Back to skill

Security audit

Xiaodi Multi Team System

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-related but asks for broad local, web, memory, session, and scheduling powers without enough scoping, and it includes unsafe setup and generated-HTML patterns.

Install only if you are comfortable reviewing prompts and commands first, limiting tool permissions where possible, and avoiding confidential content in generated HTML mind maps until the CDN dependency and HTML escaping issues are fixed. Do not run the documented curl | sh command without independent verification.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
REQUIREMENTS.md:100
Finding

Remote Rust Installer Is Downloaded and Executed Without Verification

Content
View full analysis
Remediation
View remediation
' rustup-init.sh | sha256sum --check - less rustup-init.sh sh rustup-init.sh ``` The digest must be obtained through a trusted, independently authenticated source and updated only after review. ]]>

T08 · Insecure Dependencies

Warning
Location
teams/xiaodi-office-team/scripts/mindmap.py:172
Finding

Generated Mind-Map Documents Load Mutable Third-Party JavaScript

Content
View full analysis
{structure['title']} - 思维导图 body {{ margin: 0; padding: 20px; ``` ### Technical Analysis Every generated Markmap HTML document loads `markmap-autoloader` from jsDelivr when the document is opened. The dependency URL does not specify an exact package version or immutable asset, and the generated HTML does not include a Subresource Integrity hash. Consequently, code executed by previously generated documents may change after this Skill has been reviewed. If the package, publishing account, CDN, or dependency resolution path is compromised, the browser can execute attacker-controlled JavaScript. Because generated mind maps may contain office documents, meeting records, task information, or other confidential text, remotely loaded JavaScript receives access to potentially sensitive document content. ### Attack Path 1. A user supplies office or meeting content to the mind-map generator. 2. The Skill embeds that content in an HTML document. 3. The user opens the generated document while connected to the network. 4. The browser requests the unversioned `markmap-autoloader` dependency from jsDelivr. 5. A compromised or unexpectedly changed dependency executes in the document context. 6. The script reads rendered content and can send it to an external destination or perform other browser-side actions permitted by the document context. ### Impact Assessment Potential impact includes: - Disclosure of text embedded in generated mind maps - Browser-side manipulation of generated documents - Requests to attacker-controlled network endpoints - Phishing content inserted into th ...[truncated 250 chars]
Remediation
View remediation
/" integrity="sha384-" crossorigin="anonymous"> ``` ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
teams/xiaodi-office-team/scripts/mindmap.py:155
Finding

User-Derived Content Is Inserted Into Generated HTML Without Contextual Escaping

Content
View full analysis
str: indent = " " * level lines = [f"{indent}- {node['title']}"] for child in node.get("children", []): lines.append(build_markdown_tree(child, level + 1)) return '\n'.join(lines) markdown_content = build_markdown_tree(structure) html = f''' {structure['title']} - 思维导图 body {{ margin: 0; padding: 20px; font-family: -apple-system, BlinkMacSystemFont, 'Segoe UI', Roboto, sans-serif; }} .markmap {{ width: 100%; height: 80vh; }}

🧠 {structure['title']}

''' ``` ### Technical Analysis The generated title and Markdown tree are derived from supplied document content and inserted into multiple HTML contexts without contextual escaping: - `structure['title']` is inserted into a `` element. - The same title is inserted into an `<h1>` element. - `markdown_content` is inserted into a `<script type="text/template">` element. An attacker-controlled title can inject closing tags and active HTML. More critically, content containing `</script>` can terminate the template element regardless of its non-JavaScript MIME type. Subsequent attacker-controlled markup, such as a new `<script>` element or event handler, can then become executable when the generated file is opened. This is a stored HTML injection vulnerability because the malicious content is persisted in the generated HTML output. ### Attack Path 1. An attacker ...[truncated 1090 chars]
Remediation
View remediation
` and `

` elements. 2. Do not insert untrusted text directly into a `` in varying capitalization - Event-handler attributes - SVG-based active content 8. Keep rendering logic and untrusted data separate rather than building the complete page with an f-string. For plain HTML text contexts, Python's standard escaping can be used: ```python from html import escape safe_title = escape(str(structure["title"]), quote=True) ``` Template content requires separate safe serialization and must not rely only on ordinary HTML escaping. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:8
Finding

Agent Tool Allowlist Exceeds the Minimum Privileges Required by Declared Workflows

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (106)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · REQUIREMENTS.md (reported line 77)May include surrounding context.

bash
# Ubuntu/Debian
sudo apt update && sudo apt install ffmpeg

# macOS
brew install ffmpeg

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The '| sh' pattern is especially dangerous because it turns a network fetch directly into immediate shell execution, removing the opportunity for inspection or integrity validation. In a skill that already expects command-line setup and may have access to powerful tools, this increases the chance of users running unsafe bootstrap code and suffering host compromise.

Content

Scanner excerpt · REQUIREMENTS.md (reported line 102)May include surrounding context.

bash
# 安装 Rust
curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh

# 然后安装 whisper
pip install openai-whisper

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation is only mind-map generation and file output, representing it as a four-team intelligent switcher is materially inaccurate. This discrepancy can conceal data flow and side effects, which is a legitimate security concern even absent overtly malicious code.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · teams/xiaodi-team-switcher/integration.py (reported line 35)May include surrounding context.

python
根据用户需求,选择合适的角色来处理任务。每个角色都有专业能力,协作完成任务。

"""
    return prompt


def process_user_input(user_input: str) -> dict:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The only natural-language examples are in Chinese, and the README presents them as the way the switcher routes requests without indicating multilingual support or user language preference. This can constitute a language/locale policy issue because the skill appears to assume a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that the Switcher 'automatically routes to the right team' but does not define activation boundaries, confirmation steps, or exclusions for risky domains. In a multi-tool system with web_search, exec, and browser access, overly broad routing can misclassify user intent and send requests to a team that may invoke more capable or risky tooling than necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese throughout for installation and usage instructions, which can amount to a language/locale policy violation when no user opt-in or alternative language is provided. The policy explicitly flags skills that force a specific language without user choice.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · REQUIREMENTS.md (reported line 77)May include surrounding context.

bash
# Ubuntu/Debian
sudo apt update && sudo apt install ffmpeg

# macOS
brew install ffmpeg

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · REQUIREMENTS.md (reported line 83)May include surrounding context.

bash
# Ubuntu/Debian
sudo apt update && sudo apt install ffmpeg

# macOS
brew install ffmpeg

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · REQUIREMENTS.md (reported line 90)May include surrounding context.

bash
# Ubuntu/Debian
sudo apt update && sudo apt install ffmpeg

# macOS
brew install ffmpeg

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The invocation examples are very broad and provide no trigger constraints, exclusions, or safety boundaries despite the skill requesting sensitive capabilities such as exec and browser. In this context, overly broad prompts increase the chance of unintended activation on risky tasks, especially local media/file operations and web interactions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README shows very broad natural-language activation examples like '帮我选品' and '计算这个产品的利润率' without any explicit scoping, invocation syntax, or confirmation boundaries. In an agent ecosystem, overly generic triggers can cause accidental activation or routing from unrelated user messages, increasing the chance the skill processes sensitive business data or performs unintended actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example trigger uses ordinary natural language ('帮我选品…') without any explicit invocation boundary, making it easy for unrelated user requests to accidentally activate this skill. In a multi-skill system, broad triggers can cause unintended routing to web-enabled commerce functions, increasing the chance of over-collection, unnecessary external fetching, or execution in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The monitoring description promises automated competitor tracking ('每日定时抓取', price-change alerts, coupon tracking) but does not define who can enable it, what targets are allowed, or the operational limits. In a tool-enabled agent environment, this ambiguity can lead to persistent or repeated scraping behavior beyond user intent, creating abuse, policy, and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This manifest is written entirely in Chinese for role names, descriptions, capabilities, workflow names, and data-source labels, indicating a fixed language/locale expectation. The file does not offer any user opt-in, alternative language selection, or documented region-specific justification for this constraint.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The pricing specialist has the exec tool despite a role limited to pricing strategy, profit calculation, and competitor price tracking. Granting code execution to an agent that processes external market data increases the risk of arbitrary command execution, tool misuse, or indirect prompt injection leading to local actions beyond its business purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.