Back to skill

Security audit

VC 大师指南

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language educational guide for Visual Components, with no bundled executable code, but users should verify any community plugin downloads it references.

Installers should treat this as a Visual Components learning reference. Before following its forum-plugin recommendation, confirm the plugin source, version, and integrity, and test community attachments in a non-production environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:363
Finding

Unverified Third-Party Plugin Download and Import

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 363–369
Vulnerability Type: Unverified third-party dependency
Risk Level: Medium

Vulnerable snippet:

markdown
**链接:** https://forum.visualcomponents.com/t/cad-attribute-reader-example/3205
**浏览:** 3.7k | **回复:** 30 | **价值:** ⭐⭐⭐⭐⭐

**内容:** 2D CAD 转 3D 布局工具

**使用方法:**
1. 下载插件(论坛附件)

Technical Analysis

The guide instructs users to download and use a plugin attached to a community forum post. It does not identify an immutable artifact URL, trusted publisher, exact plugin version, cryptographic checksum, digital signature, or source-review procedure.

Although the forum is hosted under the Visual Components domain, community attachments are not necessarily vendor-maintained, security-reviewed, or immutable. A plugin can contain executable logic and may run with the permissions of Visual Components or the current user. Consequently, the security properties of the resulting installation depend on mutable third-party content that is outside this project and was not available for audit.

This is an insecure supply-chain practice rather than evidence that the currently linked attachment is malicious.

Attack Path

  1. An attacker compromises the forum account, thread, attachment storage, or another mechanism capable of replacing or modifying the referenced attachment.
  2. Alternatively, a deceptive or malicious attachment is presented in the referenced discussion.
  3. A user follows the guide and downloads the forum attachment without verifying its publisher, signature, version, or digest.
  4. The user imports or installs the plugin in Visual Components.
  5. Any attacker-controlled plugin logic executes with the host application's or user's effective permissions.

Impact Assessment

Successful exploitation could permit arbitrary code execution within the plugin host's security context. Depending on Visual Components' plugin model and the user's permissions, the malicious component ...[truncated 332 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer a vendor-reviewed plugin distributed through an official, authenticated plugin repository.
  2. Identify the expected publisher, plugin name, and exact version.
  3. Link to an immutable release artifact rather than a mutable forum discussion or generic attachment.
  4. Publish a trusted SHA-256 digest or require verification of a valid digital signature before installation.
  5. Where source is available, require review of the source and ensure that the binary corresponds to that source.
  6. Warn users that community attachments are third-party content and should not be assumed safe merely because they are hosted on the vendor's forum.
  7. Recommend evaluating the plugin first in an isolated, least-privileged environment without production projects, credentials, or unrestricted network access.
  8. Document safe removal and recovery procedures in case unexpected behavior occurs.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README presents the skill entirely in Chinese, including headings, usage guidance, and example prompts, which effectively imposes a language preference on users. There is no statement offering multilingual support, user language selection, or justification that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example trigger phrase is broad enough to match ordinary user requests such as general learning or help queries, which can cause the skill to activate unintentionally outside a clearly bounded Visual Components context. This increases the chance of inappropriate routing, user confusion, or over-application of the skill to ambiguous prompts, though the content here appears educational rather than overtly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill mandates a single language for all instructions and examples, but does not provide any user opt-in, alternative language option, or justification that the skill is intended only for a Chinese-speaking audience. That creates a natural-language policy concern under the language/locale rule because users are forced into one locale by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.