T09 · Insecure Skill Coding Practices
- Location
run.mjs:52- Finding
OS Command Injection Through User-Controlled Questions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent trust-and-memory purpose, but it needs Review because normal use can expose user/model text to shell command execution and broadly persists sensitive content.
Review this skill carefully before installing. It should only be run in an isolated, low-privilege environment with trusted local or allowlisted HTTPS model endpoints, and it should not process secrets or confidential prompts until the shell-command construction, fail-open safety parsing, and raw persistent-memory behavior are fixed.
run.mjs:52OS Command Injection Through User-Controlled Questions
trust/mia-trust.mjs:334Persistent Agent Memory Poisoning Through Raw Queries and Model Output
trust/mia-trust.mjs:21Configurable LLM Endpoints Can Receive Sensitive Content and API Credentials Without Transport Enforcement
trust/mia-trust.mjs:476Safety Decisions Fail Open When LLM Responses Are Missing or Malformed
run.mjs:139Sensitive Questions, Plans, and Evaluation Results Are Persisted in Plaintext Without Data Minimization
Referenced artifact was not completely inspected
node trust/mia-trust.mjs guard_blocked '{"query":"你的问题"}'
Referenced artifact was not completely inspected
node trust/mia-trust.mjs guard_blocked '{"query":"你的问题"}'
Referenced artifact was not completely inspected
node memory/mia-memory.mjs search "之前是怎么做的"
Referenced artifact was not completely inspected
node memory/mia-memory.mjs search "之前是怎么做的"
Referenced artifact was not completely inspected
node memory/mia-memory.mjs search "之前是怎么做的"
The guide explicitly instructs storing question, plan, execution, and final_answer in local memory files, which can include sensitive prompts, secrets, personal data, or operational details. Because there is no user-facing notice, consent flow, retention policy, or minimization guidance, operators may persist sensitive content unintentionally, creating confidentiality and compliance risk.
The environment variable section configures remote API endpoints for planner and trust components but does not warn that user queries, plans, and related content may be transmitted to third-party services. This can expose sensitive user data to external processors and create privacy, data residency, and vendor trust concerns, especially in a memory-enabled pipeline.
The skill advertises installation and execution of Node-based components that use environment variables and an external planner API, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and governance gap: users and hosting agents cannot reliably constrain or review the skill's access to network and sensitive environment-backed capabilities before use.
The documentation instructs users to set an API key and a remote chat completions endpoint, but does not warn that user queries and possibly memory contents may be transmitted to a third-party service. This can lead to accidental disclosure of sensitive prompts, stored memories, or credentials through normal operation, especially in a trust/memory pipeline that implies persistent data handling.
The script persistently stores user-supplied memory records to disk and can later replace them, but there is no consent prompt, disclosure, retention control, or indication that potentially sensitive prompts and execution traces will be written to a local file. In a memory pipeline for an assistant, stored questions, steps, and execution metadata may contain personal, proprietary, or security-relevant data, so silent persistence increases privacy and data-handling risk.
The documented responsibility in the file is '生成 Search Plan,支持参考历史轨迹优化', and the code builds prompts then POSTs them to chat-completions APIs. That behavior is materially different from the manifest's description of a '信任守门+记忆进化 pipeline', indicating the implemented functionality is planning/orchestration rather than trust enforcement or memory evolution.
The code sends user questions and historical plans to a configurable endpoint, including third-party remote services in API mode, while the skill is described as a trust/memory pipeline. This creates a real data exposure risk because potentially sensitive prompt content and memory artifacts can leave the local trust boundary without clear disclosure or restriction.
The file contains explicit logic to send prompt data to a third-party endpoint at api.openai.com when API mode is enabled. In the context of a trust/memory skill, this is security-relevant because user questions and historical plan data may be externally transmitted, expanding the attack surface and privacy exposure beyond what the skill description suggests.
if (CUSTOM_URL) {
PLANNER_URL = CUSTOM_URL;
} else if (MODE === 'api') {
PLANNER_URL = 'https://api.openai.com/v1/chat/completions';
} else {
PLANNER_URL = 'http://localhost:8000/v1/chat/completions';
}
The embedded natural-language prompts are entirely in Chinese and direct the model's behavior accordingly, which effectively constrains output language. There is no indication that the user can choose another language or that the locale restriction is required for a region-specific purpose.
Question content and reference plans are transmitted to an external API endpoint without any user-facing disclosure, opt-in, or sensitivity checks. Because historical plans may contain derived context, internal procedures, or sensitive memory content, this can leak data outside the expected environment and violate user trust or policy boundaries.
Natural-language strings in the file, including the top-level description and all user-facing status/output messages, are written in Chinese only. This imposes a specific language on users without any documented language selection, which matches the language/locale policy violation category.
The manifest description focuses on a 'trust gatekeeper + memory evolution' pipeline, but this file prepares external planner URL/model/API-key configuration via environment variables. That implies integration with external model or network-backed planning infrastructure, which is not evident from the stated purpose and exceeds what a purely local trust/memory pipeline would obviously require.
The script persistently stores the full user question, generated plan, and evaluation output in a local memory file without minimization, redaction, retention controls, or consent. This can capture sensitive prompts, secrets, internal plans, or safety-review artifacts and create a durable privacy and data-exposure risk if the file is accessed by other users, tools, or later pipeline stages.
The code writes sensitive user input and model-derived output to persistent storage with no user warning or opt-in at the point of use. In a trust/safety pipeline, this is especially risky because users may submit confidential data expecting analysis, not long-term retention, and the saved records may later be exposed or reused unexpectedly.
The skill allows environment variables to fully control the paths used for experience and memory files, and later writes to those paths with writeFileSync/appendFileSync. In a shared or untrusted runtime, an attacker who can influence environment configuration could redirect writes to arbitrary files, causing file corruption, overwriting sensitive application data, or poisoning another component's state.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
function buildUrl() {
if (CUSTOM_URL) return CUSTOM_URL;
if (MODE === 'api') return 'https://api.openai.com/v1/chat/completions';
return 'http://localhost:8000/v1/chat/completions';
}
Multiple embedded prompts instruct the model entirely in Chinese and require specific Chinese verdict phrasing, and the CLI usage text is also Chinese-only. This imposes a language/locale constraint in natural-language behavior without offering user opt-in or documenting that the skill is intentionally region-specific.
appendExperience persists raw user queries and plan content into local experience and memory files without consent, minimization, or redaction. Because this component specifically handles security reviews, the stored text may include sensitive prompts, secrets, attack payloads, or proprietary plans, creating a durable privacy and data-exposure risk.
The skill creates a long-term retention path for user-provided queries and plans by writing them to experience and memory stores. Persistent storage of natural-language inputs materially increases the blast radius of any later file disclosure, debugging leak, backup exposure, or unauthorized local access.
callLLM sends supplied prompts, queries, plans, memories, and historical experience to a configurable remote endpoint, including OpenAI when MODE=api, without explicit notice or consent. This can exfiltrate sensitive user content or locally stored memory to third-party services or attacker-controlled URLs via CUSTOM_URL.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access