Back to skill

Security audit

步步为营

Security checks for vulnerabilities and agentic risk

Overview

This DevOps skill matches its stated purpose, but it exposes high-impact build, dependency, deployment, rollback, and health-check actions without enough scoping or warnings.

Install only if you are comfortable reviewing DevOps commands before execution. Treat the scripts as potentially mutating: run them in a disposable or least-privileged environment, verify the target environment before deployment or rollback, avoid running npm install or npx on untrusted projects, and restrict health checks to known safe hosts.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/checklist.sh:60
Finding

Fix-Scope Verification Produces False Success Results

Content
View full analysis
/dev/null 2>&1; then local changed_files=$(git diff --name-only HEAD) local file_count=$(echo "$changed_files" | grep -c "$target_file" || true) if [ "$file_count" -gt 1 ]; then log_warn "检测到多个文件被修改,可能影响其他功能" echo "修改的文件列表:" echo "$changed_files" else log_success "修正范围正常,仅修改了目标文件" fi fi ``` ### Technical Analysis The function is presented as a security control that verifies only the requested target file was modified. However, `file_count` counts changed paths matching `target_file`; it does not count all changed files. If the target file and several unrelated files are modified, the target will normally appear once. The condition evaluates to false and the function reports that only the target file was changed. Additional weaknesses include: - Untracked files are not included by `git diff --name-only HEAD`. - `grep` interprets the target path as a regular expression. - Partial path matches can produce incorrect results. - The advertised baseline-hash argument is accepted but never used. - The function does not fail when unrelated modifications are found. This creates a spoofed safety result: the output appears to confirm a meaningful security check even though the check does not enforce its stated property. ### Attack Path 1. An attacker or compromised automation modifies the intended target file. 2. The attacker also modifies unrelated tracked files or creates malicious untracked files. 3. The user or agent runs: ```bash ./scripts/checklist.sh verify-fix path/to/target ``` 4. `git diff --name-only HEAD` returns the target and unrelated changed files. 5. `grep -c "$target_file"` normally returns `1`. 6. The `file_count > 1` condition is false. 7. The script pr ...[truncated 767 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/checklist.sh:83
Finding

Unpinned Package Retrieval and Dependency Lifecycle-Script Execution

Content
View full analysis
/dev/null && log_success "TypeScript 语法正确" || log_warn "TypeScript 检查跳过" fi ``` ```bash # 依赖检查 log_info "检查依赖..." if [ -f "package.json" ]; then npm install 2>&1 | tail -5 fi ``` ### Technical Analysis The TypeScript verification invokes `npx tsc` without requiring a trusted, locally installed, pinned compiler. Depending on the environment and npm configuration, `npx` can retrieve a package from the configured registry and execute it. This makes the effective executable dependent on mutable external package resolution rather than an audited local binary. The development check also runs `npm install` in the target project. This operation can: - Resolve packages without enforcing a frozen lockfile. - Download mutable third-party content. - Execute dependency lifecycle scripts such as `preinstall`, `install`, and `postinstall`. - Execute lifecycle scripts defined by an attacker-controlled project. - Modify the dependency tree and lockfile during what is presented as a validation operation. Consequently, merely checking an untrusted project can result in arbitrary code execution under the account running the Skill. ### Attack Path #### Project Lifecycle-Script Path 1. An attacker supplies or modifies a project containing a `package.json`. 2. The manifest includes an attacker-controlled dependency or a malicious lifecycle script. 3. A user or agent invokes: ```bash ./scripts/checklist.sh dev-check ``` 4. The script executes `npm install`. 5. npm downloads dependencies and runs applicable lifecycle scripts. 6. The malicious script executes with the permissions and environment of the user, developer agent, or CI runner. #### Unpinned `npx` Path 1. A Typ ...[truncated 1098 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/checklist.sh:160
Finding

Unrestricted Health-Check Target Enables Internal HTTP Requests

Content
View full analysis
/dev/null) local body=$(echo "$response" | sed '$d') local status=$(echo "$response" | tail -1) ``` ### Technical Analysis The health-check function constructs an HTTP URL from caller-controlled host, port, and endpoint values and passes it to `curl`. It does not restrict the destination to an approved service or reject loopback, private, link-local, or cloud-metadata addresses. Shell quoting prevents straightforward command injection through these parameters, but it does not prevent the function from being used as an SSRF-style request primitive. The response body is subsequently printed, allowing data returned by an internal HTTP service to be exposed to the caller or agent transcript. The function also lacks explicit timeout, response-size, and destination-resolution controls. DNS names may resolve to internal addresses, and slow or large responses may consume runner resources. ### Attack Path 1. An attacker influences the arguments supplied to the health-check command. 2. The attacker selects an internal HTTP service, loopback service, or link-local metadata endpoint reachable from the agent host. 3. The user or agent invokes a command such as: ```bash ./scripts/checklist.sh health INTERNAL_HOST INTERNAL_PORT /sensitive/path ``` 4. The runner sends the HTTP request from its own network context. 5. The internal service returns content that may not be directly reachable by the attacker. 6. The function prints the response body, exposing it throug ...[truncated 787 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (20)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file advertises one-click build, release, and rollback capabilities, and later includes canary deployment and rollback commands, but it does not provide an explicit warning that these operations can affect production systems, service availability, or deployed artifacts. Under the markdown criteria for missing user warnings, operational behaviors that may affect system integrity should be disclosed to users.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 48)May include surrounding context.

git clone https://github.com/YOUR_USERNAME/bu-bu-wei-ying.git

或复制 SKILL.md 到你的 skills 目录

cp SKILL.md ~/.hermes/skills/bu-bu-wei-ying/SKILL.md

text

## 使用方法

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The usage example explicitly walks through production deployment troubleshooting and includes rollback as an agent action without a clear caution that these operations can disrupt live systems. In an agent-skill context, example workflows can normalize or encourage high-impact operational actions without requiring confirmation, change approval, or environment checks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation guidance is broad enough to match common software-development requests, causing the skill to be invoked in situations where its deployment, CI/CD, and operational instructions may be unnecessary or unsafe. Because the skill includes commands that build, push, deploy, and roll back systems, over-activation increases the chance an agent will propose or perform impactful actions without sufficient user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section describes deployment, canary release, monitoring, and rollback actions but does not prominently warn that these steps can modify live or staged systems. In a skill intended for agent use, omission of an explicit safety boundary can lead to unintended operational changes, service disruption, or rollback/deployment actions taken without informed approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example workflow instructs the agent to build and push an image to a registry and execute a canary release, yet it provides no explicit warning that these are real external side effects. In context, examples strongly shape agent behavior, so this can normalize modifying registries or live environments without a deliberate authorization step.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and demonstrates shell-capable operations (git, npm, docker, curl, netstat, tail) but does not declare any explicit tool scope or permission boundary. In an agent environment, this can cause overbroad execution authority and make it easier for routine development prompts to trigger real system-changing commands without clear guardrails.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name, description, headings, instructions, and examples are entirely in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. This creates a language-policy concern because it implicitly enforces a single locale without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation condition covers broad categories like complex app development, CI/CD, and DevOps tasks, which are common requests and may auto-apply this skill in many contexts. Because the skill includes operational and deployment actions, overly broad triggering increases the chance that an agent will propose or execute impactful commands without task-specific safety checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The release-stage guidance includes creating release tags, canary rollout, monitoring, and rollback planning, but it does not warn about production impact or require explicit authorization. In a tool-enabled agent, these are real change-management actions that can affect availability, integrity, and customer traffic if taken automatically or on the wrong target.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example workflow instructs the agent to build an image, push it, and perform canary release as a normal sequence without a safety disclaimer or approval checkpoint. Examples strongly shape agent behavior, so this normalizes production-affecting actions and can lead to unsafe execution in response to ordinary development requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header and user-facing messages indicate the skill forces a specific language/locale for interaction. Under the policy, language constraints should either be optional for the user or clearly justified as region-specific, which is not present here.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON template hard-codes monitor names and alert messages in Chinese, and the same pattern continues across the file. Because the file provides no indication that the skill is region-specific or that users can choose a locale, it appears to impose a specific language by default, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This JSON manifest contains user-facing natural-language fields in Chinese, including folder names, titles, summaries, and descriptions. Under the policy for all file types, forcing a specific language without user opt-in or documented justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The document is written in Chinese and does not offer an explicit language selection or opt-in within the README, even though it later claims bilingual support. This may constitute a language policy concern if the skill defaults users into a specific language without asking their preference.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.