Back to skill

Security audit

web-test-reporter

Security checks for vulnerabilities and agentic risk

Overview

The skill fits a web-testing/reporting workflow, but it asks for credentials, performs live state-changing tests, and embeds an admin password in generated reports.

Install only if you will use it against test or disposable environments, with least-privileged temporary accounts. Remove the hardcoded admin/admin123 report line before use, avoid putting passwords in generated reports or screenshots, pin dependencies, and require explicit operator approval before destructive actions such as submit or delete.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_report.py:125
Finding

Plaintext Administrative Credentials Embedded in Generated Reports

Content
View full analysis

Vulnerability Details

File Location: scripts/build_report.py:125
Vulnerability Type: Hardcoded credentials and plaintext sensitive-data exposure
Risk Level: Medium

Vulnerable Code

python
para(doc, "账号:租户=园区智慧应用管理系统,用户=admin,密码=admin123")

The report template inserts a tenant identifier, administrative username, and password directly into every generated Word document. Because the values are hardcoded rather than supplied through a protected secret-management mechanism, users may overlook them when adapting or executing the template.

Technical Analysis

Generated .docx reports are ordinary files that may be shared through email, uploaded to collaboration platforms, committed to repositories, or retained in broadly accessible archives. Embedding authentication secrets in such a document creates a secondary, uncontrolled copy of the credentials.

If the hardcoded values are valid in a target deployment, anyone who can read the generated report can recover and attempt them. Even when they are example values, including a recognizable default administrative password encourages insecure credential reuse and can cause operators to distribute real credentials after modifying the template.

Attack Path

  1. An operator copies or executes the report-generation template without removing the hardcoded account information.
  2. The script writes the tenant, username, and password into the generated Word report.
  3. The report is distributed, archived, uploaded, or exposed to a user who is not authorized to receive authentication secrets.
  4. The recipient extracts the credentials from the document.
  5. If the credentials remain valid and the target system is reachable, the recipient authenticates as the administrative account.
  6. The recipient can then exercise all application capabilities granted to that account.

Impact Assessment

The immediate scope is disclosure of the embedded tenant and acco ...[truncated 484 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all passwords from the report template and generated reports.
  2. Replace the vulnerable line with a redacted account reference, such as Account: admin (password omitted).
  3. Do not include real credentials in screenshots, test logs, source files, report metadata, or filenames.
  4. Obtain credentials at runtime through an approved secret manager or protected environment variable when authentication is required. Do not write those values into the report.
  5. Add a final report-redaction step that detects passwords, tokens, session identifiers, API keys, and other sensitive values before saving or distributing the document.
  6. Rotate the displayed password if it has ever been valid in any environment, and review previously generated reports for exposure.
  7. Use a dedicated, least-privileged testing account instead of a general administrative account.

T08 · Insecure Dependencies

Note
Location
scripts/build_report.py:1
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: scripts/build_report.py:1-5
Vulnerability Type: Unpinned software dependency
Risk Level: Low

Vulnerable Code

python
"""
Web 功能测试报告生成脚本模板
使用方式:复制此脚本到报告目录,按实际测试内容修改后运行
依赖:pip install python-docx
"""

The installation instruction requests python-docx without a version constraint or package-integrity hash. Consequently, the installed artifact can change over time even when the project source remains unchanged.

Technical Analysis

Unpinned dependencies make builds non-reproducible and allow future package releases to enter the execution environment without review. If a later release or its distribution channel is compromised, users following the documented command may install attacker-controlled code.

Python packages can execute code during installation and subsequently when imported. In this project, the dependency is imported at module initialization, so a malicious installed version could also execute code when the report-generation script runs.

The audit found no evidence that the currently referenced package is malicious, and the package name is not an apparent typosquat. This finding concerns the absence of version and integrity controls rather than a confirmed malicious package.

Attack Path

  1. An attacker compromises a future dependency release or its distribution path.
  2. A user follows the documented unpinned pip install python-docx instruction.
  3. Package resolution selects the compromised release because no reviewed version or hash is enforced.
  4. Malicious package code executes during installation or when build_report.py imports the package.
  5. The code operates with the privileges of the user running pip or the report script.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the installing user's account. That scope may include access to files, environment variables, source code ...[truncated 278 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin python-docx to a specifically reviewed version in a dependency manifest.
  2. Generate and verify cryptographic hashes, and install with a command such as pip install --require-hashes -r requirements.txt.
  3. Use a lock file or equivalent reproducible dependency-management process.
  4. Install packages only from an explicitly approved package index over TLS.
  5. Review dependency updates before changing the pinned version.
  6. Run dependency installation and report generation inside a least-privileged virtual environment or isolated container.
  7. Add automated dependency and supply-chain scanning to detect known vulnerabilities or unexpected package changes.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的核心能力是“Web 功能测试自动化执行与报告生成”,其中测试执行是主要组成部分;但实际代码只负责生成一个测试报告模板文档,并根据预设截图路径插入图片。脚本没有浏览器自动化、HTTP 请求、页面操作、断言校验、测试用例执行、结果汇总自测试过程等行为。虽然文档中提到‘测试工具:agent-browser CLI’,但这只是静态文本,代码本身并未使用该工具。因此,代码行为与声明用途存在实质性不一致:它只能支持报告产出,不能完成所宣称的 Web 功能测试自动化执行。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script outputs plaintext test account credentials into the final .docx report without warning or redaction, creating a direct sensitive-data exposure channel. Reports are commonly shared, stored in document systems, or emailed, so this design can unintentionally disclose privileged access far beyond the testing environment.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Including plaintext admin credentials in a report section encourages operators to disclose privileged access data in durable artifacts, increasing the chance of credential reuse, insider misuse, and accidental sharing. Because the skill's purpose is report generation, the surrounding context makes this more dangerous: it operationalizes secret leakage as part of the normal workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation criteria are broad enough to trigger on common web help, validation, or testing requests, which can cause the skill to engage in contexts the user did not intend. In this skill, overbroad activation is more dangerous because the workflow includes credential collection and potentially destructive actions such as create/edit/delete and submission operations against live systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly asks for usernames and passwords, and possibly tenant identifiers, without any privacy notice, minimization guidance, or safer alternative flow. In the context of a web-testing skill, this increases the risk of unnecessary credential exposure, accidental retention in chat logs, and misuse of privileged accounts during automated testing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s docstring and all generated report content are fixed in Chinese, including headings, captions, and instructions. This enforces a specific language/locale with no opt-in or configuration mechanism, which matches the policy concern for language/locale restrictions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template hard-codes and publishes a username/password directly into the generated report text, which can leak live or reusable credentials to anyone who receives the document or accesses the source. In a reporting skill, embedding secrets is unnecessary to core functionality and normalizes unsafe handling of administrative access data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The title and the entire specification are written as mandatory Chinese output guidance, which effectively forces a specific language/locale. The file does not indicate that Chinese is optional, user-selected, or required for a region-specific compliance reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.