Back to skill

Security audit

AI编程工程化

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language workflow guide for improving AI-assisted software engineering, with no executable payload, but users should treat its CI example as a template that needs safer dependency pinning.

Install this if you want a Chinese AI-assisted engineering workflow checklist. Before reusing the included GitHub Actions example, pin GitHub Actions and audit tools to reviewed versions or lockfile-managed dependencies, and adjust triggers/output language if broad activation or Chinese-only responses are not desired.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/details.md:271
Finding

Unpinned Package Retrieval and Execution in CI

Content
View full analysis

Vulnerability Details

File Location: references/details.md, lines 271–276
Vulnerability Type: Unpinned third-party package execution
Risk Level: Medium

Vulnerable Code:

yaml
security:
  runs-on: ubuntu-latest
  steps:
    - uses: actions/checkout@v4
    - name: Security Scan
      run: npx audit-ci --high

Technical Analysis

The CI example invokes npx audit-ci --high without showing that audit-ci is installed from an exact, reviewed version recorded in a committed lockfile. If the package is unavailable locally, npx may retrieve the current package release from the configured npm registry and execute it immediately.

This makes the effective code executed by the workflow mutable after the Skill has been reviewed. The resulting supply-chain risk includes package-registry compromise, maintainer-account compromise, or an unexpectedly unsafe future release. The example also references actions/checkout@v4 by a moving major-version tag rather than an immutable reviewed commit SHA, which provides weaker integrity guarantees.

Attack Path

  1. A user copies the documented workflow into a repository.
  2. The workflow runs in response to a push or pull request.
  3. The security job invokes npx audit-ci --high.
  4. If audit-ci is not installed locally, npx resolves and downloads it from the configured registry.
  5. A compromised or unsafe resolved release executes with the permissions of the CI runner.
  6. The package can read checked-out repository content, inspect environment data and credentials exposed to that job, alter workspace files, or influence subsequent build outputs.

Successful exploitation depends on compromise or malicious modification of the resolved dependency or its distribution channel.

Impact Assessment

Arbitrary package code can execute with CI-runner privileges. The accessible scope may include:

  • Checked-out source code and repository metadata
  • Environment variables available to the security ...[truncated 334 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add audit-ci to devDependencies using an exact reviewed version rather than relying on runtime package resolution.
  2. Commit the package lockfile and install dependencies with npm ci.
  3. Prevent npx from downloading missing packages:
yaml
- name: Install
  run: npm ci

- name: Security Scan
  run: npx --no-install audit-ci --high
  1. Alternatively, invoke a lockfile-controlled npm script:
json
{
  "scripts": {
    "security:audit": "audit-ci --high"
  }
}
yaml
- name: Security Scan
  run: npm run security:audit
  1. Pin GitHub Actions to reviewed immutable commit SHAs instead of moving tags.
  2. Configure minimal workflow permissions, for example contents: read, and grant no write permissions unless explicitly required.
  3. Avoid exposing deployment credentials or unrelated secrets to dependency-scanning jobs.
  4. Use dependency update automation with mandatory review and CI validation for version changes.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes very broad, generic terms such as '开发流程', '代码质量', and '软件质量', which can cause the skill to activate in many unrelated contexts. Over-broad activation is dangerous because it can unexpectedly inject this workflow's instructions into conversations where the user did not request it, potentially overriding more appropriate skills or steering the assistant into rigid process-heavy behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file hardcodes '中文输出', forcing responses in Chinese regardless of the user's language or system context. This can create instruction conflict, reduce usability, and in some environments cause the assistant to ignore user preferences or higher-level localization requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The document title and all instructional content are written entirely in Chinese, which can function as a language constraint for users consuming the skill guidance. There is no indication that users may choose another language or that the Chinese-only presentation is required for a region-specific or compliance-related reason.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The CI example invokes npx audit-ci --high without pinning an exact package version, so every pipeline run may fetch whatever version is current on the registry at that time. In a security-sensitive workflow document, this creates supply-chain risk and undermines build reproducibility; a malicious or compromised upstream release could execute in CI with repository access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.