Back to skill

Security audit

一键生成项目

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real project generator, but it creates and starts applications with unsafe authentication, unprotected data-changing APIs, plaintext credentials, and automatic database reset behavior.

Install only if you are comfortable reviewing and hardening the generated application before use. Run it in an isolated development environment, point it only at disposable local databases, avoid real credentials, rotate any credentials written into generated files, and do not expose the generated backend until authentication, authorization, token handling, destructive SQL, dependency locking, and shell launch behavior are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/optimized-start-win.py:620
Finding

Universal Password Authentication Bypass and Forgeable Access Tokens

Content
View full analysis
login(@RequestBody Map loginData) { String username = loginData.get("username"); String password = loginData.get("password"); Map result = new HashMap<>(); LambdaQueryWrapper wrapper = new LambdaQueryWrapper<>(); wrapper.eq(SysUser::getUsername, username); SysUser user = sysUserService.getOne(wrapper); if (user == null || (!password.equals("123456") && !password.equals(user.getPassword()))) { result.put("code", 401); result.put("message", "用户名或密码错误"); return result; } String token = "token-" + user.getId() + "-" + System.currentTimeMillis(); result.put("code", 200); result.put("message", "登录成功"); Map data = new HashMap<>(); data.put("token", token); data.put("username", user.getUsername()); data.put("realName", user.getRealName()); result.put("data", data); return result; } @GetMapping("/info") public Map info(@RequestHeader("Authorization") String authHeader) { Map result = new HashMap<>(); if (authHeader == null || !authHeader.startsWith("Bearer ")) { result.put("code", 401); result.put("message", "未登录"); return result; } result.put("code", 200); result.put("message", "success"); Map data = new HashMap<>(); data.put("roles", new String[]{"admin"}); data.put("name", "管理员"); result.put("data", data); return result; } ``` ### Technical Analysis The generated login controller treats the literal password `123456` as valid for every existing user. The password comparison also directly compares supplied plaintext with the stored ...[truncated 1439 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/optimized-start-win.py:537
Finding

Generated CRUD Endpoints Lack Server-Side Authentication and Authorization

Content
View full analysis
list( @RequestParam(defaultValue = "1") int current, @RequestParam(defaultValue = "10") int size, @RequestParam(required = false) String keyword) { Page<{class_name}> page = new Page<>(current, size); LambdaQueryWrapper<{class_name}> wrapper = new LambdaQueryWrapper<>(); if (keyword != null && !keyword.isEmpty()) { // Keyword query conditions } Page<{class_name}> result = {var_name}Service.page(page, wrapper); Map map = new HashMap<>(); map.put("records", result.getRecords()); map.put("total", result.getTotal()); return map; } @GetMapping("/{id}") public {class_name} getById(@PathVariable Long id) { return {var_name}Service.getById(id); } @PostMapping public boolean save(@RequestBody {class_name} {var_name}) { return {var_name}Service.save({var_name}); } @PutMapping("/{id}") public boolean update(@PathVariable Long id, @RequestBody {class_name} {var_name}) { {var_name}.setId(id); return {var_name}Service.updateById({var_name}); } @DeleteMapping("/{id}") public boolean delete(@PathVariable Long id) { return {var_name}Service.removeById(id); } } ``` ### Technical Analysis The generated controllers expose list, read, create, update, and delete operations without Spring Security, authentication middleware, authorization annotations, or explicit ownership checks. This applies to generated R ...[truncated 1153 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/optimized-start.py:382
Finding

Configuration-Derived Values Are Executed Through a Command Shell

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/optimized-start-win.py:946
Finding

Database and Redis Credentials Are Written into Generated Source Files

Content
View full analysis
Remediation
View remediation

other

Error
Location
scripts/optimized-start-win.py:2172
Finding

Automatic Database Initialization Drops Existing Tables Without Confirmation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/optimized-start-win.py:1179
Finding

Non-Reproducible Dependency Installation Uses Version Ranges and an Alternate Registry

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (35)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The generated AuthController contains a built-in authentication bypass: any existing user can authenticate with the hardcoded password "123456", and token generation is unauthenticated beyond that weak check. For a scaffolding skill, embedding a universal access mechanism is unjustified and directly produces insecure applications by default.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill description promises a far broader set of capabilities than the implementation reportedly provides, including full code generation, CRUD scaffolding, Swagger, and Redis support. Security-wise, this is dangerous because users may trust the skill with sensitive configuration, credentials, database access, and shell execution under false assumptions about what it actually does.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
GET    /api/users/{id}     # 根据ID查询(查看详情)
POST   /api/users          # 新增
PUT    /api/users/{id}     # 修改
DELETE /api/users/{id}     # 删除(物理删除)

GET    /api/roles          # 列表查询
GET    /api/roles/{id}     # 根据ID查询

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

md
GET    /api/roles/{id}     # 根据ID查询
POST   /api/roles          # 新增
PUT    /api/roles/{id}     # 修改
DELETE /api/roles/{id}     # 删除

GET    /api/permissions          # 列表查询
GET    /api/permissions/{id}     # 根据ID查询

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
GET    /api/permissions/{id}     # 根据ID查询
POST   /api/permissions          # 新增
PUT    /api/permissions/{id}     # 修改
DELETE /api/permissions/{id}     # 删除

POST   /api/auth/login    # 登录
GET    /api/auth/info     # 获取当前用户信息

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 254)May include surrounding context.

GET /api/{entities}/{id} # 根据ID查询 POST /api/{entities} # 新增 PUT /api/{entities}/{id} # 修改 DELETE /api/{entities}/{id} # 删除

text

---

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Despite claiming RBAC support, the generated authorization logic does not validate roles or permissions and returns a fixed admin role for any bearer token in /auth/info. This means UI and downstream logic will treat any token holder as an administrator, defeating authorization boundaries and misleading users into deploying non-functional RBAC protection.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The generated login flow advertises a default admin credential, while the authentication backend accepts password "123456" for any existing username. This creates a universal weak-password bypass for all provisioned accounts rather than just an initial bootstrap account, making unauthorized access trivial once a username is known.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The initialization flow executes SQL that drops and recreates core tables, and it does so automatically without explicit destructive-action confirmation. In a one-click launcher, this can wipe an existing database or overwrite important data if pointed at the wrong instance, making the context more dangerous because automation reduces opportunities for user review.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

This is the same risky execution pattern as the subprocess finding: shell=True is used with a constructed command for Maven. Tool-path and environment influence can be abused to run unintended commands, and the one-click automation makes it easier to trigger without scrutiny.

Content

Scanner excerpt · scripts/optimized-start-win.py (reported line 2371)May include surrounding context.

python
return False

        try:
            result = subprocess.run(f'"{mvn_path}" clean package -DskipTests -q',
                                   cwd=backend_dir, shell=True, capture_output=True, timeout=300)
            if result.returncode == 0:
                print(f"{Colors.GREEN}[SUCCESS] 后端构建成功{Colors.RESET}")

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The npm install invocation also suffers from tool-parameter abuse because it delegates command parsing to the shell. Since npm install executes lifecycle scripts from dependencies, combining shell-based invocation with automatic dependency installation magnifies the chance of unwanted code execution on the host.

Content

Scanner excerpt · scripts/optimized-start-win.py (reported line 2397)May include surrounding context.

python
return False

        try:
            result = subprocess.run(f'"{npm_path}" install',
                                   cwd=frontend_dir, shell=True, capture_output=True, timeout=180)
            if result.returncode == 0:
                print(f"{Colors.GREEN}[SUCCESS] 前端依赖安装成功{Colors.RESET}")

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
86% confidence
Finding

The script launches a generated batch file via os.system using a shell command string. Although the batch path is quoted, it is derived from configuration-controlled project paths and still relies on cmd.exe parsing, which increases risk of command execution quirks or path-based injection on Windows. In a code generator that writes and immediately launches scripts, shell execution expands the attack surface unnecessarily.

Content

Scanner excerpt · scripts/optimized-start-win.py (reported line 2433)May include surrounding context.

python
'''
        bat_path = backend_dir / 'start-backend.bat'
        bat_path.write_text(bat_content, encoding='gbk')
        os.system(f'start "" "{bat_path}"')
        print(f"{Colors.GREEN}[SUCCESS] 后端服务已在新窗口启动{Colors.RESET}")
        return True

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
86% confidence
Finding

This call starts a generated frontend batch file through the Windows shell using os.system. Because the script content and path are built from config-derived values, shell invocation can mis-handle crafted paths and needlessly enables command interpretation beyond simply starting the process.

Content

Scanner excerpt · scripts/optimized-start-win.py (reported line 2457)May include surrounding context.

python
'''
        bat_path = frontend_dir / 'start-frontend.bat'
        bat_path.write_text(bat_content, encoding='gbk')
        os.system(f'start "" "{bat_path}"')
        print(f"{Colors.GREEN}[SUCCESS] 前端服务已在新窗口启动{Colors.RESET}")

        time.sleep(5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script automatically executes an SQL initialization file against the configured database after only a connectivity test, with no confirmation, dry run, environment guardrails, or destructive-action warning. Because the description explicitly supports remote database execution, this can modify or destroy non-local databases if the config is wrong or maliciously supplied.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a strong true positive for tool-parameter abuse because a shell command is assembled from runtime values and executed with shell=True. Any attacker influence over configuration values, path names, or discovered JAR file names can turn a benign start action into arbitrary OS command execution.

Content

Scanner excerpt · scripts/optimized-start.py (reported line 467)May include surrounding context.

python
try:
            # 启动后端服务
            cmd = f"start /B java -jar {jar_file} --server.port={self.backend_port}"
            subprocess.run(cmd, shell=True, cwd=backend_dir)
            
            print(f"{Colors.GREEN}✅ 后端服务已启动 (端口: {self.backend_port}){Colors.RESET}")
            return True

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This frontend startup path has the same issue: shell=True plus interpolated runtime data creates a command-execution surface. In a config-driven automation script, that surface is especially risky because users may run it on trust, giving attacker-supplied parameters a straightforward route to local execution.

Content

Scanner excerpt · scripts/optimized-start.py (reported line 485)May include surrounding context.

python
try:
            # 启动前端开发服务器
            cmd = f"start /B npm run dev -- --port {self.frontend_port}"
            subprocess.run(cmd, shell=True, cwd=frontend_dir)
            
            print(f"{Colors.GREEN}✅ 前端服务已启动 (端口: {self.frontend_port}){Colors.RESET}")
            return True

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises behavior that clearly requires powerful capabilities such as file writes, shell execution, network access, and browser/process launching, but it declares no explicit tool scope or permission boundaries. In an agent setting, missing scope declarations increases the chance that the skill is invoked with overly broad authority and that users are not warned about the real execution surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly documents default credentials such as admin/123456 and presents them as part of the generated system without a prominent warning to change them immediately. Shipping or encouraging predictable credentials creates a straightforward unauthorized-access path if the generated application is exposed beyond a local development environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises physical deletion as a feature but does not include an explicit safety warning about irreversible data loss, backup expectations, or environment restrictions. In a one-click automation context that also initializes and starts services, destructive deletion semantics materially increase the risk of accidental or unauthorized data destruction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script hardcodes user-facing text, generated page labels, prompts, and messages in Chinese throughout the generated application and command-line output. There is no indication that users can choose another language or that the locale restriction is intentionally limited to a China-specific deployment context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The script creates directories and writes numerous source files, configuration files, SQL files, and .bat startup scripts across the target project tree. Although this behavior is part of the tool's purpose, the file itself lacks a clear docstring or user-facing warning describing the extent of these filesystem modifications before execution begins.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

The backend build command is executed with subprocess.run(..., shell=True) and interpolates a tool path string into the command line. Any compromise of tool-path resolution or unexpected characters in the resolved path can lead to shell injection or execution of an unintended program. In a project launcher that automatically builds generated code, this creates a meaningful local code-execution risk.

Content

Scanner excerpt · scripts/optimized-start-win.py (reported line 2371)May include surrounding context.

python
return False

        try:
            result = subprocess.run(f'"{mvn_path}" clean package -DskipTests -q',
                                   cwd=backend_dir, shell=True, capture_output=True, timeout=300)
            if result.returncode == 0:
                print(f"{Colors.GREEN}[SUCCESS] 后端构建成功{Colors.RESET}")

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

The frontend dependency installation uses subprocess.run with shell=True and a command string containing the npm path. If the resolved executable path is manipulated, or if the environment/path lookup is attacker-controlled, the shell may execute unintended commands. Because the script automatically installs dependencies, successful abuse can directly execute attacker-chosen code on the developer machine.

Content

Scanner excerpt · scripts/optimized-start-win.py (reported line 2397)May include surrounding context.

python
return False

        try:
            result = subprocess.run(f'"{npm_path}" install',
                                   cwd=frontend_dir, shell=True, capture_output=True, timeout=180)
            if result.returncode == 0:
                print(f"{Colors.GREEN}[SUCCESS] 前端依赖安装成功{Colors.RESET}")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

User-facing docstrings and console messages are written exclusively in Chinese, including the usage output. This imposes a specific language on all users without any opt-in or documented locale constraint, which matches the policy's language/locale violation category.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/optimized-start.py (reported line 269)May include surrounding context.

python
all_passed = True
        for name, cmd, check_str in checks:
            try:
                result = subprocess.run(
                    cmd.split(), 
                    capture_output=True, 
                    text=True,

Static analysis

No suspicious patterns detected.