Back to skill

Security audit

conspect

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches a report-generation purpose, but it gives itself broad automatic control, persistent workflow state, and risky file/rendering behavior that users should review before installing.

Install only if you are comfortable with an autonomous report workflow that writes many files into `.agent/harness/`, resumes from saved state, and may render spreadsheet-derived content into HTML/PDF. Review generated reports before sharing them, avoid sensitive spreadsheets unless masking is verified independently, and restrict output paths to a dedicated project folder.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
SKILL-execution.md:13
Finding

Agent Session Hijacking and Persistent Workflow Control

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
conspect_tools/run.py:1025
Finding

Arbitrary File Write Through Unrestricted Output Paths and Filenames

Content
View full analysis
str: if filename.startswith("report."): filepath = self.report_dir / filename else: filepath = self.output_dir / filename filepath.write_text(content, encoding="utf-8") return str(filepath) def _save_binary(self, content: bytes, filename: str) -> str: if filename.startswith("report."): filepath = self.report_dir / filename else: filepath = self.output_dir / filename filepath.write_bytes(content) return str(filepath) ``` ### Technical Analysis The `save_report` and `save_with_chinese_name` CLI actions accept caller-controlled `output_dir`, `filename`, and `content`. The exporter joins the filename to the selected directory but does not reject: - Absolute paths. - Parent-directory components such as `..`. - Symbolic-link escapes. - Unexpected file extensions. - Existing sensitive files. `Path` joining does not enforce containment. An absolute filename can replace the preceding output directory, while traversal components can escape it after path resolution. The use of `write_text` and `write_bytes` overwrites existing files by default. ### Attack Path 1. A ...[truncated 1086 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
conspect_tools/render_engine.py:465
Finding

Stored Script Injection in Generated Dashboards

Content
View full analysis

{title}

{f'

{description}

' if description else ''} """ ``` ```python cards += f"""
{m.get('label', '')}
{value_str}
{change_sign}{change_val*100:.1f}% vs peer period
""" ``` ```python def _render_conclusion(self, insights: List[str]) -> str: items = "".join([f"
  • {i}
  • " for i in insights]) ``` ```python thead = "" + "".join(f'{col}' for col in columns) + "" tbody = "" for row in rows: padded = list(row) + [""] * (max_cols - len(row)) cells = "".join(f"{c}" for c in padded[:max_cols]) tbody += f"{cells}" ``` ### Technical Analysis The renderer constructs HTML through string interpolation and concatenation without context-sensitive escaping. Untrusted values are inserted into: - Element bodies. - HTML attributes. - Table headers and cells. - Dashboard titles and descriptions. - Insight lists. - A fully unrestricted custom HTML section. Spreadsheet values can flow into layout tables and report metadata. A value containing active markup, an event-handler attribute, or a script element can therefore be stored in the generated dashboard and executed when the file is opened. The unrestricted `custom` section provides a direct injection primitive, while ordinary title and table fields allow injection even when custom sections are not used. ### Attack Path 1. An attacker supplie ...[truncated 1181 chars]
    Remediation
    View remediation

    T09 · Insecure Skill Coding Practices

    Error
    Location
    conspect_tools/report_renderer.py:55
    Finding

    Unsafe Report HTML Is Executed in a Headless Browser

    Content
    View full analysis
    str: md_content = self.render_markdown(report_design) html = self._md_to_html(md_content) return self._wrap_html_template( html, report_design.get("title", "Data Analysis Report") ) ``` ```python with sync_playwright() as p: browser = p.chromium.launch() page = browser.new_page() page.set_content(html) pdf = page.pdf( format='A4', margin={ 'top': '20mm', 'right': '20mm', 'bottom': '20mm', 'left': '20mm' }, print_background=True ) ``` ```python try: import markdown return markdown.markdown( md_content, extensions=['tables', 'fenced_code'] ) except ImportError: html = md_content html = html.replace("# ", "

    ").replace("\n", "

    \n", 1) html = html.replace("## ", "

    ").replace("\n", "

    \n", 1) html = html.replace("### ", "

    ").replace("\n", "

    \n", 1) return html ``` ```python return f""" {title} {content} """ ``` ### Technical Analysis Report fields are converted to Markdown and then HTML without a sanitization stage. Markdown parsers commonly preserve raw HTML unless explicitly configured otherwise, and the fallback converter starts with the original content unchanged. The untrusted result is inserted into the page template, including an unescaped document title. During PDF generation, Playwright loads this HTML with JavaScript and network access enabled. Consequently, malicious report content can execute automatically during server-side PDF rendering, even before a rec ...[truncated 1428 chars]
    Remediation
    View remediation
    ` element. 4. Create the Playwright page with JavaScript disabled where report functionality permits: ```python context = browser.new_context(java_script_enabled=False) page = context.new_page() ``` 5. Intercept and abort all network requests during PDF generation unless an explicit local-resource allowlist requires them. 6. Block `file:`, `javascript:`, `data:`, and unexpected remote URL schemes. 7. Run Chromium in a dedicated, least-privileged sandboxed worker with no secrets and restricted network access. 8. Apply strict execution time, memory, page-size, and navigation limits. 9. Add Content Security Policy headers or equivalent document metadata. 10. Test malicious HTML in every report field and verify that no request or script executes during PDF rendering. ]]>

    T09 · Insecure Skill Coding Practices

    Warning
    Location
    conspect_tools/run.py:140
    Finding

    Sensitive Data Is Returned and Rendered Without the Documented Masking Controls

    Content
    View full analysis
    {c}" for c in padded[:max_cols]) tbody += f"{cells}" ``` ### Technical Analysis The Skill documentation claims that phone numbers, identity numbers, bank card numbers, email addresses, and detailed addresses are detected and automatically masked. No corresponding masking implementation was found in the executable pipeline. Instead: - `analyze` serializes the first five cleaned rows. - `read_all_sheets_raw` returns raw sample values. - The dashboard renderer accepts and displays arbitrary detail rows. - No sensitive-column exclusion or value transformation occurs before serialization. Because masking is only described as an Agent instruction, it is not a reliable data-security boundary. Direct CLI use, errors in Agent reasoning, or alternative rendering paths can expose unmasked values. ### Attack Path 1. A source spreadsheet contains personal or confidential fields. 2. The caller invokes `analyze` or `read_all`. 3. Raw sample values ar ...[truncated 966 chars]
    Remediation
    View remediation

    T03 · Remote Payload Retrieval and Execution

    Warning
    Location
    conspect_tools/render_engine.py:575
    Finding

    Generated Offline Reports Execute an Unpinned Remote JavaScript Dependency

    Content
    View full analysis
    {title} ``` ```python def render_offline_html(self, layout: Dict) -> str: """Generate offline HTML.""" return self.render_web_dashboard(layout) ``` ### Technical Analysis The purported offline report loads executable JavaScript from jsDelivr whenever it is opened. The dependency URL pins only the major version (`@5`) and does not include a Subresource Integrity hash. As a result, the effective JavaScript payload is not fully contained in the audited project and can change after review. The generated report also requires network access despite being described as offline. The browser establishes a third-party connection that exposes ordinary request metadata. If the CDN account, package publication process, or distribution infrastructure is compromised, modified code executes in every generated report that references the URL. ### Attack Path 1. The Skill generates a dashboard or offline report. 2. The report contains the jsDelivr script reference. 3. A recipient opens the report while connected to the network. 4. The browser requests the current ECharts 5 distribution from the CDN. 5. The CDN-provided code executes in the report context. 6. A compromised or unexpectedly changed dependency can inspect and manipulate page content or make further network requests. ### Impact Assessment The remote code execu ...[truncated 604 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
    Findings (124)

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    该代码片段的职责非常窄,核心是对传入数据字典做特征提取和基础统计,属于分析流水线中的一个底层模块。文件注释和类文档都明确写明“只负责提取数据特征,不负责图表选型决策”,这与声明中“AI自动完成数据解析、图表选型、商务排版、可视化渲染,输出专业报表”的完整产品能力明显不一致。代码中也没有看到Excel文件处理、多表合并、报表生成、图表渲染、投屏输出等相关实现。因此这不是轻微的实现细节差异,而是声明描述了一个完整自动化报表系统,而代码实际只是其中一个支持性子模块,主用途存在实质性偏差。

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    96% confidence
    Finding

    声明描述的是完整的智能报表生成产品,核心能力应包括自动图表选择、报表布局、视觉渲染和最终报告产出。而提供的代码仅覆盖数据读取和基础分析层:用 pandas/openpyxl 读取 Excel,返回 sheet 结构,进行去重/填充,按列类型识别时间/分类/数值维度,做 sum/avg/max/min/count 聚合和分组汇总,并生成非常基础的 insights 文本。虽然这些功能与“数据解析、多表分析”部分有关,属于支持性子能力,但距离声明中的主要能力——自动生成专业商务报表并完成可视化呈现——差距明显。因此描述显著夸大了代码实际行为,构成实质性不匹配。

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    The declared description promises a comprehensive automated reporting product: ingesting Excel, performing AI analysis, selecting charts, producing business-formatted visual reports, and outputting presentation-ready deliverables. The supplied code does something much narrower and different: it defines a DataStatistics class for core statistical calculations such as mean/median/std, concentration ratios, trend metrics, distribution characteristics, anomaly detection, and correlation. The module docstring explicitly says it only handles basic statistical computation and not insight generation or decision-making. There is no file handling, Excel processing, charting, rendering, templating, report generation, dashboard production, multi-table merging, or autonomous workflow management. This is therefore a clear description-behavior mismatch, with the code representing only a small analytical support component rather than the declared full automated reporting tool.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    The declared description promises an end-to-end intelligent analytics/reporting system centered on Excel ingestion, automatic analysis, visualization selection, business formatting, and final report generation. However, the supplied code chunk does not perform data ingestion, analysis, charting, rendering, or AI orchestration. Its actual purpose is much narrower: exporting provided content to files in several formats, saving an index, and duplicating files with Chinese names. While export could be a supporting component of a larger reporting system, this chunk by itself materially differs from the declared primary purpose and mainly implements an undeclared exporter module rather than the advertised autonomous analytics workflow.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    94% confidence
    Finding

    描述强调的是一个端到端、全自动的 AI 数据分析与商务报表生成工具,核心能力应包括数据源接入(尤其Excel)、自动解析、多表合并、智能分析、图表选型和最终渲染。当前代码片段仅覆盖最后一环:把外部已整理好的 layout/data 渲染成 HTML 看板,并附带简单的主题、样式、交互和表格展示功能。虽然这与“商务报表渲染”部分一致,但与声明中的主要价值主张——自动数据分析与全流程托管——存在明显落差,因此属于描述与实际行为不匹配。

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    97% confidence
    Finding

    声明描述的是一个端到端的“数据智能分析+商务报表自动生成”系统,重点在于数据摄取、解析、分析、图表选型和全流程自动产出。实际代码则只接收一个已经准备好的 report_design 结构,并将其渲染成多种文档格式。代码中没有任何 Excel 处理、数据清洗、多源合并、AI 推理、图表生成或分析决策逻辑。虽然“商务报表渲染”这一子能力与声明部分吻合,但该代码块体现的主要职责仅是最终展示/导出层,显著窄于声明的核心能力,因此属于描述与行为不一致。

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    99% confidence
    Finding

    The declared description promises an end-to-end AI business reporting system: ingesting Excel, automatically analyzing data, selecting chart types, laying out business reports, rendering visualizations, and producing ready-to-present outputs without user confirmation. The supplied code does something much narrower and materially different. It defines a ReviewDataLoader whose documented role is only to load audit/review data and perform simple comparisons. It reads JSON and text files from disk, returns context dictionaries, extracts existing chart/color/layout fields, and compares numeric values or dict fields for consistency. There is no Excel handling, no AI orchestration, no autonomous chart selection, no report rendering, no dashboard generation, and no final output production. This is a clear description-behavior mismatch in primary purpose and advertised capabilities.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    96% confidence
    Finding

    声明描述聚焦于 Excel 数据自动分析、图表选型、商务排版和报表/看板渲染,这与代码中的分析、统计、图表、洞察、渲染、保存等部分基本一致。但该代码块还明显实现了一整套额外的审核/质检工作流:review_design、review_implement、verify_end_to_end、final_judgment、generate_review_report、load_review_context,以及 compare_data 等。这些功能更像项目质量审计/评审工具,而不是单纯的商务报表自动生成器,属于未声明的重要能力扩展。另一个偏差是,描述强调“全流程托管AI自动生成,零用户确认环节”,而代码实际提供的是一个多 action 的通用 CLI,很多步骤需要显式调用不同动作来完成,并没有在该入口中体现一个单一的、完全自动的端到端流水线。因此描述不能完整且准确代表实际代码行为,应判定为不匹配。

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    97% confidence
    Finding

    The declared description presents a complete production skill for automatic Excel-based multi-source analysis and polished report rendering. However, the provided code is only a test module (tests/test_ai_agent.py) validating data classes and several AI-agent decision methods such as chart choice, insight generation, and review checks. While chart selection and insight generation are loosely related to the description, the primary purpose of this code chunk is software testing, not executing the advertised workflow. There is no evidence here of file ingestion, Excel parsing, multi-table consolidation, visualization rendering, business formatting, or presentation-ready report export. Therefore the description materially overstates and misrepresents what this supplied code chunk actually does.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    The declared description presents a complete automated reporting product with Excel ingestion, intelligent analysis, charting, visual rendering, and polished business-report output. The supplied code chunk does not implement that workflow. It is a test module validating a narrow helper/component behavior: extracting basic structural features from provided data dictionaries. While such feature extraction could be a supporting internal detail of a larger analytics system, this code chunk by itself materially differs from the declared primary purpose and lacks the major advertised capabilities. Therefore this is a description-behavior mismatch.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    The declared description promises a comprehensive automated reporting product focused on Excel/multi-source ingestion, AI analysis, charting, business formatting, and final rendered reports. The actual code provided is only a unit test module for a statistical helper class. Its observable behavior is limited to validating numerical/statistical functions such as totals, averages, concentration, trends, distributions, and anomaly detection. This is materially different from the declared primary purpose and lacks the core advertised capabilities, so the description does not accurately represent the supplied code chunk.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    94% confidence
    Finding

    The declared description promises a broad end-to-end AI analytics product: ingesting Excel and multiple data sources, automatically analyzing data, selecting charts, composing business layouts, and rendering polished reports with no user interaction. However, the provided code chunk only contains tests for a report renderer component. The tests pass in manually constructed report_design dictionaries and verify output files for Markdown/HTML, with minimal interface checks for PDF/Word. This behavior is much narrower and centered on rendering formatted output from an existing design, not on automated data ingestion, AI analysis, chart recommendation, or multi-source/table analysis. Therefore the supplied code does not accurately represent the declared full-purpose skill.

    Content

    No source excerpt is available for this finding.

    Tp4

    High
    Category
    MCP Tool Poisoning
    Confidence
    98% confidence
    Finding

    The declared description promises an end-to-end automated Excel-based intelligent analysis and report-rendering system. The actual code chunk does not implement or even directly invoke such functionality; it is a unit test module for a ReviewDataLoader. Its behaviors are limited to loading JSON-based context/chart data, comparing dictionaries for consistency, and extracting chart/color metadata. That is materially different from the declared primary purpose and omits the headline capabilities (Excel upload, AI analysis, chart choice, report composition, visual rendering/output).

    Content

    No source excerpt is available for this finding.

    Vague Triggers

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The skill activates on broad generic intent like data analysis or report generation, then mandates immediate execution. In a file-writing, autonomous workflow, such loose triggering can cause unintended activation and automatic processing of user files or project data without a deliberate opt-in.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    High
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The skill requires automatic creation of baton, analysis, QA, report, and other files, and says execution must begin immediately without waiting for extra user instruction. Silent or insufficiently disclosed file generation is dangerous because it creates persistent side effects, may overwrite expectations about workspace cleanliness, and can expose sensitive derived data into predictable local paths.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    High
    Category
    Not specified by scanner
    Confidence
    97% confidence
    Finding

    The document states that the agent must not write custom HTML/CSS/JS rendering logic and must rely on RenderEngine, but later sections instruct the agent to generate HTML skeletons, inject CSS/JS, and inline chart code. This contradiction weakens safety boundaries, making it easier for an agent to justify arbitrary code generation outside the intended controlled rendering path.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    High
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The file claims all rendering and file operations must go through the CLI layer, but later directs direct execution of a Python HTTP server and OS-level process termination. This inconsistency undermines the control boundary of the CLI and permits unmanaged process execution, which can lead to persistent background services, unintended network exposure, or unsafe shell/process behavior.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    High
    Category
    Not specified by scanner
    Confidence
    99% confidence
    Finding

    export_pdf 和 export_png 的注释声称分别“导出PDF”和“导出PNG”,但实际实现仅执行 html.encode('utf-8'),返回的是原始 HTML 文本字节,而不是 PDF/PNG 格式内容。这不是简单的未实现细节,而是接口语义与代码行为直接冲突。

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    High
    Category
    Not specified by scanner
    Confidence
    98% confidence
    Finding

    The protocol explicitly removes user confirmation and mandates automatic progression across analysis, design, implementation, and report generation. In a skill that ingests user-supplied Excel data and autonomously produces deliverables, eliminating human approval creates a meaningful risk of unauthorized actions, misinterpretation of sensitive data, or generation of misleading outputs without a stop point.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    High
    Category
    Not specified by scanner
    Confidence
    99% confidence
    Finding

    The change note normalizes zero user confirmation without any compensating safety warning or control requirements. In this context, the skill is designed for end-to-end automated business reporting, so silent progression can propagate data quality errors, privacy issues, or unsafe conclusions directly into polished outputs that users may trust and present externally.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    90% confidence
    Finding

    The manifest explicitly advertises fully automated processing of uploaded Excel data and rendered report generation with 'zero user confirmation,' but it provides no warning, consent boundary, or description of how uploaded data is handled. In a data-analysis skill, this increases the risk of unintended processing of sensitive spreadsheet contents, surprising actions, or silent generation/output behavior without meaningful user review.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    92% confidence
    Finding

    The manifest sets language: zh-CN, which appears to impose a single language/locale. Under the policy, forcing a specific language without opt-in or documented justification is a natural-language policy violation.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The changelog explicitly documents removal of the user confirmation step and emphasizes fully automatic progression with zero user confirmation. In a skill that ingests uploaded Excel data and automatically generates business reports, eliminating human approval increases the risk of unreviewed analysis, misleading output, unintended disclosure in rendered reports, and unsafe autonomous actions without an explicit warning or consent boundary.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The README explicitly advertises a zero-confirmation, fully automated workflow and elsewhere states that artifacts are written into the project workspace under .agent/harness/. In an agent environment, automatic file creation without an explicit warning or confirmation increases the risk of unintended overwrites, leakage into shared workspaces, and surprising side effects from a simple natural-language trigger.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The skill mandates immediate creation and repeated modification of files under {项目路径}/.agent/harness/ before doing substantive work and without user-facing consent. Silent writes into the user's project can overwrite expectations, create persistence artifacts, and violate trust boundaries, especially when activation alone triggers the behavior.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.