Back to skill

Security audit

Vue Component Generator

Security checks for vulnerabilities and agentic risk

Overview

This Vue component generator is simple and mostly purpose-aligned, but its bundled shell script can overwrite arbitrary writable files and can execute injected commands through an unsanitized component name.

Review before installing. Only use this with trusted component names, avoid passing user-controlled input to the script, and prefer a fixed output directory with strict name validation. The current package should be corrected to reject path separators, traversal, newlines, sed metacharacters, and existing destinations before being used in automation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
vue-component-generator.sh:2
Finding

Arbitrary File Creation and Overwrite Through Unsanitized Component Name

Content
View full analysis
"$NAME.vue" << 'VUE' ``` The generated file is subsequently used without path validation: ```bash sed -i "s/COMP_NAME/$NAME/g" "$NAME.vue" ``` ### Technical Analysis The first positional argument is assigned directly to `NAME` and used as a filesystem path. Quoting prevents shell word splitting, but it does not prevent absolute paths, directory separators, or traversal sequences such as `../`. The `cat > "$NAME.vue"` redirection creates the selected file or truncates it if it already exists. Consequently, an attacker who can influence the component name can select any writable path whose constructed name ends in `.vue`. For example, a name such as `../../target` causes the script to write to `../../target.vue`. An absolute value such as `/tmp/target` writes to `/tmp/target.vue`. If an attacker can pre-create a symbolic link with a `.vue` filename, shell redirection will normally follow that link, potentially allowing an arbitrary writable target without requiring the final target itself to have a `.vue` suffix. ### Attack Path 1. An attacker gains control over the component-name argument, such as through an automated agent request, wrapper script, CI parameter, or untrusted user input. 2. The attacker supplies a traversal or absolute path: ```bash ./vue-component-generator.sh ../../target ``` 3. The shell resolves `"$NAME.vue"` to `../../target.vue`. 4. The output redirection creates or truncates that file before writing the Vue template. 5. The subsequent `sed -i` operation modifies the same attacker-selected file. 6. Data in an existing writable file can therefore be destroyed or replaced under the invoking user's permissions. ### Impact Assessment The vulnerability permits creation, truncation, and ...[truncated 583 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. Reject path separators, traversal sequences, control characters, newlines, and names beginning with `-`. 3. If output-directory selection is required, accept it through a separate option and canonicalize it before use. 4. Verify that the resolved destination remains inside the authorized output directory. 5. Refuse to overwrite existing files unless an explicit trusted `--force` option is supplied: ```bash OUTPUT_FILE="$OUTPUT_DIR/$NAME.vue" if [[ -e "$OUTPUT_FILE" || -L "$OUTPUT_FILE" ]]; then printf 'Error: destination already exists\n' >&2 exit 1 fi ``` 6. Reject symbolic-link destinations and use safe file-creation semantics where possible. 7. Run the generator with the minimum filesystem permissions required. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
vue-component-generator.sh:19
Finding

GNU sed Command Injection Through Unsanitized Component Name

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi ``` 2. Do not dynamically construct interpreter programs from untrusted data. 3. Prefer generating the file directly with a mechanism that treats the name as data. For example, after strict validation: ```bash cat > "$NAME.vue" <

$NAME

.$NAME { } VUE ``` 4. If `sed` must be retained, escape every character meaningful in the replacement context, including the selected delimiter, backslashes, ampersands, and newlines. Strict allowlist validation should still be enforced. 5. Add regression tests for `/`, `;`, backslashes, ampersands, command substitutions, carriage returns, newlines, absolute paths, and `../`. 6. Run the generator with least privilege and avoid exposing its arguments directly to untrusted requests. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill metadata and documentation claim support for multiple Vue 3 generation modes, including Options API and TypeScript, but the provided behavior only demonstrates a fixed basic script-setup template. This can mislead users and downstream agents into relying on unsupported functionality, causing incorrect code generation, automation failures, or unsafe assumptions about the produced artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written entirely in Chinese, and the file provides no indication that language is configurable or limited to a China-specific use case. This can violate language/locale policy when a skill effectively defaults to a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description "生成 Vue 组件" is overly broad and does not clearly limit the circumstances under which the skill should be invoked. Vague activation metadata can cause the agent to select this skill in unintended contexts, increasing the chance of inappropriate code generation or misuse when a more specific skill would be safer.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.