Back to skill

Security audit

Apollo Workflow

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed development workflow tool, but its broad activation, global state files, and unsafe helper scripts make it risky to install without review.

Install only if you want a Chinese-language, stateful coding workflow that can spawn subagents and guide git operations. Avoid running the bundled shell scripts with untrusted task IDs, result paths, or phase names until the heredoc injection issues are fixed, prefer a project-local workflow directory, and do not use the --break-system-packages testing command on a shared or system Python environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/workflow/state-manager.sh:73
Finding

Arbitrary Python Code Execution Through Unsanitized Phase Argument

Content
View full analysis
" exit 1 fi if [ ! -f "$STATE_FILE" ]; then echo "❌ 未找到state.json" exit 1 fi # 更新current_phase python3 - < ``` 2. The a ...[truncated 1028 chars]
Remediation
View remediation
&2 exit 1 ;; esac ``` 4. Run the workflow under a dedicated, unprivileged account and avoid hard-coded root-owned paths. 5. Add tests using phase arguments containing quotes, newlines, backslashes, and shell/Python metacharacters to verify they are rejected rather than executed. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/workflow/task-result-collector.sh:11
Finding

Arbitrary Python Execution and Unsafe Destination Construction in Task Result Collection

Content
View full analysis
" echo "示例: task-result-collector.sh 01 /tmp/task-01-result.md" exit 1 fi mkdir -p "$TASK_RESULTS_DIR" DEST="$TASK_RESULTS_DIR/task-${TASK_ID}-result.json" # 如果result_file是markdown,转为json摘要 if [[ "$RESULT_FILE" == *.md ]]; then python3 - <
Remediation
View remediation
&2 exit 1 fi ``` 2. Pass all data to Python through `sys.argv` or environment variables rather than source interpolation: ```bash python3 - "$TASK_ID" "$RESULT_FILE" "$DEST" <<'PY' import json import sys from datetime import datetime, timezone from pathlib import Path task_id, result_file, destination = sys.argv[1:4] content = Path(result_file).read_text(encoding="utf-8") summary = "\n".join(content.splitlines()[:20]) result = { "task_id": task_id, "source_file": result_file, "summary": summary, "collected_at": datetime.now(timezone.utc).strftime("%Y-%m-%dT%H:%M:%SZ"), } Path(destination).write_text( json.dumps(result, indent=2, ensure_ascii=False), encoding="utf-8", ) PY ``` 3. Use single-quoted heredocs so the shell cannot modify Python source. 4. Resolve and validate the destination before writing: - Canonicalize `TASK_RESULTS_DIR` and `DEST`. - Verify the destination's parent is exactly the canonical task-results directory. - Reject path separators and traversal components in identifiers. - Reject symbolic-link destinations. 5. Validate source files: - Require a regular file. - Reject symbolic links when they are unnecessary. - Apply a reasonable file-size limit. - Parse and schema-check JSON before accepting it. 6. Update `state.json` atomically by writing a temporary file in the same directory, validating it, and then renaming it. 7. Mark a task complete only after collection and validation succeed. The script should exit nonzero if state updating fails. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/workflow/phase-gate-check.sh:21
Finding

Workflow Hard Gates Can Be Bypassed with Empty or Forged Files

Content
View full analysis
Remediation
View remediation
", "plan_file": "docs/plans/example.md", "execution_mode": "subagent" } ``` 4. Verify supporting evidence instead of trusting declarations: - Confirm referenced files exist under the project root. - Confirm task counts match state. - Confirm required commits exist. - Confirm test records are associated with the current revision. - Require an explicit user-approval event where applicable. 5. Store state in a project-local, workflow-specific directory rather than the global hard-coded directory. 6. Protect the directory with restrictive permissions and reject symbolic-link gate files: ```bash umask 077 ``` 7. Use atomic file creation and updates to prevent partial or race-condition-driven state. 8. If gate records are used as true authorization artifacts across trust boundaries, authenticate them with a trusted approval mechanism rather than relying on mutable local JSON. ]]>

T08 · Insecure Dependencies

Warning
Location
references/testing.md:8
Finding

Unpinned Package Installation Bypasses System Python Protections

Content
View full analysis
Remediation
View remediation
``` 3. For stronger reproducibility, include hashes and require them: ```bash python -m pip install --require-hashes -r requirements-test.txt ``` 4. Use an approved package index and explicitly configure it where organizational policy requires this. 5. Remove `--break-system-packages`. Testing dependencies should not modify the operating system's Python environment. 6. Run package installation and tests as an unprivileged account. 7. Regularly review and update the locked dependency set through a controlled dependency-update process. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The advertised purpose is a planning/development workflow, but the skill also performs hidden state management, gate-file writes, and workflow bookkeeping in concealed directories. This mismatch is dangerous because users may invoke it for innocuous coding help while it silently modifies repository state and hidden control files beyond what the description clearly discloses.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are extremely broad, including common words like build, plan, develop, debug, and coding task, which are likely to appear in normal conversations. This raises the chance of unintended activation, causing the skill to take over routine interactions and potentially run file-writing or exec-backed workflow steps without deliberate user selection.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares executable capabilities and references workflow scripts plus stateful file operations, but it does not define any explicit tool scope or allowed-tools boundary. In practice this can let the skill run with broader file read/write authority than users expect, increasing the blast radius of accidental or unsafe workflow actions.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
88% confidence
Finding

Using the trigger term 'build' creates a shadow-command conflict with a common built-in command. That can divert expected platform behavior into this custom skill, unexpectedly invoking its workflow, file creation, or shell-script guidance instead of the safer built-in path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill description and operational instructions are written in Chinese, and the file does not indicate that language choice is optional or region-specific. This can violate language or locale policy when a skill effectively constrains interaction to a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
89% confidence
Finding

Using the trigger term 'debug' conflicts with a common built-in debugging command and can capture routine user requests unintentionally. In this skill's context, that is more dangerous because debug requests may jump directly into Phase 4 and steer the session into stateful workflow behavior rather than normal debugging assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The debug trigger phrases include very common natural-language terms such as "debug," "bug," and especially "this is broken," which can be said in ordinary conversation or while discussing status rather than intentionally invoking the debugging workflow. In an agent skill, overly broad triggers can cause unintended mode switches, bypass normal sequencing, and alter workflow behavior without explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The init command writes a new JSON document directly to the workflow state file, replacing any existing contents. Although there is a success message after the write, there is no prior warning, confirmation prompt, or comment/docstring disclosing that existing workflow state may be overwritten.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script’s comments and user-visible messages are written in Chinese, including usage/help text and status output. This imposes a specific language on users without any opt-in or documented justification, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructions entirely in Chinese, including headings and procedural guidance, with no indication that the language choice is optional or region-specific. The policy for this audit flags language or locale constraints when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script contains natural-language comments and output primarily in Chinese, including the usage text shown to users. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation, and the file does not indicate that the skill is region-specific or that alternative language output is available.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The advance command opens the state file and writes updated JSON back to disk, modifying persisted workflow state. While it prints a completion message afterward, there is no prior user-facing warning, confirmation, or inline documentation explaining that the command performs an in-place file write.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments, usage text, and status messages are written in Chinese, which imposes a specific language on users. The file does not provide an opt-in, fallback, or documentation indicating that this is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.