Back to skill

Security audit

house-ops · 驱动 agent,帮你把房选好 / Drive your agent, choose the right home

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed local home-buying assistant; it handles sensitive buyer profile data, but I found its file writes, scripts, and network use to be purpose-aligned rather than malicious.

Before installing, be comfortable with local storage of sensitive home-buying details such as budget, household needs, residency/eligibility, and property history. Do not share generated reports or data/map.html casually because they may contain profile and listing data; delete config/profile.yml, modes/_profile.md, reports/, and data/ if you want to remove saved history.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (70)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
5. `stats` 优先跑 `node scripts/stats.mjs`,失败或需要更深解读时按 mode 文件人工汇总。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
6. `scan`:只读 `modes/scan.md`;先跑 `node scripts/scan.mjs detect <url>...` 获取平台与字段清单(输出按平台分组,同平台负载只读一次;单次 ≤3 条链接,超预算落 `status: partial` 并把未查项交给用户);涉及成交价/政务数据时跑 `no

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These sections direct the collection of especially sensitive personal data such as residency/visa status, household registration or social-security history, buyer classification, and city-specific legal eligibility inputs, then tie them into persisted profile data. Because the skill normalizes this collection as mandatory workflow without a clear privacy warning, purpose limitation, or sensitivity handling, it increases the risk of overcollection, unauthorized retention, and downstream misuse of regulated personal data.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/dashboard.mjs (reported line 36)May include surrounding context.

js
// ---------- 跨平台打开 URL 或文件 ----------
// 打开的目标里有一部分是**抓取来的房源链接**,所以:
// 1) 不能拼进 shell 字符串——只转义双引号挡不住 `; rm -rf` 这类注入。一律 execFile 传数组,参数不经 shell。
// 2) 按目标类型分别放行:http(s) 交给浏览器;仓库内的文件才允许打开,其余 scheme(javascript:、smb:…)一律拒绝。
const HTTP_URL = /^https?:\/\//i;
const ANY_SCHEME = /^[a-z][a-z0-9+.-]*:/i;

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/selftest.mjs (reported line 712)May include surrounding context.

js
// ---------- 跨平台打开 URL 或文件 ----------
// 打开的目标里有一部分是**抓取来的房源链接**,所以:
// 1) 不能拼进 shell 字符串——只转义双引号挡不住 `; rm -rf` 这类注入。一律 execFile 传数组,参数不经 shell。
// 2) 按目标类型分别放行:http(s) 交给浏览器;仓库内的文件才允许打开,其余 scheme(javascript:、smb:…)一律拒绝。
const HTTP_URL = /^https?:\/\//i;
const ANY_SCHEME = /^[a-z][a-z0-9+.-]*:/i;

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/selftest.mjs (reported line 739)May include surrounding context.

js
// ---------- 跨平台打开 URL 或文件 ----------
// 打开的目标里有一部分是**抓取来的房源链接**,所以:
// 1) 不能拼进 shell 字符串——只转义双引号挡不住 `; rm -rf` 这类注入。一律 execFile 传数组,参数不经 shell。
// 2) 按目标类型分别放行:http(s) 交给浏览器;仓库内的文件才允许打开,其余 scheme(javascript:、smb:…)一律拒绝。
const HTTP_URL = /^https?:\/\//i;
const ANY_SCHEME = /^[a-z][a-z0-9+.-]*:/i;

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/selftest.mjs (reported line 739)May include surrounding context.

js
openExternal(target);
      has(`openExternal 放行正常目标:${target.slice(0, 30)}`, calls.length === 1);
    }
    for (const target of ['; rm -rf /', '$(whoami)', '`id`', 'javascript:alert(1)', 'smb://evil/share', resolve(ROOT, '../outside.md')]) {
      calls.length = 0; errs.length = 0;
      openExternal(target);
      has(`openExternal 拦下恶意/越界目标:${target.slice(0, 26)}`, calls.length === 0 && errs.length === 1);

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/selftest.mjs (reported line 739)May include surrounding context.

js
openExternal(target);
      has(`openExternal 放行正常目标:${target.slice(0, 30)}`, calls.length === 1);
    }
    for (const target of ['; rm -rf /', '$(whoami)', '`id`', 'javascript:alert(1)', 'smb://evil/share', resolve(ROOT, '../outside.md')]) {
      calls.length = 0; errs.length = 0;
      openExternal(target);
      has(`openExternal 拦下恶意/越界目标:${target.slice(0, 26)}`, calls.length === 0 && errs.length === 1);

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/selftest.mjs (reported line 739)May include surrounding context.

js
openExternal(target);
      has(`openExternal 放行正常目标:${target.slice(0, 30)}`, calls.length === 1);
    }
    for (const target of ['; rm -rf /', '$(whoami)', '`id`', 'javascript:alert(1)', 'smb://evil/share', resolve(ROOT, '../outside.md')]) {
      calls.length = 0; errs.length = 0;
      openExternal(target);
      has(`openExternal 拦下恶意/越界目标:${target.slice(0, 26)}`, calls.length === 0 && errs.length === 1);

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes networked Node scripts and reads configuration/project files, but it does not declare an explicit tool scope such as allowed tools or permissions. That creates an over-privileged execution surface where the agent may use broader environment or network capabilities than the user expects, increasing the chance of unintended data access or outbound requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Routing content that merely 'looks like' a property into evaluate mode is ambiguous and susceptible to misclassification. An attacker can craft text that matches the heuristic and causes the agent to enter a mode that loads additional files or performs external lookups, creating an unnecessary attack surface from loosely defined natural-language triggers.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction mandates that all user-facing output use the language from config/profile.yml, defaulting to simplified Chinese. This is a locale/language policy concern because it enforces a specific language behavior without stating that the user can choose or override it in-session.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Automatically treating any pasted listing URL as a signal to run evaluation can trigger network fetches, file reads, or downstream scripts without a clear confirmation step. In a security context, broad auto-routing increases the risk of prompt-triggered actions on attacker-supplied content and can surprise users into executing a higher-privilege workflow than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The configuration sets language.output: zh as the default output language. Under the policy, forcing a specific language without user opt-in is a natural-language locale policy violation unless the skill explicitly offers a language choice or justifies the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L181 states that output language must follow config/profile.yml and defaults to Chinese. Under the policy rule, forcing a specific language or locale without explicit user choice or opt-in is a natural-language policy concern, and this file does not state that the user is offered a language selection at runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s title, trigger examples, workflow text, and required output phrases are entirely specified in Chinese, indicating the skill is designed to operate in Chinese by default. There is no statement offering alternative languages or asking the user to choose a preferred language, which creates a locale/language policy concern under the natural-language policy rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is written entirely in Chinese and references a Chinese checklist file (contract-checklist.cn.yml), but it does not indicate that the language choice is optional or based on user preference. This can violate language/locale policy if the skill is invoked for users who have not opted into Chinese output.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file defines activation on the phrase “帮我看看这份合同”, which is a common everyday request and does not by itself tightly constrain the skill’s invocation boundaries. The description does not provide negative examples or clearer scope limits for when this mode should or should not activate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The mode instructions, trigger text, and outputs are entirely in Chinese, which implicitly enforces a specific language for use of the skill. There is no indication that users may choose another language, nor any documented justification that the skill is intentionally limited to a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation description includes "自检/体检", which are broad natural-language phrases that can occur in ordinary conversation and may unintentionally invoke the skill. The file does not provide exclusion conditions or negative examples to clarify when these phrases should or should not activate the mode.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · AGENTS.md (reported line 33)May include surrounding context.

md
逐项输出 `✅ / ⚠️ / ⛔ + 一句话`:

1. **系统层完整性**:`AGENTS.md`、`CLAUDE.md`、`modes/_shared.md`、各模式文件,以及全部 `templates/policy-notes.*.yml` 与 `templates/official-sources.*.yml`(现为 cn / eu / apac 三对)存在且非空。
2. **技能链接**:`.claude/skills/house-ops`、`.zcode/skills/house-ops` 符号链接可解析到 `.agents/skills/house-ops/SKILL.md`。
3. **用户层状态**:
   - `config/profile.yml` 存在?(缺失 → 建议先跑 intake)
   - `modes/_profile.md` / `_brief.md` / `_custom.md` 存在性(可选件,缺失只提示)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · modes/doctor.md (reported line 10)May include surrounding context.

md
逐项输出 `✅ / ⚠️ / ⛔ + 一句话`:

1. **系统层完整性**:`AGENTS.md`、`CLAUDE.md`、`modes/_shared.md`、各模式文件,以及全部 `templates/policy-notes.*.yml` 与 `templates/official-sources.*.yml`(现为 cn / eu / apac 三对)存在且非空。
2. **技能链接**:`.claude/skills/house-ops`、`.zcode/skills/house-ops` 符号链接可解析到 `.agents/skills/house-ops/SKILL.md`。
3. **用户层状态**:
   - `config/profile.yml` 存在?(缺失 → 建议先跑 intake)
   - `modes/_profile.md` / `_brief.md` / `_custom.md` 存在性(可选件,缺失只提示)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown skill specifies all instructions, outputs, and user-facing report structure in Chinese without indicating that another language can be selected. That creates a language/locale policy issue because it effectively requires Chinese usage rather than offering user choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The mode explicitly instructs the agent to persist a structured buyer profile to disk, including family composition and later highly sensitive qualifiers, but does not require a prior notice, consent prompt, retention policy, or deletion option. In this context, the collected data can include household structure, children, elders, location anchors, financial limits, and qualification status, making silent persistence a meaningful privacy and safety risk rather than a purely theoretical issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill defaults to Chinese, WeChat-style messaging for negotiation scripts without a clear opt-in. While not a classic security flaw, it can cause unintended disclosure, miscommunication, or social-engineering risk if the generated message uses a channel, language, or tone the user did not intend to send.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/dashboard.mjs:70

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/selftest.mjs:237