Back to skill

Security audit

processon-ai-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill’s diagram features match its stated purpose, but its API-key authorization flow and persistent credential storage deserve careful review before installation.

Install only if you trust ProcessOn and are comfortable granting this skill access to create, edit, search, and export files in your ProcessOn account. Only approve authorization links generated during your own session, and revoke or rotate the ProcessOn API key if you suspect an authorization link was opened from an untrusted source.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get-token.mjs:98
Finding

Forgeable Authorization Flow Can Expose User API Keys

Content
View full analysis

Vulnerability Details

File Location: scripts/get-token.mjs, lines 98 and 289–402
Vulnerability Type: Hardcoded shared secret in a client-generated authorization flow
Risk Level: Medium

Complete Code Snippet

js
authPsk: process.env.PO_AUTH_PSK || "processon_mcp_psk_2026",
js
function generateCode() {
  const byteLen = 4 + Math.floor(Math.random() * 4); // 4~7
  const randomId = crypto.randomBytes(byteLen).toString("hex");
  const timestamp = Math.floor(Date.now() / 1000);
  const payload = `po_mcp_${randomId}_${timestamp}`;

  const md5Hex = crypto.createHash("md5").update(config.authPsk).digest("hex");
  const ivHex = md5Hex.split("").reverse().join("");
  const cipher = crypto.createCipheriv("aes-128-cbc", Buffer.from(md5Hex, "hex"), Buffer.from(ivHex, "hex"));
  const encryptedBuf = Buffer.concat([cipher.update(payload, "utf8"), cipher.final()]);
  const base64Str = encryptedBuf.toString("base64");
  const result = base64Str.replace(/\+/g, "-").replace(/\//g, "_").replace(/=+$/g, "");
  if (result.length < 26 || result.length > 49) return generateCode();
  return result;
}
js
function generateAuthUrl() {
  ensureStateDir();
  const code = generateCode();
  fs.writeFileSync(codeFile, `${code}\n`, { encoding: "utf8", mode: 0o600 });
  return `${config.authBase}?uuid=${code}&origin=skill&source=processon_skill&payPointSource=${encodeURIComponent(SKILL_SOURCE)}`;
}
js
async function queryToken(uuid) {
  const url = new URL(config.tokenQueryPath, config.apiBase);
  url.searchParams.set("uuid", uuid);
  return requestJson(url);
}

async function fetchToken(explicitCode) {
  const code = readCode(explicitCode);
  if (!code) { console.log("ERROR:no_code"); return 1; }

  let payload;
  try { payload = await queryToken(code); } catch { console.log("ERROR:network"); return 1; }

  const token = extractToken(payload);
  if (token) {
    if (saveToken(token)) { cleanup(); console.log("TOKEN_READY"); return 0; }
    consol
...[truncated 2204 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace client-generated encrypted authorization codes with cryptographically random, one-time device codes issued by the server.
  2. Bind token redemption to a separate verifier held only by the initiating client, such as a PKCE-style verifier and challenge.
  3. Do not embed shared authentication secrets in distributed client code. Treat all values shipped in the Skill package as public.
  4. Clearly display the requesting client and authorization scope to the user before approval.
  5. Make each authorization code single-use and invalidate it atomically after successful redemption.
  6. Enforce short expiration periods, strict rate limits, and replay detection on authorization and token-query endpoints.
  7. Bind the authorization transaction to its intended client instance where feasible.
  8. Review and revoke credentials issued through suspicious or replayed authorization transactions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (57)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
- **`scripts/mcp.mjs`**:MCP 直连客户端。所有脚本通过它用 Node 原生 fetch 调 MCP JSON-RPC 接口(`Accept: application/json`,不经 mcporter,规避 SSE 406 问题)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
- **`scripts/mcp.mjs`**:MCP 直连客户端。所有脚本通过它用 Node 原生 fetch 调 MCP JSON-RPC 接口(`Accept: application/json`,不经 mcporter,规避 SSE 406 问题)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
- **`scripts/mcp.mjs`**:MCP 直连客户端。所有脚本通过它用 Node 原生 fetch 调 MCP JSON-RPC 接口(`Accept: application/json`,不经 mcporter,规避 SSE 406 问题)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
- **`scripts/mindcreate.mjs`**:思维导图线专用,AI 只给 Markdown 与主题名;脚本内部完成 theme JSON 取值、base64 编码与落库(新建/编辑一条命令)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- **`scripts/mindcreate.mjs`**:思维导图线专用,AI 只给 Markdown 与主题名;脚本内部完成 theme JSON 取值、base64 编码与落库(新建/编辑一条命令)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
- **`scripts/mindcreate.mjs`**:思维导图线专用,AI 只给 Markdown 与主题名;脚本内部完成 theme JSON 取值、base64 编码与落库(新建/编辑一条命令)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
- **`scripts/mindcreate.mjs`**:思维导图线专用,AI 只给 Markdown 与主题名;脚本内部完成 theme JSON 取值、base64 编码与落库(新建/编辑一条命令)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
- **`scripts/mindcreate.mjs`**:思维导图线专用,AI 只给 Markdown 与主题名;脚本内部完成 theme JSON 取值、base64 编码与落库(新建/编辑一条命令)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
- **`scripts/mindcreate.mjs`**:思维导图线专用,AI 只给 Markdown 与主题名;脚本内部完成 theme JSON 取值、base64 编码与落库(新建/编辑一条命令)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
- **`scripts/mindcreate.mjs`**:思维导图线专用,AI 只给 Markdown 与主题名;脚本内部完成 theme JSON 取值、base64 编码与落库(新建/编辑一条命令)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
- **`scripts/mindcreate.mjs`**:思维导图线专用,AI 只给 Markdown 与主题名;脚本内部完成 theme JSON 取值、base64 编码与落库(新建/编辑一条命令)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
- **`scripts/export.mjs`**:导出文件为图片 / PDF 并下载到本地 `~/Downloads/`,AI 直接调用:`node scripts/export.mjs chartId=<id> type=png|svg|pdf name='<文件标题>'`(`name` 建议总是传,否则文件名会

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
- **`scripts/export.mjs`**:导出文件为图片 / PDF 并下载到本地 `~/Downloads/`,AI 直接调用:`node scripts/export.mjs chartId=<id> type=png|svg|pdf name='<文件标题>'`(`name` 建议总是传,否则文件名会

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
- **`scripts/export.mjs`**:导出文件为图片 / PDF 并下载到本地 `~/Downloads/`,AI 直接调用:`node scripts/export.mjs chartId=<id> type=png|svg|pdf name='<文件标题>'`(`name` 建议总是传,否则文件名会

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
- **`scripts/svg2pdf.mjs`**:本地 SVG→PDF 转换器(`export.mjs type=pdf` 内部自动调用;也可单独用 `node scripts/svg2pdf.mjs <in.svg> [-o out.pdf]`)。引擎自动探测:Chrome/Chromium/Edge head

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
- **`scripts/get-version.mjs`**:版本自检(非阻塞)。拉取线上版本信息与本地比对,输出 `STATUS` / `CHANGELOG`,供会话首次成功后决定要不要提示更新。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
- **`scripts/get-version.mjs`**:版本自检(非阻塞)。拉取线上版本信息与本地比对,输出 `STATUS` / `CHANGELOG`,供会话首次成功后决定要不要提示更新。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
- **`scripts/get-version.mjs`**:版本自检(非阻塞)。拉取线上版本信息与本地比对,输出 `STATUS` / `CHANGELOG`,供会话首次成功后决定要不要提示更新。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- **`scripts/env.mjs`**:多环境解析与凭据分槽(正式 / 灰度 / 测试),同时提供当前环境的**用户侧链接表**。当前环境的端点、mcporter 服务名、凭据读写统一由它决定;切换环境用 `PO_ENV`(缺省取**默认环境**,见下文「多环境」)。环境清单分两层:**包内 `scripts/

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
| 查看当前环境 / 各环境授权情况 / 当前环境的用户侧链接 | `node scripts/get-token.mjs processon_env_info` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
| 查看当前环境 / 各环境授权情况 / 当前环境的用户侧链接 | `node scripts/get-token.mjs processon_env_info` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
| 查看当前环境 / 各环境授权情况 / 当前环境的用户侧链接 | `node scripts/get-token.mjs processon_env_info` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
| 查看当前环境 / 各环境授权情况 / 当前环境的用户侧链接 | `node scripts/get-token.mjs processon_env_info` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
| 查看当前环境 / 各环境授权情况 / 当前环境的用户侧链接 | `node scripts/get-token.mjs processon_env_info` |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
| 查看当前环境 / 各环境授权情况 / 当前环境的用户侧链接 | `node scripts/get-token.mjs processon_env_info` |

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/export.mjs:211

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/get-token.mjs:131

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/setup/setup.cjs:72

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/svg2pdf.mjs:69