Back to skill

Security audit

Online Analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent test log analysis tool, but it broadly handles potentially sensitive logs, streams, and database-derived data without clear consent, scoping, or privacy guidance.

Install only if you are comfortable with a skill that may analyze logs, API responses, streams, or database outputs. Use sanitized test data where possible, avoid production secrets or regulated data, confirm any live-source access before running it, and prefer a pinned dependency install in an isolated environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:94
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
=3.8", "numpy": ">=1.21.0" } ``` ### Technical Analysis The installation instructions tell users to install `numpy` without selecting an exact audited version or verifying an integrity hash. The metadata similarly defines only a lower version bound. Consequently, the package artifact installed in the future may differ from the artifact reviewed when this skill was published. Package installation is a code-execution boundary because Python packages may execute build backends or installation-related code. The actual source also depends on the user's configured package index and mirror settings. A compromised package publisher, package index, mirror, or local pip configuration could therefore cause a malicious artifact to be installed. The project uses the correct package name, so there is no evidence of deliberate typosquatting or dependency confusion in the audited files. The risk arises from mutable, unverified dependency resolution rather than a confirmed malicious dependency. ### Attack Path 1. A user follows the documented `pip install numpy` instruction. 2. Pip queries the configured package index or mirror and resolves a mutable package version. 3. An attacker has compromised the relevant publisher account, index, mirror, or package-resolution configuration. 4. Pip downloads a malicious or tampered distribution because no exact version and cryptographic hash are enforced. 5. Installation-related code executes with the privileges of the user running pip. 6. The installed dependency can subsequently execute again when `scripts/anoma ...[truncated 604 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/rule_extractor.py:27
Finding

Unescaped User-Controlled Content in Generated Markdown Reports

Content
View full analysis
1 else 0.6 } extracted.append(rule) ``` User-controlled JSON field names and values are also incorporated into rule conditions: ```python if len(stats['types']) == 1: extracted.append({ 'type': 'field_type', 'condition': f"{field} must be of type {stats['types'].pop()}", 'confidence': 1.0 }) if len(stats['values']) > 0 and len(stats['values']) < 10: extracted.append({ 'type': 'field_enum', 'condition': f"{field} must be one of: {', '.join(map(str, stats['values']))}", 'confidence': 0.9 }) ``` Those conditions are interpolated directly into a Markdown table: ```python def export_markdown(self) -> str: """Export rules as markdown document""" md = "# Extracted Business Rules\n\n" md += f"Generated at: {datetime.now().strftime('%Y-%m-%d %H:%M:%S')}\n\n" md += "| Rule Type | Condition | Confidence |\n" md += "|-----------|-----------|------------|\n" for rule in self.get_rules(): md += f"| {rule['type']} | {rule['condition']} | {rule['confidence']:.1f} |\n" return md ``` ### Technical Analysis The extractor treats log contents, JSON property names, and JSON scalar values as untrusted input, but it does not escape them for the Markdown table context. Characters and constructs such as `|`, backslashes, line breaks, links, images, and renderer-dependent inline HTML ...[truncated 1834 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/rule_extraction_standards.md (reported line 28)May include surrounding context.

md
Each extracted rule must include:
1. **Rule ID:** Unique identifier (RULE-XXXX)
2. **Rule Type:** Business/Technical/Implicit
3. **Condition:** Clear statement of the rule condition
4. **Source:** Data source where the rule was observed
5. **Confidence:** 0.0-1.0 score indicating reliability
6. **Examples:** 1-2 concrete examples of the rule in action

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README encourages analysis of transaction logs, API responses, and business data streams but provides no warning about secrets, personal data, or regulated data that may appear in those inputs. Because this skill is explicitly designed to process operational data in real time, the lack of guidance on redaction, minimization, and secure handling materially increases the risk of exposing sensitive information during use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, generic terms like '日志分析', '异常检测', and '规则提取' that could match many unrelated user requests and cause unintended activation of this skill. In an agent environment, overbroad activation can route sensitive logs or data into tooling the user did not explicitly request, increasing the chance of unnecessary data exposure or incorrect behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises handling logs, streams, and database-query inputs and includes example scripts that read local files, but it declares no explicit tool scope or permissions boundary. That can cause the platform to invoke the skill in contexts where file-reading behavior is possible without clear least-privilege constraints or user awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description uses ambiguous activation conditions such as real-time data rule extraction and log/stream analysis without defining clear limits. This can make routing overly permissive and cause the skill to engage for generic analysis requests that were not intended to grant access to potentially sensitive operational data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly ingests log files, API streams, and database queries but provides no warning about secrets, personal data, production telemetry, or operational load. Users may submit sensitive or live-system data without understanding the privacy and system-impact risks, increasing the chance of data exposure or unsafe analysis of production sources.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
### Step 3: Result Generation
1. Generate structured rule documentation in markdown format
2. Create test case suggestions based on extracted patterns
3. Produce anomaly reports with actionable insights

### Step 4: Output Delivery

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad terms like 'online analysis', 'rule extraction', and 'anomaly detection' that commonly appear in ordinary requests. Over-broad activation increases the chance the skill runs unintentionally on unrelated prompts, potentially exposing sensitive logs or causing unintended analysis/export actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written entirely in Chinese, which indicates a language-specific skill presentation without offering any user language choice or documenting a justified locale restriction. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Nearly all user-facing documentation, feature descriptions, and trigger instructions are presented only in Chinese, with no indication that users may choose another language. This can constitute a language-policy issue when a skill implicitly requires a specific language without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This is a code file, so SQP-2 applies to safety-relevant file operations. At L097 the script opens whatever path is passed on the command line, but there is no comment, docstring, or user-facing message disclosing that the skill will read local files; the existing usage line only shows syntax, not a warning about data access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.