Back to skill

Security audit

Code Starter - 中学生编程启蒙智能体

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese programming tutor, but its beginner sample for bulk file renaming can change many local files without enough safety checks or recovery guidance.

Review before installing if learners may run the included scripts. Use the batch rename example only in a disposable test folder with backed-up sample files, and avoid real personal, school, or work directories until the script validates filenames, checks for collisions, and shows full destination paths.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/batch_rename.py:44
Finding

Unrestricted Rename Destinations Permit Directory Escape and File Overwrites

Content
View full analysis

Vulnerability Details

File Location: scripts/batch_rename.py, lines 44-65 and 95-110
Vulnerability Type: Unvalidated filesystem destination and unsafe file replacement
Risk Level: Medium

Vulnerable Code

python
new_name = f"{prefix}{name}{suffix}{ext}"

print(f"{filename:30s} → {new_name}")
rename_list.append((filename, new_name))

success = 0
for old_name, new_name in rename_list:
    try:
        old_path = os.path.join(folder_path, old_name)
        new_path = os.path.join(folder_path, new_name)
        os.rename(old_path, new_path)
        success += 1
    except Exception as e:
        print(f"Rename of {old_name} failed: {e}")

The numbering mode performs the same unsafe destination operation:

python
new_name = f"{i:03d}_{name}{ext}"
rename_list.append((filename, new_name))

for old_name, new_name in rename_list:
    old_path = os.path.join(folder_path, old_name)
    new_path = os.path.join(folder_path, new_name)
    os.rename(old_path, new_path)

Technical Analysis

The prefix and suffix used to construct new_name come directly from interactive input. The program does not require the resulting value to remain a single filename component. In particular, a prefix can contain path separators and parent-directory components such as ../.

os.path.join(folder_path, new_name) does not enforce containment within folder_path. For example, a prefix of ../target/ can produce a destination equivalent to:

text
selected-folder/../target/original-file.txt

The normalized destination is outside the directory selected for batch renaming.

The program also does not check whether:

  • A destination already exists.
  • Two source files resolve to the same destination.
  • A destination conflicts with another source in the rename batch.
  • The resolved destination remains inside the selected directory.
  • A failure leaves the operation only part ...[truncated 2317 chars]
Remediation
View remediation

Remediation Suggestions

  1. Restrict prefix and suffix values to filename-safe text. Reject path separators, parent-directory components, NUL bytes, and platform-specific separators:

    python
    def validate_affix(value):
        if "\x00" in value or value in {".", ".."}:
            raise ValueError("Invalid filename component")
        if any(separator and separator in value
               for separator in (os.sep, os.altsep)):
            raise ValueError("Path separators are not allowed")
    
  2. Resolve and enforce destination containment. Verify that every destination has the selected directory as its direct parent:

    python
    base = os.path.realpath(folder_path)
    destination = os.path.realpath(os.path.join(base, new_name))
    
    if os.path.dirname(destination) != base:
        raise ValueError("Destination escapes the selected directory")
    
  3. Reject existing destinations. Before changing any files, check every planned destination with os.path.lexists(). Abort the entire operation if a destination already exists and is not the same source path.

  4. Detect duplicate and cross-operation destinations. Normalize all destinations and verify that they are unique. Also detect cases where one generated destination is another source file in the same batch.

  5. Use a two-phase rename strategy. First rename each source to a unique temporary name inside the same directory. After every first-phase operation succeeds, rename the temporary files to their final validated destinations. If either phase fails, attempt rollback.

  6. Validate the selected path as a directory. Replace the existence-only check with:

    python
    if not os.path.isdir(folder_path):
        raise ValueError("The selected path must be a directory")
    
  7. Display normalized absolute destinations in the preview. This makes directory escape or unexpected path resolut ...[truncated 241 chars]

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个用于编程启蒙和互动教学的智能体,核心能力应是教学、解释概念、引导学习。实际代码并未实现任何教学流程、课程引导、游戏化学习或编程辅导逻辑,而是一个直接操作本地文件系统的实用脚本。虽然代码注释提到“适合教学 - 展示文件操作和自动化”,这只能说明它可作为教学示例,不等于实现了声明中的教学智能体能力。其主要行为和资源访问都与声明目的明显不一致,因此存在显著描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的核心是“中学生编程启蒙智能体”,重点应在教授编程、引导入门、围绕项目开展教学,并具备特定教学方法。实际代码只是一个基于关键词匹配的简单聊天机器人,能对问候、年龄、爱好、情绪和少量‘编程/代码/python’词汇做泛化回复,其中编程相关回复也仅是闲聊式一句话,并不承担教学功能。因此其主要目的与描述存在实质性偏差。代码没有明显越权访问资源或额外敏感能力,但其核心行为与声明不符,应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions consistently prescribe Chinese-language behavior for the skill and do not indicate that the user may choose another language. Under SQP-3, forcing a specific language without user opt-in is a policy concern unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill recommends '批量重命名文件' as a starter automation project for minors/beginners without any warning about filesystem side effects, scoping, backups, or safe practice directories. In a novice-focused context, users may run destructive rename scripts on real folders and accidentally lose organization, overwrite expectations, or disrupt other software workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This is a markdown file, so SQP-2 applies to omissions in user-facing safety disclosures. The project list explicitly includes file operations and personal-data-oriented apps, but does not mention privacy, local data storage, or the need to avoid saving sensitive information insecurely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Batch renaming is a potentially destructive operation because it can rename large numbers of files and be difficult to reverse if done incorrectly. In this markdown description, there is no caution about accidental bulk changes, backups, or testing on a sample directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all instructional content exclusively in Chinese, and there is no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-speaking audience. The policy requires avoiding forced language or locale constraints unless user choice or clear justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language UI text exclusively in Chinese, starting with the module description and continuing throughout the interactive prompts. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring, prompts, and usage instructions are all written in Chinese and the chatbot explicitly instructs users to interact using Chinese exit terms such as '再见'. There is no indication that the skill supports user language choice or that the Chinese-only behavior is an intentional region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The document forces a specific language throughout without any opt-in, fallback, or note that the content is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

For markdown files, SQP-2 covers missing warnings about behaviors affecting privacy or system integrity. The project explicitly teaches requests and HTML parsing, indicating outbound network activity, but provides no disclosure that data will be fetched from external sites or that users should respect site rules and avoid sending sensitive data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire guide is written as an instruction set in Chinese and is framed as a general programming-concept teaching guide, but it does not indicate that Chinese is optional or limited to a China-specific audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents the game title, docstrings, and all user-facing prompts entirely in Chinese, with no option for the user to select another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.