Back to skill

Security audit

S2-BAS-Causal-OS (S2 楼宇自控因果操作系统)

Security checks for vulnerabilities and agentic risk

Overview

This skill should be reviewed because it describes high-impact building HVAC control, but the shipped safety and authorization implementation is incomplete and not reliable.

Install only for review, simulation, or documentation experiments. Do not connect this skill to real building controls or treat its authorization result as proof of permission until the physics engine is complete, hardware actuation is separately gated, and signed short-lived tokens are verified by the BMS or homeowner authority outside the plugin.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
handler.py:8
Finding

Hardcoded Authorization Identifiers Allow Forged L2/L3 Access

Content
View full analysis

Vulnerability Details

File Location: handler.py, lines 8-10 and 28-47
Vulnerability Type: Hardcoded credentials and inadequate authorization validation
Risk Level: High

Vulnerable Code

python
self.registered_sssu = {
    "SSSU-OFFICE-801": {"mode": "commercial", "bms_pub_key": "BMS_ROOT_001"},
    "SSSU-HOME-201": {"mode": "residential", "owner_id": "MILES-XIANG-888"}
}
python
if mode == "commercial":
    if digital_id != space_info["bms_pub_key"]:
        return {
            "authorized": False,
            "mode": "commercial",
            "reason": "Commercial L2/L3 execution requires central BMS authorization."
        }
    return {"authorized": True, "mode": "commercial", "status": "bms_dispatch_granted"}

elif mode == "residential":
    if digital_id != space_info["owner_id"]:
        return {
            "authorized": False,
            "mode": "residential",
            "reason": "Residential hardware execution requires homeowner authorization."
        }
    return {"authorized": True, "mode": "residential", "status": "owner_execution_granted"}

The denial-message text above is translated into English for report-language compliance; the authorization conditions and identifiers correspond directly to the audited source.

Technical Analysis

The authorization gateway embeds trusted BMS and homeowner identifiers directly in publicly distributed source code. It then treats exact string equality as sufficient proof that the caller holds execution rights.

The values BMS_ROOT_001 and MILES-XIANG-888 are therefore not secrets: any user who can inspect the package can recover and submit them. No cryptographic signature is verified, despite the documentation describing signed Dispatch_Token and Owner_Token credentials.

The implementation also lacks:

  • Token expiration and issuance-time checks.
  • Nonce or replay protection.
  • Issuer and au ...[truncated 3000 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all trusted identities, authorization tokens, and credential-equivalent values from source code.
  2. For commercial operations, require a short-lived BMS dispatch token signed by a securely managed private key. Verify it using a securely provisioned public key.
  3. For residential operations, require a short-lived owner authorization token generated by a registered owner device and verify its digital signature.
  4. Bind every token to:
    • The exact SSSU address.
    • The requested action and L2/L3 control level.
    • The issuing authority and intended audience.
    • An issuance time and narrow expiration time.
    • A unique nonce or transaction identifier.
  5. Persist used transaction identifiers for the token lifetime to prevent replay.
  6. Store keys in an operating-system key store, secrets manager, hardware security module, or equivalent protected facility. Do not store private keys or bearer secrets in the package.
  7. Enforce authorization again at the BMS or physical actuator boundary. A successful result from the prediction plugin must not independently authorize hardware changes.
  8. Use an explicit deny-by-default policy for unknown decision levels. Validate requested_level against a strict enumeration rather than relying on selected string comparisons.
  9. Add negative tests covering forged tokens, altered SSSU addresses, expired tokens, replayed tokens, incorrect audiences, unauthorized control levels, and unknown decision values.
  10. Complete and test the handler safely by implementing or removing the undefined prediction call, importing required modules, and ensuring failures always produce a denied authorization state.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill advertises a thermodynamic prediction engine, but the actual content primarily defines authorization and control-handling rules while leaving the claimed spatial mapping, calibration, and CLC functionality unspecified or delegated to an external tool. This mismatch can mislead downstream agents or operators into granting the skill trust, permissions, or decision authority it has not earned, creating a confused-deputy risk in a safety-critical BAS context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes real-time HVAC prediction, automated control, and hardware protection strategies for building systems without any operator-safety warning, approval requirement, or validation boundary. In a BAS context, unclear autonomy claims can lead an agent or integrator to treat the skill as safe for direct actuation, creating risk of equipment damage, unsafe indoor conditions, or disruption to occupied spaces.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes spatial mapping, thermal calibration, and Causal Lookahead Control prediction, with dual-track authorization as an included safety feature. In this file, the substantive implemented behavior is the S2SecurityGateway authorization logic and policy enforcement, while the actual physics-engine behaviors are absent or stubbed out, so the code behavior does not match the skill's claimed primary function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

User-visible docstrings and returned reason messages are written exclusively in Chinese, including authorization denial text that appears intended for end users. The file does not offer a language choice or document a justified region-specific constraint, so it violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The skill describes an agent that can autonomously generate operational decisions in a cyber-physical BAS context, including proposals affecting HVAC setpoints, fan behavior, and shutdown actions. Although the document claims Dual-Track authorization and token gating, it also overstates that this architecture 'entirely neutralizes prompt-injection vulnerabilities,' which is a red flag because it can encourage overtrust in autonomous control logic around safety-critical infrastructure.

Content

Scanner excerpt · s2-bas-causal-decision-en.md (reported line 31)May include surrounding context.

md
## 5. Cyber-Physical Security: S2 Dual-Track Authorization
**(CRITICAL SECURITY DECLARATION)** An AI Agent generating L0-L4 decisions does NOT possess implicit physical execution rights. All hardware modifications must pass the **Dual-Track Auth Gateway**:
* **Commercial/Public Spaces**: Agents can only autonomously execute L0/L1 advisory actions. For L2/L3 hardware interventions, the Agent is strictly forbidden from directly cutting power. It must submit the decision as a "crisis proposal" to the central Building Management System (BMS). Physical execution is blocked unless a cryptographically signed `Dispatch_Token` is returned by the BMS.
* **Residential Spaces**: The Agent must attach an `Owner_Token` generated by the Homeowner's registered digital identity to execute L2/L3 interventions.
This Zero-Trust architecture entirely neutralizes prompt-injection vulnerabilities, preventing rogue AI agents from arbitrarily shutting down critical building infrastructure.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly describes autonomous override of room controls, including changing setpoints, locking fan speed, and forcibly cutting FCU water valve and power, without requiring explicit occupant warning, operator approval, or clearly defined safety interlocks. In a BAS context, these actions can directly affect occupant safety, comfort, and equipment operation, and normalization of such behavior in guidance increases the risk that downstream implementations will perform unsafe or unauthorized control actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The language endorses bypassing occupant intent by labeling the guest setting 'absurd' and instructing the agent to take control directly. In an operational BAS skill, this is dangerous because it frames unauthorized override as normal behavior, which can lead to deployments that ignore consent, local policy, accessibility needs, or legitimate edge cases where the occupant setting is intentional.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · s2-swm-spatial-causality-en.md (reported line 25)May include surrounding context.

md
## 3. Spatial Sovereignty and Authorization Axiom
Intervention in physical space requires strict legitimacy. The model prevents unauthorized control via the following mechanism:
* **Axiom 10 (Spatial Sovereignty Mutex Lock)**: Any fundamental physical alteration to an SSSU (e.g., forcing a supply source offline) must adhere to a Dual-Track Governance Model:
  * **Residential Mode**: Absolute execution rights are reserved exclusively for the "Homeowner" possessing the 22-digit digital destiny chart and SSSU root deed (requires `Owner_Token` validation).
  * **Commercial Mode**: Individuals within the physical space (e.g., hotel guests, office workers) hold only "environmental request rights." All L2/L3 physical execution commands must be cryptographically signed and issued as a `Dispatch_Token` by the central Building Management System (BMS).

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

A language or locale policy violation applies to all file types when content forces a specific language without user opt-in. This file presents all instructions and policy content only in Chinese, and no text indicates that the skill is region-specific or that users may choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The top-level title and tagline present content in both Chinese and English, but the document does not indicate whether language selection is user-configurable or intentionally region-specific. Under the policy, forcing or assuming a language/locale without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The inline comment states that L0 and L1 are 'just suggestions' and therefore do not involve physical modifications. However, the implementation returns an authorization success object for those requested levels, which operationalizes them as granted actions rather than merely non-executable suggestions; this creates an intent/code mismatch in how those levels are represented.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The handler returns detailed authorization failure reasons tied to specific space types and identifiers, which can leak sensitive operational details about protected locations and authorization models. In an access-control context, verbose denial messages help attackers enumerate valid addresses, infer whether a target is commercial or residential, and tailor subsequent impersonation attempts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file presents the skill content exclusively in English and does not indicate any user choice, localization option, or justification for enforcing a single language. Under the policy rule, a forced language without opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

文件标题及全文内容均固定为中文表述,但文档中没有说明这是面向特定中文用户群体,或提供其他语言/locale 选项。按规则,若技能在自然语言层面强制特定语言而无用户选择或明确地域性理由,可构成语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file name and title indicate an English-specific variant (-en and English-only content), but the document does not offer a language choice or explain why English is required. This can violate language/locale policy when a skill effectively forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.