Back to skill

Security audit

Ai Shopping Assistant

Security checks for vulnerabilities and agentic risk

Overview

The shopping assistant appears purpose-built and non-malicious, but it asks for broader Python execution authority than its own engine needs.

Install only if you are comfortable granting this skill broad local Python execution in addition to web research permissions. Prefer a version that restricts Bash to the bundled workbuddy_shopping.py entry point and required flags, and expect Chinese-language prompts and reports.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:4
Finding

Overly Broad Python Execution Permission Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 4
Vulnerability Type: Overly broad interpreter execution permission
Risk Level: Medium

yaml
allowed-tools: Read, WebSearch, WebFetch, Skill, Bash(python3:*), Bash(python:*)

Technical Analysis

The Skill only needs to run its bundled entry point, scripts/workbuddy_shopping.py. However, the wildcard permissions Bash(python3:*) and Bash(python:*) authorize the interpreters with arbitrary arguments rather than limiting execution to that entry point.

Depending on the host's tool-policy semantics, this can permit commands such as python3 -c '<code>', execution of arbitrary local scripts, or Python standard-library calls that access files, create network connections, and launch child processes. The restrictions implemented by the bundled shopping engine do not constrain separate interpreter commands invoked through this broad permission.

No evidence indicates that the bundled code abuses this capability. The risk arises from granting more execution authority than the Skill's legitimate functionality requires.

Attack Path

  1. The Skill is loaded with wildcard permission to invoke python or python3.
  2. A malicious webpage, conflicting instruction, or other untrusted content attempts to induce a Bash call using one of those interpreters.
  3. The command satisfies the broad interpreter allowlist even if it does not invoke scripts/workbuddy_shopping.py.
  4. Arbitrary Python code executes with the operating-system privileges and resource access available to the Agent process.
  5. That code may access readable files, contact external systems, or start subprocesses where the runtime sandbox permits those operations.

Exploitation still requires an instruction path capable of inducing an unintended tool call and is subject to any additional sandbox controls enforced by the host.

Impact Assessment

Successful exploitation could bypass the ...[truncated 477 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace wildcard interpreter permissions with a rule restricted to the exact bundled entry point:
    • scripts/workbuddy_shopping.py
    • The explicitly required flags, such as --self-test and --version
    • JSON input supplied through standard input
  2. Explicitly deny interpreter options that execute arbitrary code, particularly -c, -m, interactive mode, and arbitrary script paths.
  3. Prefer a dedicated non-shell tool or fixed wrapper that:
    • Accepts only a JSON object.
    • Enforces the 4 MB input limit.
    • Invokes only the bundled engine.
    • Uses a fixed working directory and sanitized environment.
    • Rejects unknown flags and paths.
  4. Apply runtime sandboxing even after narrowing the allowlist:
    • Disable outbound networking.
    • Restrict filesystem access to required read-only resources.
    • Prevent child-process creation.
    • Run with a low-privilege operating-system identity.
  5. Add a release-time policy test that fails if wildcard Python or unrestricted shell permissions are reintroduced.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (17)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
请求结构参考 `schemas/engine-request.schema.json`。Agent 负责收集并结构化证据,Python 引擎负责确定性计算。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire README is written in Chinese and presents the skill as a general-purpose shopping assistant, but it does not state that the skill is region-specific or provide any language-choice/opt-in mechanism. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

该 manifest 描述包含“我不知道买什么”“帮我比较几个商品”“哪里买更合适”等自然语言示例,这些短语非常接近日常通用求助表达,且未给出明确边界或排除条件。由于文件未限定这些示例仅在特定入口、平台或上下文中触发,容易造成技能被过度匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code constructs warning messages exclusively in Chinese string literals. For a general-purpose code file, forcing a specific language without user opt-in can violate language/locale policy because downstream users may be unable to understand important safety guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The user-facing question strings are all written in Chinese, which makes the skill's interaction language effectively fixed for clarification prompts. There is no visible opt-in, fallback, or documentation in this file indicating that the skill is intentionally region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code emits multiple user-visible strings in Chinese, including evidence labels, warnings, level names, and the legal note. That effectively forces a specific language/locale for all users, and the file does not show any opt-in, localization mechanism, or documented region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains multiple user-facing strings in Chinese, such as default discount names, rejection reasons, analyses, requirements, and the final rule text. Because the file does not indicate that the skill is region-specific or provide any user opt-in or language selection, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code emits a fixed Chinese-language note string in the returned item, which imposes a specific language on all users. This is a natural-language policy issue because there is no opt-in, locale selection, or documented region-specific justification for restricting output language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The returned top-level field contains a fixed Chinese-language description, which enforces a specific locale for user-facing output. The file does not provide any mechanism for language selection or explain that the skill is limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code returns multiple fixed Chinese-language messages in warnings and report fields, which imposes a specific language on users. The file does not indicate any user opt-in, locale selection, or justified region-specific requirement, so it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code returns user-facing natural-language strings in Chinese, including the ignored-review reason and warning messages. Because the file provides no language selection, fallback, or documented locale constraint, it imposes a specific language/locale and violates the language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The returned plan includes user-facing natural-language strings in Chinese, such as the fallback guidance and safety instructions. Because the file also supports multiple country profiles including US and TH, forcing Chinese output here appears to impose a language choice without user opt-in or a documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The returned natural-language warning string is fixed as Chinese text, which forces a specific language for at least part of the skill output. The file does not indicate user opt-in for Chinese or document that this is a region-specific skill, so this appears to violate the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The function explicitly prioritizes and returns location data from multiple sources including ip, which is privacy-relevant user/system data. There is no confirmation prompt, user-visible log, or explanatory comment/docstring in this file disclosing that IP-based location may be used to influence behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language title is fixed as "WorkBuddy AI Shopping Engine Request" with no indication that alternate languages or locale options are supported. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The self-test payload uses multiple Chinese-language literals such as "未知补贴", "售后", and "该页面要求私下转账并只展示A品牌". For a general-purpose engine file, embedding a single language in natural-language examples can reflect a locale-specific assumption without any opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The returned reason message is a natural-language string in Chinese, which forces a specific language for user-visible output. The file provides no indication of locale selection, user preference handling, or justification for restricting output to that language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.