Back to skill

Security audit

smart-charts

Security checks for vulnerabilities and agentic risk

Overview

This charting skill mostly matches its stated purpose, but it automatically executes generated Python transform code in-process with weak resource containment.

Install only if you are comfortable with a charting tool that runs generated pandas/numpy transform code locally. Use trusted input files, keep output directories explicit, avoid using it in shared or production agents without subprocess/container isolation and CPU/memory limits, and review transform code for unusually large loops, allocations, or broad DataFrame construction before execution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/data_transformer.py:138
Finding

In-Process Transform Sandbox Permits Host Resource Exhaustion

Content
View full analysis
pd.DataFrame: ns: Dict[str, Any] = {'df': df.copy(), 'pd': pd, 'np': np} safe_builtins = { 'len': len, 'range': range, 'list': list, 'dict': dict, 'str': str, 'int': int, 'float': float, 'bool': bool, 'sorted': sorted, 'enumerate': enumerate, 'zip': zip, 'map': map, 'filter': filter, 'sum': sum, 'min': min, 'max': max, 'abs': abs, 'round': round, 'set': set, 'tuple': tuple, 'isinstan ...[truncated 4904 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (38)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
1. **MUST 走 CLI 工作流**(`data_parser.py` → `cli.py`),不要自写脚本替代。

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/REFERENCE.md (reported line 65)May include surrounding context.

md
**Numeric coercion is observable:** string columns are cleaned (currency symbols → thousands separators → `%` → Chinese magnitude suffixes `亿`/`万`/`千`, so `8.5万` → `85000`) and then coerced. If only *some* cells fail to parse but ≥50% succeed, the column still becomes numeric with the failures set to missing, and an advisory is emitted naming the column and the number of discarded cells. Below 50% the column is left as text. Previously a single stray `-` silently degraded a whole column to string with no warning.

exec() call detected

High
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The code executes LLM-generated Python with exec() against real pandas/numpy module objects. Although it adds blacklist and AST filtering plus reduced builtins, this remains dangerous because Python sandboxing is brittle, module objects expose large attack surfaces, and timeout/resource controls are incomplete (notably Windows lacks SIGALRM protection and loops/heavy computation can still cause denial of service).

Content

Scanner excerpt · scripts/data_transformer.py (reported line 368)May include surrounding context.

python
# P2-print 修复:把 transform 代码里的 print 重定向到 stderr,
            # 避免污染 cli.py 末尾输出到 stdout 的 JSON 契约。
            with contextlib.redirect_stdout(sys.stderr):
                exec(code, ns)
        except TimeoutError:
            raise TransformError(
                f"转换代码执行超时(超过 {self.timeout} 秒),可能存在无限循环",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes capabilities that include shell execution, file reads/writes, and references to network-related capabilities, but it does not declare a restrictive tool scope such as permissions or allowed-tools. That leaves enforcement to prose instructions rather than machine-checkable policy, increasing the risk that an agent can invoke overly powerful tools or access unintended resources during chart generation and retries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list includes generic terms such as "画图", "chart", and "visualization", which can appear in many ordinary requests unrelated to this specific skill. Although the file provides some do-not-trigger guidance elsewhere, this line itself defines a broad activation surface that could overlap with common speech and cause unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This instruction sets output language behavior based on the data language rather than the user's explicit preference. That can violate language or locale choice policy because it imposes a locale decision unless the user explicitly asks otherwise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The capability boundaries section says world maps, city-level maps, or custom regions are not supported and are out of scope. Later, the CLI reference explicitly documents --geo-path for self-supplied GeoJSON covering any region, which materially expands the skill beyond the earlier stated boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language documentation states that chart text language is forced to 'zh' or 'en', and the code enforces only those two values. This is a locale policy constraint without an explicit user opt-in mechanism beyond parameter passing and without documented justification for excluding other languages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and later user-facing help/error text are written in Chinese, while the file also exposes a --lang option only for chart text rather than CLI interaction. This creates a locale policy issue because the skill's command-line interface appears to require a specific language for core usage and failure handling without offering the user a choice.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/cli.py (reported line 33)May include surrounding context.

python
ok_all = True
    for name, min_ver in REQUIREMENTS:
        try:
            mod = __import__(name)
            ver = getattr(mod, '__version__', 'unknown')
            ok = _version_ok(ver, min_ver)
        except ImportError as e:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains natural-language instructions and descriptions exclusively in Chinese, including the module docstring and later CLI/help text. Under the language/locale policy rule, forcing a single language without opt-in or justification is a policy concern because users are not offered a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argparse description, argument help text, success messages, and error messages are all presented in Chinese only. This creates a natural-language locale restriction in user-facing behavior without offering the user a choice or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file explicitly normalizes executing LLM-generated code without user confirmation, which increases exposure because untrusted generated code is run automatically. In this skill context, the danger is amplified by the fact that the code path ultimately reaches exec(), so mistakes or sandbox bypasses become immediately exploitable instead of being gated by review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The parser's docstring and raised error/suggestion strings are user-facing and hard-coded in Chinese, including the help guidance text. There is no indication of user locale selection or a documented reason that the skill is region-specific, which violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language instructions and documentation entirely in Chinese, including the top-level module docstring and many explanatory comments. Because the file does not offer an opt-in language choice or explain that the skill is intentionally limited to a Chinese-speaking or region-specific context, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file’s user-facing module docstring is entirely in Chinese, including the script description and usage instructions. That creates a language/locale policy concern because the skill presents operational guidance in a fixed language without offering an alternative or indicating that the language is region-specific by design.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/regression_check.py (reported line 49)May include surrounding context.

python
def run_cli(args, timeout=90):
    t0 = time.time()
    proc = subprocess.run([sys.executable, str(CLI)] + [str(a) for a in args],
                          capture_output=True, text=True, timeout=timeout)
    dt = time.time() - t0
    out = None

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/regression_check.py (reported line 61)May include surrounding context.

python
return proc.returncode, out, proc.stderr, dt

def run_dp(args, timeout=60):
    proc = subprocess.run([sys.executable, str(DP)] + [str(a) for a in args],
                          capture_output=True, text=True, timeout=timeout)
    return proc.returncode, proc.stdout, proc.stderr

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/regression_check.py (reported line 786)May include surrounding context.

python
rec("P1-8-requirements改用兼容区间",
    'pandas>=' in _req and 'pandas==' not in _req and 'numpy>=' in _req,
    f"{_req[:80]}")
_proc = subprocess.run([sys.executable, str(CLI), '--doctor'], capture_output=True, text=True, timeout=60)
try:
    _doc = json.loads(_proc.stdout)
    rec("P1-8---doctor输出版本矩阵",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and extensive inline natural-language strings are written entirely in Chinese, and the file repeatedly hard-codes Chinese labels and messages as the default user-facing behavior. Because the file does not indicate any user opt-in or locale-selection mechanism here, this creates a natural-language locale constraint that may violate an organizational policy requiring language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
73% confidence
Finding

The HTML lang attribute is restricted to 'zh-CN' when ctx.lang is 'zh' and otherwise defaults to 'en', and the file-level documentation is written in Chinese. Under the policy, forcing a specific language/locale without explicit user choice or documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
72% confidence
Finding

This branch sets the HTML lang attribute to 'zh-CN' for Chinese and 'en' for all other cases, which can impose a locale choice rather than offering one. The file does not clearly state that the user selected this behavior or that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code sets the default locale to ZH when the browser or document language contains Chinese, otherwise EN, via document.documentElement.lang / navigator.language. This is a natural-language locale policy concern because it forces locale selection automatically rather than explicitly offering user choice or opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Earlier the document states that any other exception is wrapped as UNKNOWN_ERROR JSON on stderr in both cli.py and data_parser.py. Later it says other exceptions are printed as plain text to stderr, which is an active contradiction about error-handling behavior relevant to consumers and safety expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This requirements file includes all explanatory natural-language comments in Chinese, such as the title and installation notes, with no indication that the skill supports other languages or that Chinese-only documentation is intentional for a region-specific audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
assets/echarts.min.js:45

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/data_transformer.py:25

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/regression_check.py:172