outputIndex + 1]) { throw new Error('--output requires a file path'); } const outPath = outputIndex >= 0 ? process.argv[outputIndex + 1] : 'group_def.json'; fs.writeFileSync(outPath, JSON.stringify(output, null, 2), { encoding: 'utf8', flag: 'wx' }); ``` Additional hardening should include: - Use a maintained command-line parser with required-value validation. - Reject output paths that resolve to directories or protected executables. - Consider requiring explicit confirmation before overwriting an existing file. - Use the `wx` flag when overwriting is not intended. - Never recommend executing this script with elevated privileges. - Add tests covering absent `--output`, a missing argument value, duplicate arguments, and an existing destination. ]]>

T08 · Insecure Dependencies

Error
Location
scripts/write_xlsx.js:13
Finding

Executable Dependency Loaded from a Predictable Shared Temporary Directory

Content
View full analysis
= 0 ? args[i + 1] : null; } const groupDefPath = getArg('group') || 'group_def.json'; const messagesPath = getArg('messages') || 'messages.json'; const outputPath = getArg('output') || 'output.xlsx'; const xlsxModule = getArg('xlsx') || '/tmp/xlsxparse/node_modules/xlsx'; ``` The associated setup instructions are: ```markdown - Node.js + xlsx library (`npm install xlsx`, usually cached at `/tmp/xlsxparse/node_modules/xlsx`) - If it is not installed: `mkdir -p /tmp/xlsxparse && cd /tmp/xlsxparse && npm install xlsx` ``` ### Technical Analysis The script executes the initialization code of an `xlsx` module from the fixed, predictable path `/tmp/xlsxparse/node_modules/xlsx`. Shared temporary directories are inappropriate locations for trusted executable dependencies because another local user or process may create the expected directory and module before the legitimate user does. Node.js executes module-level JavaScript immediately when `require()` loads a package. Consequently, a malicious package placed at this path can execute arbitrary code before any workbook processing begins. The documentation compounds the issue by treating the shared temporary installation as a reusable cache and installing an unpinned dependency without a project lockfile. There is no package version constraint, integrity verification, ownership check, or trusted-directory check. The script also parses an advertised `--xlsx` option into `xlsxModule`, but that ...[truncated 1696 chars]
Remediation
View remediation
" } } ``` Additional hardening should include: - Commit and enforce a lockfile with dependency integrity metadata. - Install dependencies in the project directory using a reproducible installation command such as `npm ci`. - Do not use shared `/tmp` paths as persistent executable package caches. - Pin the dependency to an exact reviewed version rather than accepting the latest registry release. - Use a trusted package registry and apply package provenance or integrity verification where available. - Remove the unused `--xlsx` option. If custom module locations are genuinely required, validate the resolved path, ownership, permissions, and expected package integrity before loading it. - Load dependencies only after configuration validation when runtime selection is supported. - Run the Skill as an unprivileged account and isolate it from sensitive files and environment variables. ]]>
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个完整的模拟微信群聊 Excel 数据生成器,输出应为兼容平台的 .xlsx 文件,并包含多个工作表和聊天记录数据。实际代码只是一个辅助脚本 generate_group_def.js:读取静态 CONFIG,构造群组定义对象,转换时间为 Excel 序列值,然后写出 group_def.json。它不涉及 Excel 写入库、不创建工作簿或工作表、不生成 message_stream,也没有模拟对话内容。因此其实际行为与声明的主要目的存在明显不一致。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
收集所有子 Agent 结果后,运行 `scripts/write_xlsx.js` 写入文件。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest name/description and the embedded prompt template are entirely specified in Chinese and instruct generation of WeChat-style chat records with Chinese fields and examples, which effectively constrains output to a specific language/locale. There is no indication that the user can choose another language or locale, nor any documented justification that this skill must be Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file uses Chinese as the only language for the specification title and continues in that language throughout the document. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header comments present the script description and usage only in Chinese, which imposes a specific language on users without any opt-in or alternative locale guidance. The stated policy flags language-forcing behavior when no user choice or documented justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script emits completion and summary messages exclusively in Chinese, so any user running it receives a fixed locale with no configuration option. This is a natural-language policy issue because the skill does not offer language choice or explain a required regional/language scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.