Back to skill

Security audit

test转储

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed business data-transfer automation, but it is under-scoped for unattended imports over plaintext HTTP.

Review this before installing in any real environment. Use only approved HTTPS endpoints or a trusted private network, pin dependencies, restrict the source and destination pages, require confirmation or dry-run validation before importing, avoid unattended cron until logging and rollback are in place, and clean up generated Excel files that may contain sensitive data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:32
Finding

Unpinned Third-Party Dependencies and Browser Runtime

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 32-35
Vulnerability Type: Uncontrolled third-party dependency versions
Risk Level: Medium

Vulnerable Code:

bash
pip install playwright openpyxl
playwright install chromium

Technical Analysis

The installation instructions retrieve playwright, openpyxl, and a Chromium runtime without pinning reviewed versions or validating artifact hashes. Consequently, the effective installed components can change after the skill has been reviewed.

This is an insecure supply-chain practice rather than proof that the current upstream packages are malicious. If an upstream package, package-index account, configured package repository, or downloaded browser artifact is compromised, following these instructions could install attacker-controlled content. Python packages can execute code during installation or when imported, while a compromised browser runtime would execute when the automation starts.

Attack Path

  1. An attacker compromises an upstream dependency release, package-index account, configured package source, or browser artifact.
  2. A user follows the documented installation commands.
  3. pip and Playwright resolve and download the mutable, unverified artifacts.
  4. Malicious code executes during package installation, module import, or browser startup.
  5. The code operates with the privileges of the user performing the installation or running the skill.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions, the attacker could access user-readable files, browser automation data, environment variables, authentication sessions, and network resources available to the host. No evidence shows that the referenced legitimate dependencies are currently malicious, and no privilege escalation beyond the invoking user's permissions is demonstra ...[truncated 4 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every Python dependency to a reviewed version in a lock file or fully pinned requirements file.
  • Use hash verification, such as pip install --require-hashes -r requirements.txt.
  • Pin the Playwright package and corresponding browser revision as a tested pair.
  • Download packages only from explicitly approved repositories over TLS.
  • Verify package provenance and browser artifact integrity before installation.
  • Run installation and browser automation in a non-privileged, isolated environment.
  • Add automated dependency scanning and a controlled process for reviewing version updates.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Plaintext HTTP Used for Data Export and Import Workflow

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 16-18 and 44-48
Vulnerability Type: Unencrypted transport of application data
Risk Level: Medium

Vulnerable Configuration and Workflow:

yaml
config:
  pcs_url: "http://1x.xx.xx.xx:5173"
  pcs_page: "/#/vmodelDemo"
  epbp_page: "/#/home"
text
1. Open the PCS page: http://xxx:5173/#/vmodelDemo
2. Scrape table data
3. Export it as Excel (pcs_data.xlsx)
4. Open the EBP page: http://xxx:5173/#/home
5. Automatically upload the Excel file and import it

The English rendering above preserves the documented URLs and workflow semantics from SKILL.md.

Technical Analysis

The documented workflow connects to PCS and EBP pages using plaintext HTTP while retrieving table data and uploading an Excel file. HTTP does not provide transport confidentiality, server authentication, or cryptographic integrity.

If these endpoints are accessed over an untrusted or attacker-controlled network, an on-path attacker could observe requests and responses or modify page content in transit. Because browser automation acts on the returned page, injected content could also alter the data being exported, change the destination or content of an upload, or interfere with the workflow. The actual sensitivity of the transferred data and authentication mechanism cannot be established because the project contains only documentation and no implementation.

Attack Path

  1. A user runs the documented workflow against an HTTP endpoint.
  2. An attacker gains an on-path position, such as through a compromised gateway, hostile network, DNS manipulation, or local-network interception.
  3. The attacker observes or modifies unencrypted HTTP traffic.
  4. The attacker captures exposed application data or injects modified page content and responses.
  5. The automation processes the altered content or uploads data through a tampered session, compromising workflow con ...[truncated 573 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace all http:// endpoints with https:// endpoints protected by valid, trusted certificates.
  • Configure the automation to reject certificate errors and prohibit fallback to plaintext HTTP.
  • Redirect HTTP to HTTPS at the service boundary and enable HTTP Strict Transport Security where appropriate.
  • Protect session cookies with Secure, HttpOnly, and suitable SameSite attributes.
  • Restrict access to the services through an authenticated private network when they are internal systems.
  • Validate the destination host before uploading files and verify imported/exported data integrity where feasible.
  • Avoid logging authentication headers, cookies, spreadsheet contents, or other sensitive workflow data.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases "RPA" and "数据转储" are broad and loosely scoped, so the skill may be invoked in contexts beyond the intended PCS-to-EBP transfer workflow. For a skill that automates browser actions and moves data between systems, ambiguous activation increases the chance of unintended execution against the wrong page, dataset, or environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes automated export, Excel generation, import into another system, and scheduled execution, but it does not warn users about data movement, persistence in local files, or the effect of unattended runs on external systems. In this context, omission of those warnings is risky because the automation can alter business data and repeatedly transmit potentially sensitive records without user awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.