Back to skill

Security audit

AIPyApp - AI自动化任务执行工具

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real AI automation helper, but it asks users to install and run broad code-generating automation with system-wide package changes and weak privacy/secret guidance.

Review before installing. Use a virtual environment or pipx instead of `--break-system-packages`, pin the package version, avoid running the installer as root unless you intentionally accept system changes, keep API keys out of logs and generated files, and disable result sharing or auto-install behavior unless you explicitly need it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
scripts/install.sh:17
Finding

Unpinned Third-Party Package Installed into the System Python Environment

Content
View full analysis
/dev/null; then echo "📦 安装 python3-pip..." apt update && apt install -y python3-full python3-pip fi echo "✅ pip 已就绪" # 安装 aipyapp echo "📦 安装 aipyapp..." python3 -m pip install aipyapp --break-system-packages ``` `SKILL.md:26-33`: ```bash # 检查并安装 python3-pip apt update && apt install -y python3-full python3-pip # 安装 aipyapp python3 -m pip install aipyapp --break-system-packages ``` ### Technical Analysis The installation process retrieves `aipyapp` from the package index without specifying an audited version or cryptographic hash. Consequently, the package content installed at any given time can differ from the content that was previously reviewed. Python packages can execute arbitrary code during installation and when their modules or command-line entry points are used. If the upstream package, maintainer account, distribution infrastructure, or a future release is compromised, executing this installer can introduce attacker-controlled code. The `--break-system-packages` option bypasses Python's externally managed environment protection. Instead of isolating the dependency in a virtual environment, the command permits changes to the system Python environment. This can overwrite or conflict with packages used by other applications and broadens the effect of a compromised dependency. The repository does not include a lockfile, version constraint, hash manifest, vendored source, or other integrity control for the installed package. The external package's implementation therefore falls outside the reviewed project and cannot be verified by this static audit. ### Attack Path 1. An attacker compr ...[truncated 1551 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises trigger phrases such as '抓取网页', '执行python脚本', and '自动化任务', which are common user intents rather than narrowly scoped tool-invocation phrases. This can cause the skill to activate unexpectedly for routine requests and route the user into a workflow that generates code, installs packages, and executes automation with materially higher risk than the user may realize.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The overview states that the tool will write and execute Python scripts and install dependencies, but it does not warn the user that this may modify the filesystem, invoke network access, or run untrusted/generated code. In this skill context, the omission is especially dangerous because the core function is autonomous code execution based on natural-language input, which raises the chance of unsafe actions without informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing descriptions, triggers, and examples are presented only in Chinese, with no indication that another language can be used or that the language choice is intentional and limited to a region-specific context. This can violate language/locale policy when a skill implicitly constrains interaction language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs users to place API credentials in a local config file but provides no warning about secret storage, file permissions, redaction, or avoiding accidental disclosure in logs and outputs. Because this same tool can generate and execute code, mishandled credentials could be exposed to generated scripts, external services, or copied artifacts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
[llm.openai]
type = "openai"
api_key = "sk-your-key"
base_url = "https://api.openai.com/v1"
model = "gpt-4"
enable = true
default = true

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/config.md (reported line 9)May include surrounding context.

md
[llm.openai]
type = "openai"
api_key = "sk-your-key"
base_url = "https://api.openai.com/v1"
model = "gpt-4"
enable = true
default = true

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/config.md (reported line 58)May include surrounding context.

md
[llm.openai]
type = "openai"
api_key = "sk-your-key"
base_url = "https://api.openai.com/v1"
model = "gpt-4"
enable = true
default = true

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration template includes third-party API endpoints and a full example enabling result sharing (share_result = true) without any warning that prompts, scraped data, files, or outputs may be transmitted to external services. In the context of an AI-driven automation tool that can process user data and perform web/file tasks, this omission materially increases the risk of unintended data disclosure and privacy violations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs apt update and installs python3-full and python3-pip, which are system-wide package-manager operations beyond the narrow task of installing the Python package. In the context of an agent skill that may be invoked by non-expert users for automation, silently modifying the host OS increases attack surface, can change unrelated system state, and may have privileged side effects users did not intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script makes package-manager changes and installs software without any confirmation, warning, or dry-run path, which is risky for an installation path likely to be triggered through an AI-driven skill. Because the skill is designed for automated execution, this lack of consent is more dangerous than in a purely manual admin script: users may not realize the host system will be modified, and privileged execution could lead to unintended persistence or environment breakage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple comments and output strings are written only in Chinese, including installation status and usage instructions. Under the language policy, forcing a single language without opt-in or a documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.