Back to skill

Security audit

智能测试报告

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent test-report generator, but its sample exporters can create unsafe HTML and Excel reports that may run injected or third-party code when opened.

Install only if you are comfortable reviewing or modifying the generated report code before use. Treat test logs and test names as untrusted input, escape all HTML/JavaScript output, neutralize spreadsheet formulas, pin or bundle chart dependencies, and choose explicit output filenames in a workspace report directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:260
Finding

Stored HTML and JavaScript Injection in Generated Reports

Content
View full analysis
{i+1}{c["name"]}{c.get("module","-")}{c.get("error_type","-")}{c.get("error_message","-")}{c.get("severity","-")}' for i, c in enumerate(data.get('failed_cases', [])))} ``` ```python {''.join(f'{i+1}{c["name"]}{c["time"]:.2f}{"✅" if c["status"]=="passed" else "❌"}' for i, c in enumerate(data.get('slowest_cases', [])[:10]))} ``` ```python {''.join(f'{p["pattern"]}{p["count"]}{p["percentage"]:.1f}%{p["suggestion"]}' for p in data.get('failure_patterns', []))} ``` ```python {''.join(f'
  • {s}
  • ' for s in data.get('suggestions', []))} ``` ```python

    {data.get('release_verdict','待定')}

    {data.get('release_note','')}

    ``` ### Technical Analysis The HTML report generator directly interpolates test names, module names, error messages, failure-pattern descriptions, suggestions, and release information into HTML markup. No HTML escaping, contextual output encoding, sanitization, or validation is applied. Test reports and log-derived values must be considered untrusted because they may contain attacker-controlled test names, assertion messages, parameter values, service responses, or exception text. A value such as: ```html ``` would be inserted into the generated report as active markup rather than displayed as text. The `release_color` value is also placed into a CSS declaration without validation. Although this sink is less directly exploitable in modern browsers than raw HTML insertion, it violates contextual encoding requirements and ...[truncated 1687 chars]
    Remediation
    View remediation
    "> ``` The generated report must display these values as inert text. ]]>

    T09 · Insecure Skill Coding Practices

    Warning
    Location
    SKILL.md:412
    Finding

    Spreadsheet Formula Injection in Excel Report Export

    Content
    View full analysis
    Remediation
    View remediation

    T08 · Insecure Dependencies

    Warning
    Location
    SKILL.md:192
    Finding

    Unpinned Third-Party JavaScript Loaded at Report Viewing Time

    Content
    View full analysis
    ``` ### Technical Analysis Every generated HTML report loads and executes Chart.js from a third-party CDN when the report is viewed. The dependency URL does not specify an exact package version, and the script element does not include a Subresource Integrity hash. Consequently, the effective JavaScript executed by the report can change after the skill has been audited. A compromised package release, CDN account, package registry, delivery path, or unexpectedly incompatible future version could cause generated reports to execute code that was not present during review. TLS protects the transport connection but does not guarantee that the CDN-hosted package remains immutable or that the delivered file is the specific artifact approved by the project. ### Attack Path 1. The skill generates an HTML report containing the unversioned CDN script reference. 2. A user opens the report while connected to the network. 3. The browser requests the current Chart.js package selected by the mutable URL. 4. The CDN or package supply chain returns changed or compromised JavaScript. 5. The browser executes that code as part of the report. 6. The injected dependency can access report content and perform actions available to the report's browser context. ### Impact Assessment A compromised dependency could: - Read test results and other data rendered in the report. - Alter or falsify the displayed report. - Make arbitrary network requests from the browser. - Present phishing content or redirect the viewer. - Exploit any additional browser or hosting-origin privileges available to the report. The code executes with browser-page privileges rather than direct operating-system privileges. The repor ...[truncated 81 chars]
    Remediation
    View remediation
    /dist/chart.umd.min.js" integrity="sha384-" crossorigin="anonymous"> ``` 4. Verify the integrity hash against the reviewed artifact rather than copying it from an untrusted source. 5. Add a Content Security Policy that permits scripts only from explicitly approved locations and avoids inline JavaScript. 6. Establish a dependency update process that includes security review, compatibility testing, and integrity-hash regeneration. 7. Provide an offline-safe fallback or embed chart rendering assets directly in the report package. ]]>
    Vulnerability Patterns
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    Findings (3)

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    该 markdown 文件的 description 将“生成测试报告、分析测试结果、统计测试通过率、生成质量看板、导出测试数据、测试趋势分析”等宽泛需求以及“测试分析”“质量报告”等泛化表达都作为适用场景,但没有提供明确的边界、限定条件或反例。这类触发描述容易与一般性的分析/报表请求重叠,增加意外触发该技能的风险。

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    88% confidence
    Finding

    The skill explicitly supports exporting HTML, PDF, and Excel reports and includes code that writes output files, but it does not require user confirmation, disclose that files may be created/overwritten, or define safe output-path handling. In an agent environment, this can lead to unintended filesystem writes, overwriting user files, or generating active content such as HTML without adequate warning or constraints.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    文件中的名称、描述和主要说明均以中文固定表述,且未说明可根据用户语言偏好切换输出语言。按照该规则,若技能默认强制特定语言而没有用户选择或明确、合理的地域性限制,应视为自然语言策略违规。

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.