Back to skill

Security audit

study-workbench

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent study workbench template, but its JSON customization and backup restore paths can turn untrusted files into executable browser code.

Review before installing. Use only trusted content-pack JSON and backup files, and avoid publishing generated workbenches from third-party packs until the injector escapes JSON for inline-script contexts and backup import validates or regenerates IDs. The skill does not show hidden OS-level persistence or credential access, but the browser-code injection risk is material.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/inject_pack.js:21
Finding

Content-pack injection permits arbitrary script execution in generated workbenches

Content
View full analysis
` element. JSON validity does not make text safe for an HTML script context. A JSON string may legally contain the literal sequence ``. HTML parsing terminates a script element when this sequence is encountered, even when it appears inside a JavaScript string literal. An attacker-controlled pack can therefore close the engine's script element, introduce a new script or other active HTML, and place the remainder inside a harmless element. For example, a valid JSON string value can contain a payload structurally equivalent to: ```json { "meta": { "grade": "
Remediation
View remediation
/g, '\\u003e') .replace(/&/g, '\\u0026') .replace(/\u2028/g, '\\u2028') .replace(/\u2029/g, '\\u2029'); const injected = `const CONTENT_PACK = ${safeJson};\n` + `const SUBJECTS = CONTENT_PACK.subjects;`; ``` Escaping `<` prevents `` from being recognized by the HTML parser. 3. Prefer storing the pack in a non-executable element: ```html ``` The content must still escape `<` before insertion. Parse it using `JSON.parse(document.getElementById('content-pack').textContent)`. 4. Enforce a strict schema before generating output. Reject unknown fields, malformed arrays, invalid dates, unsafe identifiers, and values exceeding reasonable size limits. 5. Add regression tests containing: - `` - HTML tags in every text field - Unicode line separators - Quotes and backslashes 6. Add a restrictive Content Security Policy. Eliminate inline event handlers and, where feasible, move JavaScript into a separate static file so `script-src 'self'` can be used without `'unsafe-inline'`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
assets/study-workbench-engine.html:2007
Finding

Structurally unvalidated backup imports enable persistent DOM-based script execution

Content
View full analysis
{ try{ const d=JSON.parse(r.result); if(typeof d!=='object') throw 0; progress=d.progress||{}; tasks=d.tasks||[]; startDate=d.startDate||START_DEFAULT; exams=d.exams||exams; previewDay=d.previewDay||null; saveJSON(KEY_PROG,progress); saveJSON(KEY_TASK,tasks); saveJSON(KEY_START,startDate); saveJSON(KEY_EXAMS,exams); saveJSON(KEY_DAY,previewDay); alert('恢复成功'); render(); }catch(e){ alert('文件格式不对,导入失败'); } input.value=''; }; r.readAsText(f); } ``` Imported task identifiers are subsequently placed directly into inline JavaScript event handlers: ```javascript return list.map(t=>`
${ICON_OK} ${esc(t.text)} ...
`).join(''); ``` The same pattern is used for imported exam identifiers: ```javascript ... 保存此项 ``` ### Technical Analysis The application checks only `typeof d === 'object'`. This test also accepts arrays and does not establish that: - `tasks` is an array of safe task records. - Task IDs are generated application ...[truncated 2688 chars]
Remediation
View remediation
toggleTask(task.id)); ``` 3. Regenerate internal task and exam IDs during import rather than trusting IDs from the file: ```javascript const safeTasks = d.tasks.map(task => ({ id: uid(), text: String(task.text).slice(0, 500), date: validateDate(task.date) ? task.date : '', done: task.done === true })); ``` 4. If identifiers must be preserved, restrict them to a safe allowlist such as: ```javascript const SAFE_ID = /^[A-Za-z0-9_-]{1,64}$/; ``` Reject any identifier that fails validation. 5. Build user-controlled content with DOM APIs and `textContent` instead of constructing HTML strings with `innerHTML`. 6. Add import regression tests containing quotes, angle brackets, backticks, newlines, malformed arrays, null values, oversized input, and JavaScript fragments in every field. 7. Consider warning users that backup files are untrusted input and should be imported only from known sources. This warning is supplementary and must not replace validation. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- **引擎**(`assets/study-workbench-engine.html`):排课/渲染/积累/任务/复习/倒计时/导出/localStorage/UI 全部逻辑,**零外部依赖**(系统字体、无 CDN、可选 `bookUrl`)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
- **引擎**(`assets/study-workbench-engine.html`):排课/渲染/积累/任务/复习/倒计时/导出/localStorage/UI 全部逻辑,**零外部依赖**(系统字体、无 CDN、可选 `bookUrl`)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
- **引擎**(`assets/study-workbench-engine.html`):排课/渲染/积累/任务/复习/倒计时/导出/localStorage/UI 全部逻辑,**零外部依赖**(系统字体、无 CDN、可选 `bookUrl`)。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README presents the skill entirely in Chinese and instructs activation with Chinese phrases, with only a single English trigger token and no stated language-choice option. This can be interpreted as a language policy violation because the skill appears to require a specific language without user opt-in or a documented locale-specific justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very generic natural-language requests like “做个学习台” and “生成学生台”, which can overlap with ordinary user conversation and cause the skill to activate unexpectedly. Unintended activation can override the user’s actual intent, inject long templated output, or steer the agent into generating artifacts the user did not request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to match ordinary study-related requests like '课程表', '备考', or generic grade/subject mentions, which can cause the skill to activate outside the user's clear intent. In an agent environment, overbroad activation increases the chance of incorrect routing, unexpected file generation, or the skill preempting more appropriate tools.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file declares lang="zh-CN" and the visible title and interface strings are entirely in Chinese, indicating a fixed locale. Because the skill does not offer any language selection or opt-in, this is a natural-language locale policy issue under the stated rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The user-facing name and description are entirely in Chinese, which signals a fixed language/locale experience without any stated option for other languages. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains generic educational phrases such as '课程表', '每日学习', and '学习台' that are likely to match ordinary user requests unrelated to this specific skill. This can cause over-broad invocation or routing, leading the skill to activate unexpectedly and potentially override user intent or expose users to generated content they did not explicitly request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L087 explicitly requires Chinese-style quotation marks, which imposes a language/locale-specific requirement in natural language. The file does not indicate that this constraint is optional, user-selected, or justified by a region-specific compliance need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON manifest embeds the skill content in Chinese, including the grade, edition note, and substantial instructional text, with no indication that users can opt into another language or locale. Under the policy rule for natural-language violations, a forced language/locale without opt-in can be a policy issue unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The requirement “国内习惯:日期 YYYY-MM-DD;配色与表达符合国内学情” is a natural-language constraint that forces a specific locale and expression style. The file does not indicate that users can choose another locale or opt into this region-specific behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

L087 says to use '弯引号' for Chinese content, but L088 immediately states the content pack must be valid JSON with double-quoted keys. Curly quotes are not valid JSON string delimiters, so this documentation actively contradicts the stated JSON requirement and would mislead users into producing invalid content packs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.