Back to skill

Security audit

AI编程工程化

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only Chinese AI engineering workflow skill with no hidden execution, persistence, or data access, though users should review its broad activation terms and CI example before reuse.

Installers should treat this as a Chinese-language workflow/checklist skill. Before copying its CI/CD example into a real repository, pin or lock `audit-ci` and run it through controlled project dependencies. Users who do not want broad workflow intervention should narrow the trigger terms or invoke the skill only explicitly.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/details.md:276
Finding

Unpinned Third-Party Package Execution in CI Example

Content
View full analysis

Vulnerability Details

File Location: references/details.md, line 276
Vulnerability Type: Unpinned package execution through npx
Risk Level: Medium

Vulnerable Code Snippet:

yaml
security:
  runs-on: ubuntu-latest
  steps:
    - uses: actions/checkout@v4
    - name: Security Scan
      run: npx audit-ci --high

Technical Analysis

The documented CI workflow executes audit-ci through npx without specifying an exact package version. The package is also not shown as a lockfile-pinned project dependency. If the package is unavailable locally, npx may resolve, download, and immediately execute a package selected from the configured npm registry.

This creates mutable CI behavior: the code executed by the workflow may differ from the code reviewed when the workflow was created. The risk arises from the third-party package supply chain, including compromise of the package publisher, a malicious package release, registry compromise, or unsafe registry configuration.

Attack Path

  1. An attacker compromises the relevant npm package, publisher account, release process, or configured package registry.
  2. The attacker publishes or serves a malicious version that satisfies the unpinned npx audit-ci resolution.
  3. A repository adopts and runs the documented CI workflow.
  4. During the security job, npx resolves and downloads the mutable package version.
  5. Package installation lifecycle code or the invoked executable runs with the CI runner's permissions.
  6. The malicious code accesses or alters runner-visible resources, subject to the workflow's token permissions and secret exposure controls.

Impact Assessment

Successful exploitation could provide arbitrary code execution within the CI runner's security context. Potentially exposed resources include checked-out source code, environment variables, generated build artifacts, package-registry credentials, and workflow tokens av ...[truncated 304 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add audit-ci as a development dependency using an explicitly approved version and commit the generated lockfile.

  2. Install dependencies with npm ci so CI uses the exact dependency graph recorded in the lockfile.

  3. Invoke the installed binary through a package script or an offline command, for example:

    yaml
    - name: Install dependencies
      run: npm ci
    
    - name: Security Scan
      run: npm exec --offline audit-ci -- --high
    
  4. Review dependency updates through controlled pull requests and enable lockfile integrity verification.

  5. Apply least-privilege workflow permissions and avoid exposing secrets to jobs that do not require them.

  6. As defense in depth, pin third-party GitHub Actions to reviewed immutable commit SHAs rather than mutable version tags.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is extremely broad and includes generic terms like '开发流程', '代码质量', and 'API设计', which can cause the skill to activate in many unrelated conversations. Unintended activation can override more appropriate skills or inject rigid workflow instructions into contexts where they were not requested, reducing reliability and potentially steering users away from safer or more suitable guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill unconditionally forces Chinese output regardless of the user's language preference. While not a classic security flaw, this can cause misuse, misunderstanding, or policy/compliance issues in multilingual environments, especially if users cannot accurately review generated plans, review reports, or safety guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and the entire document are written in Chinese, and there is no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking or region-specific context. This creates a natural-language locale policy concern because it effectively mandates one language without user opt-in.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.