Back to skill

Security audit

Api Doc Gen

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward API documentation generator with user-directed local file access, but it has dependency and disclosure hygiene issues users should notice before installing.

Install in a virtual environment, pin or lock dependency versions before production use, and review generated OpenAPI/Postman/Markdown files before sharing them because they may reveal internal API structure. Expect Chinese-language CLI/help text and documentation unless the maintainer adds locale support.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unbounded Third-Party Dependency Versions Expand the Supply-Chain Attack Surface

Content
View full analysis

Vulnerability Details

File Location: requirements.txt, lines 1-2
Vulnerability Type: Unbounded dependency resolution
Risk Level: Medium

Affected Code:

text
pytest>=7.0.0
pyyaml>=6.0

The affected installation command is documented in README.md, line 27:

bash
pip install -r requirements.txt

Technical Analysis

Both dependencies specify only minimum versions. Consequently, package installation may resolve to any future release accepted by the package index rather than to a version that the project maintainers reviewed and tested.

If a future release, package-index account, distribution channel, or dependency in the resolved graph is compromised, users following the documented installation procedure could receive attacker-controlled package code. Python packages and their transitive dependencies may execute code during build or installation and later when imported.

The exposure is unnecessarily broad because pytest is used only by the test suite but is included in the general requirements file. PyYAML is a runtime dependency for generator.py, where YAML output imports yaml, despite SKILL.md claiming that the project uses only the standard library.

This finding does not establish that the currently available PyPI releases are malicious. The vulnerability is the absence of reproducible, reviewed dependency constraints and integrity verification.

Attack Path

  1. An attacker compromises a permitted future release of pytest, PyYAML, or a resolved transitive dependency, or compromises its package distribution account.
  2. The attacker publishes a release whose version satisfies the open-ended >= constraint.
  3. A user follows the documented command, pip install -r requirements.txt.
  4. pip selects and downloads the compromised release because no exact version, lock file, or cryptographic hash restricts resolution.
  5. Attacker-controlled package code ...[truncated 720 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin reviewed dependency versions exactly instead of using open-ended lower bounds.
  2. Generate and commit a reproducible lock file covering transitive dependencies.
  3. Use hash verification, such as pip's --require-hashes, to validate downloaded distributions.
  4. Separate runtime and development dependencies:
    • Keep PyYAML in the runtime dependency set only if YAML output remains supported.
    • Move pytest to a development or test requirements file.
  5. Use automated dependency scanning and controlled update reviews before accepting newer releases.
  6. Install dependencies in an isolated virtual environment or unprivileged CI container rather than with administrative privileges.
  7. Correct SKILL.md so that it accurately discloses the PyYAML dependency.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (13)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 152)May include surrounding context.

[2] POST /api/users

[3] GET /api/users/:id

[4] PUT /api/users/:id

[5] DELETE /api/users/:id

text

### 示例 5:直接从代码字符串生成

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description is presented in Chinese and positions the tool around Chinese project adaptation, but it does not offer the user a language/locale choice or state that the skill is intentionally region-specific. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README encourages batch analysis of whole projects and export of OpenAPI/Postman artifacts, but it does not warn that generated documentation may include internal endpoints, sensitive parameter names, example data, or unpublished administrative APIs. In practice, users may share or publish the generated outputs without reviewing them, leading to unintentional information disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The natural-language content of the skill file is entirely Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Per the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module description states in Chinese that it generates API documentation from code, and the rest of the built-in descriptions and response text are also hard-coded in Chinese. This creates a language/locale policy concern because the skill appears to enforce a specific language without any user opt-in or configurable locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The phrase indicating compatibility with 'Chinese project' API style introduces a locale-specific framing that may steer outputs toward one regional convention without asking the user. The file does not clarify that this is optional or limited to a region-specific compliance need.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file describes a batch command using -o docs/, which implies creating or overwriting generated documentation files on the local filesystem. The skill description does not include any warning or note about file-writing behavior, so users may not realize it modifies disk contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code file contains user-facing natural-language text in Chinese in the module docstring, and later help strings are also primarily Chinese. The skill does not offer users an opt-in or locale selection for the CLI help language, which can violate a language/locale policy requiring user choice.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The dependency specifier for pytest uses a lower-bound range instead of an exact pinned version, which makes builds non-reproducible and can allow installation of a vulnerable or breaking release if the resolver selects an unsafe version. In a security review context this is a real supply-chain hygiene issue, though the direct impact is limited because pytest is typically a development/test dependency.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
pytest>=7.0.0
pyyaml>=6.0

Unverifiable Dependency: pytest has 2 known advisory(ies) (CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
75% confidence
Finding

Pytest has known advisories, and because the manifest does not pin an exact version, it is impossible to verify whether the installed version is affected. The risk is somewhat limited because pytest is generally a development dependency, but ambiguous version resolution still weakens assurance and could expose CI or developer environments.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specifier for PyYAML is not pinned to an exact version, so deployments may resolve to different releases over time, including versions with known security issues. This is more concerning than a test-only package because PyYAML is often used at runtime and has a history of unsafe deserialization-related vulnerabilities.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
pytest>=7.0.0
pyyaml>=6.0

Unverifiable Dependency: pyyaml has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

PyYAML has multiple historical security advisories, and the unpinned dependency means the actual installed version could be vulnerable without any visibility from the manifest alone. Given PyYAML's history with unsafe parsing/deserialization, this creates meaningful runtime risk if the package is used to process untrusted YAML.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This Python test file includes user-facing natural-language text in Chinese, beginning with the module docstring on L002 and repeated throughout docstrings and inline sample content. Under the language/locale policy, forcing a specific language without opt-in can be a policy concern when no alternative language choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.