Back to skill

Security audit

Ux Usability Auditor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent UX audit tool, but its automatic page discovery can navigate beyond the intended target and save captured content locally.

Install only after reviewing the scripts and run it against systems you are authorized to test. Prefer a test account with minimal permissions, avoid real production secrets, set a tightly controlled output directory, and treat screenshots/results/reports as sensitive. Do not use auto-discovery on untrusted apps unless same-origin URL filtering is added; provide a vetted page list after fixing the explicit-pages bug or patch the inspector to reject cross-origin and non-http(s) destinations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/inspect.js:59
Finding

Unrestricted Navigation to Page-Controlled URLs Enables Browser-Based SSRF

Content
View full analysis
{ const text = (el.innerText || el.textContent || '').replace(/\s+/g, ' ').trim(); let href = el.getAttribute('href') || ''; // For SPA hash routes, resolve full URL if (href && !href.startsWith('http')) { href = window.location.origin + window.location.pathname + href; } const key = text + '||' + href; if (text.length > 1 && text.length < 50 && !seen.has(key)) { seen.add(key); results.push({ name: text, url: href || window.location.href }); } }); ``` ```javascript try { await page.goto(p.url, { waitUntil: 'networkidle', timeout: 20000 }).catch(() => {}); await sleep(config.pageWaitMs || 2500); ``` ### Technical Analysis The page-discovery routine extracts links from the audited application's DOM and accepts absolute URLs without validating their origin, protocol, hostname, or resolved IP address. Every discovered URL is subsequently supplied to Playwright's `page.goto()`. Because the audited application controls the DOM from which links are collected, it can direct the browser to resources outside the configured application's origin. Potential destinations include loopback addresses, private network services, link-local addresses, administrative interfaces, and cloud instance metadata endpoints. The code also does not distinguish ordinary navigation links from GET endpoints that perform state-changing actions. The inspection process captures screenshots and extracts visible page content after navigation. Consequently, content returned by an internally reachable destinati ...[truncated 1610 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_report.js:178
Finding

Unescaped Application and Checklist Data Is Injected into Generated Markdown Reports

Content
View full analysis
{ const icon = issue.severity === 'P0' ? '🔴' : issue.severity === 'P1' ? '🟡' : '🟢'; lines.push(`### ${icon} ${issue.severity} — ${issue.item}`); lines.push(`**Category:** ${issue.category}`); lines.push(`**Finding:** ${issue.finding}`); lines.push(''); }); ``` ```javascript evaluated.forEach((cat) => { lines.push(`### ${cat.category}`); lines.push(''); cat.results.forEach((r) => { lines.push(`**${r.item.name}**`); lines.push(`- Status: ${r.status}`); lines.push(`- Standard: ${r.item.standard || 'N/A'}`); lines.push(`- Finding: ${r.finding}`); lines.push(''); }); }); ``` ```javascript results.filter((r) => r.status === 'ok').forEach((r) => { const pg = (r.page || '').substring(0, 20); lines.push(`| ${pg} | ${r.buttons || 0} | ${r.inputs || 0} | ${r.tables || 0} | ${r.emptyState ? 'Yes' : 'No'} | ${r.breadcrumb ? 'Yes' : 'No'} |`); }); ``` ### Technical Analysis The report generator directly interpolates values from the configuration, checklist, and inspection results into Markdown without escaping Markdown metacharacters, table delimiters, line breaks, or raw HTML. The inspected application controls some of these values. In particular, page names originate from menu and anchor text extracted from the audited page. Custom checklist content is also treated as trusted report text. An attacker can therefore supply crafted content that changes the structure or rendered meaning of the generated report. Depending on the Markdown renderer, injected raw HTML or ext ...[truncated 2221 chars]
Remediation
View remediation
/g, '>') .replace(/([\\`*_{}\[\]()#+\-.!|])/g, '\\$1') .replace(/\r?\n/g, ' '); } function escapeMarkdownTableCell(value) { return escapeMarkdownText(value) .replace(/\|/g, '\\|'); } ``` 10. Add regression tests using malicious page names, checklist categories, raw HTML, external image syntax, pipes, and embedded newlines. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill’s declared purpose understates sensitive behavior: it performs authenticated login using supplied credentials and navigates protected application areas, which materially increases data exposure beyond a generic UX audit. The documentation also overstates end-to-end audit capability because the inspection phase only collects screenshots and simple UI metadata, creating a trust gap that can cause users to run it against real systems without understanding the access and collection scope.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
2. **Run inspection** — `node scripts/inspect.js config.json`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
2. **Run inspection** — `node scripts/inspect.js config.json`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
2. **Run inspection** — `node scripts/inspect.js config.json`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
4. **Generate report** — `node scripts/generate_report.js config.json`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
4. **Generate report** — `node scripts/generate_report.js config.json`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
4. **Generate report** — `node scripts/generate_report.js config.json`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
4. **Generate report** — `node scripts/generate_report.js config.json`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
4. **Generate report** — `node scripts/generate_report.js config.json`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration example includes plaintext credentials and the skill describes writing screenshots and inspection results to local files without a prominent warning about sensitive data retention. In practice, screenshots, UI metadata, and config files may contain secrets, personal data, or internal business information, so omission of storage warnings can lead to accidental leakage through source control, shared workstations, or artifact collection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code emits multiple user-facing report statuses and findings in Chinese, such as '无法评估', '存在问题', and other explanatory strings, while the rest of the tool usage and report structure are in English. That creates a language policy issue because the skill imposes a specific locale on users without offering a language choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script performs a credentialed login flow and then traverses authenticated pages, but the skill description does not clearly disclose that it will handle user credentials and access post-login application data. In a usability-auditor context this expands data access significantly and can surprise users into exposing sensitive internal content, especially because the tool also captures screenshots and UI metadata after authentication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The automated login flow fills supplied username and password values directly into the page without any visible warning or consent mechanism about credential handling. In this skill, that is risky because users may provide sensitive enterprise credentials to a tool they believe is only doing passive UX inspection, and the script then uses those credentials to access protected application areas.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script saves screenshots of authenticated pages and structured inspection results to local disk without warning that potentially sensitive page contents will be persisted. In a UX audit context this is particularly dangerous because screenshots can capture PII, internal dashboards, secrets displayed in UI, or business data from many pages in bulk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The text claims compatibility with both Chinese and English audit workflows, yet the actual checklist instructions and criteria are written only in English. If organizational policy requires offering language choice rather than implicitly forcing one language, this wording can be misleading and may not satisfy the stated bilingual expectation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.