T09 · Insecure Skill Coding Practices
- Location
check-ssl.sh:58- Finding
Unescaped Domain Data Enables JSON Output Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a purpose-aligned SSL certificate checker with some disclosed batch-monitoring behavior and minor implementation cautions.
Install only if you are comfortable with a Chinese-language SSL checker that may use a local domains list for batch checks. Review or control the domains file before running the script, and avoid trusting its JSON output in automation unless the JSON escaping issue is fixed.
check-ssl.sh:58Unescaped Domain Data Enables JSON Output Injection
声明描述的是一个按自然语言触发、查询某个指定域名证书过期时间的技能。实际代码并不解析用户给出的单个域名,而是依赖本地 ssl-domains.txt 文件进行批量检查,这使其主要用途更接近“SSL 证书监控器”而非“单次查询工具”。此外,代码会访问并在缺失时创建本地文件,进行阈值告警分级、汇总统计、JSON 输出以及通过退出码表示失败状态,这些都是未在描述中体现的能力。虽然核心主题仍与 SSL 证书到期检查相关,但其实际行为和资源访问方式与声明存在实质差异,因此应判定为描述与行为不一致。
The description and usage instructions require Chinese phrasing such as 「查 xxx.cn 证书」 and present the skill entirely in Chinese, which indicates a language-specific constraint. The file does not provide user opt-in, alternative language support, or a documented justification that this is a region-specific skill.
The skill metadata says it checks a user-specified domain's SSL certificate, but the implementation ignores that model and instead reads a local batch file, with behavior centered on monitoring a persistent domain list. This mismatch is dangerous because users or calling agents may provide a single domain expecting a read-only query, while the script performs broader, stateful operations that can inspect unintended hosts and behaves differently than advertised.
When the expected domains file is missing, the script creates directories and writes a template file under the user's home directory, even though the stated purpose is just querying certificate expiry. Unnecessary filesystem writes expand the skill's side effects and can violate user expectations or agent sandbox assumptions, especially in automation contexts that expect read-only inspection.
The skill title and all example invocations are presented only in Chinese, including the user trigger phrases in the usage section. This can constitute a language/locale policy issue because the documentation implicitly requires Chinese-language use without giving users an explicit language option or stating that the skill is intentionally China/Chinese-specific.
No suspicious patterns detected.