Back to skill

Security audit

design-doc-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent document-generation purpose, but it asks agents to collect login passwords and save authenticated page screenshots without enough user control or secret-handling guidance.

Install only if you are comfortable with the agent reading the relevant repositories and saving UI screenshots locally. Do not provide production passwords in chat; prefer logging in yourself, using a temporary least-privilege account, or sharing only a short-lived session mechanism. Review screenshots and generated documents for secrets, personal data, tenant details, and business data before storing or sharing them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
scripts/build_design_doc.py:4
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/build_design_doc.py, line 4
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

text
Dependency: pip install python-docx

The script documentation directs users to install python-docx without specifying an approved version, dependency lock file, package hash, or trusted package repository. Consequently, installation resolves mutable package content from the user's configured Python package index.

Technical Analysis

An unpinned installation can retrieve a future package version that was not present during this audit. It also inherits the security of the configured package index and all transitively resolved dependencies. If the upstream package, a transitive dependency, the package-index account, or the user's index configuration is compromised, following this instruction could install attacker-controlled content.

Exploitation is contingent upon compromise or manipulation of the dependency supply chain; the audited project does not itself host or retrieve a known malicious payload. Nevertheless, the instruction lacks controls that would ensure users install the same reviewed artifacts on every system.

Attack Path

  1. An attacker compromises a relevant package release, transitive dependency, package-index account, or package source configured on the victim's system.
  2. The user follows the documented installation command without a pinned version or integrity hashes.
  3. Package resolution selects the attacker-controlled or unexpectedly changed artifact.
  4. Malicious installation behavior executes during package installation, or malicious code executes when the generated script imports the package.
  5. The payload operates with the privileges of the user running pip or the document-generation script.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing us ...[truncated 564 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin python-docx to a reviewed exact version rather than installing the latest available release.
  2. Maintain dependencies in a lock file that also fixes all transitive dependency versions.
  3. Require package hashes, such as through a hash-locked requirements file and pip install --require-hashes.
  4. Specify and enforce an approved package index rather than inheriting arbitrary user or environment index configuration.
  5. Install dependencies inside an isolated virtual environment without administrator or root privileges.
  6. Scan locked dependencies regularly with a software composition analysis tool and update them through a reviewed process.
  7. Replace the current instruction with a reproducible command, for example:
text
python -m pip install --require-hashes -r requirements.lock

The lock file should contain the reviewed exact version and cryptographic hashes for every required distribution.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to ask for tenant, username, and password so it can log into the frontend, but it provides no warning, consent flow, secret-handling guidance, or safer alternative. Collecting credentials in routine chat or agent workflow creates a clear risk of exposing authentication secrets and enables direct access to potentially sensitive internal systems.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation text is broad enough to trigger on ordinary requests for technical documentation, which can cause the skill to activate and begin reading project code or navigating frontend pages without the user explicitly requesting this specific workflow. In this context, overbroad triggering increases the chance of unnecessary access to source code, APIs, screenshots, and other sensitive project artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description and output requirements are entirely specified in Chinese, including required Chinese labels and document structure, with no indication that the user may choose another language. This can constitute a language-policy issue when a specific language is imposed without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Directing the agent to collect login credentials and use them to access the application creates a sensitive-data handling risk and expands the agent's operational authority into authenticated environments. In a code-and-doc generation skill, this is especially dangerous because the agent is also instructed to inspect pages and artifacts, increasing the amount of sensitive information it can reach once logged in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow mandates capturing and saving frontend screenshots to a local output directory without clearly warning the user that UI data will be stored. Screenshots can contain sensitive business data, personal data, tenant identifiers, or authentication context, so silent local persistence increases data leakage risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Requiring a screenshot of the login page can capture usernames, tenant names, branding, environment details, MFA prompts, or even partially entered secrets, creating unnecessary exposure of authentication-related context. Because the skill also saves screenshots to disk, the risk persists beyond the live session.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script claims the document is generated automatically from frontend/backend code and screenshots, but the implementation is only a manual template with fixed placeholders and no code parsing or validation. In a documentation-generation skill, this can mislead users into trusting fabricated or unverified technical content, which may propagate incorrect architecture, schema, or process details into formal deliverables.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code file contains user-facing natural-language text in the module docstring and throughout the generated document, all fixed to Chinese. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless clearly justified as region-specific, which is not documented here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The generated summary asserts that all functional modules, table structures, and code-derived content have been fully organized, even though the output is static example text. This creates a supply-chain style integrity risk for engineering documentation: teams may approve designs, implement features, or make audit decisions based on false statements embedded in an apparently authoritative document.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The document specifies Chinese-language document standards throughout, including Chinese title text and Chinese font requirements such as 宋体/仿宋. Because the file does not state that this skill is intended only for Chinese-language documentation or that users may opt into another locale, it can be read as forcing a specific language/locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.