Back to skill

Security audit

Data Pipeline

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent data-pipeline helper with real hardening issues, but I found no hidden execution, credential access, persistence, exfiltration, or destructive behavior.

Install only if you are comfortable with a Chinese-language JavaScript helper and can update or audit the dev dependency tree. Avoid feeding attacker-controlled field names, rename maps, join keys, or defaults into the transforms until the special-key handling is hardened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
src/pipeline.js:328
Finding

Unsafe Dynamic Property Keys Enable Object Prototype Manipulation and Denial of Service

Content
View full analysis
{ const result = { ...item }; for (const [oldName, newName] of Object.entries(fieldMap)) { if (result[oldName] !== undefined) { result[newName] = result[oldName]; delete result[oldName]; } } return result; }); } const result = { ...data }; for (const [oldName, newName] of Object.entries(fieldMap)) { if (result[oldName] !== undefined) { result[newName] = result[oldName]; delete result[oldName]; } } return result; ``` #### Merge lookup, lines 462–471 ```javascript const lookup = {}; for (const source of sources) { for (const item of source) { const key = item[joinKey]; if (key !== undefined) lookup[key] = { ...lookup[key], ...item }; } } return data.map(item => { const key = item[joinKey]; return key !== undefined ? { ...item, ...(lookup[key] || {}) } : { ...item }; }); ``` #### Default-field assignment, lines 608–614 ```javascript const result = { ...item }; for (const [field, defaultValue] of Object.entries(fieldDefaults)) { if (result[field] === undefined || result[field ...[truncated 4280 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Known Vulnerable Dependency: brace-expansion==2.1.0 — 3 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro); CVE-2026-69152 (brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-1)

High
Category
Supply Chain
Confidence
97% confidence
Finding

The lockfile pins brace-expansion 2.1.0, which is reported as vulnerable to denial-of-service conditions from pathological brace patterns that can trigger excessive CPU or memory consumption. Even though this package is a transitive dev dependency, vulnerable parsers and pattern expanders can still be exercised during local development, CI, or automated test runs where attacker-controlled patterns may be processed.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: js-yaml==4.1.1 — 4 advisory(ies): CVE-2026-84375 (js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources); CVE-2026-59869 (js-yaml: YAML merge-key chains can force quadratic CPU consumption); GHSA-5p4m-2wfm-xmqj (JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026) +1 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

The lockfile pins js-yaml 4.1.1, which has multiple reported CPU exhaustion issues involving crafted YAML structures such as merge-key chains and omap handling. Although present as a transitive dev dependency, YAML parsing libraries are high-risk when any untrusted or semi-trusted input can reach them in test fixtures, CI inputs, or auxiliary tooling.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: serialize-javascript==6.0.2 — 2 advisory(ies): GHSA-5c6j-r48x-rmvq (Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.to); CVE-2026-34043 (Serialize JavaScript has CPU Exhaustion Denial of Service via crafted array-like)

High
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile includes serialize-javascript 6.0.2, which has reported risks including potential RCE vectors and CPU exhaustion when serializing crafted input. Because serialization libraries can become dangerous when used on attacker-controlled objects, the presence of this package in the test/tooling chain increases supply-chain and developer-environment risk even if it is not part of production runtime.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger conditions are very broad and consist of common data-processing terms that can appear in many benign conversations. This can cause the skill to activate unintentionally, increasing the chance that it handles user data or influences responses outside its intended scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This JavaScript file contains natural-language comments and console output entirely in Chinese, including the title, example headings, and status messages. Under the policy, forcing a specific language without user opt-in is a locale-policy violation unless the restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The header comments and feature descriptions are presented exclusively in Chinese, which creates a language/locale constraint in the skill’s natural-language interface. Under the policy, forcing a specific language without opt-in or justification is a violation, and this file does not provide an alternative language option or state that the skill is region-specific.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

标题与全文均以中文呈现,且未说明这是可选语言、区域限定要求,或提供其他语言选项。按规则,若技能在自然语言层面强制特定语言而无用户选择或正当说明,属于语言/区域策略风险。

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: diff==7.0.0 — 1 advisory(ies): CVE-2026-24001 (jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch)

Low
Category
Supply Chain
Confidence
83% confidence
Finding

The lockfile includes diff 7.0.0, which has a reported denial-of-service issue in patch parsing/application routines. In this file it appears only as a dev dependency through Mocha, so exposure is more limited, but if untrusted patch content is ever processed in tests or developer tooling, it could cause resource exhaustion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written entirely in Chinese, which can constitute a language/locale policy issue when the skill does not offer a user language choice or document that it is intentionally region-specific. Nothing in the file indicates this package is limited to a Chinese-speaking context or provides multilingual support.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"etl"
  ],
  "devDependencies": {
    "mocha": "^11.7.5"
  }
}

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s natural-language comments and test descriptions are written in Chinese, including the suite header and coverage notes. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation, and this file does not indicate that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.