Back to skill

Security audit

Auto Create AI Team

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a local file generator, but its file-writing behavior is broader than its own documentation says.

Review this skill before installing if you need strict filesystem containment. Use it only on project directories you trust, avoid running it with elevated privileges, avoid external --log-file paths, and treat the generated ai-team files as documentation scaffolding rather than actual running AI automation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
create_ai_team.py:474
Finding

Generated Files Can Escape the Project Boundary Through Symlinks and Arbitrary Log Paths

Content
View full analysis

Vulnerability Details

File Location: create_ai_team.py:474-476, 557-558, 623-624, 671-672, 734-735, 849-855; error_handler.py:27-34, 84-90
Vulnerability Type: Unconfined file write and symlink-following overwrite
Risk Level: Medium

Vulnerable Code

create_ai_team.py:474-476:

python
# Create main ai-team directory
ai_team_dir = self.project_path / 'ai-team'
safe_create_directory(ai_team_dir)

create_ai_team.py:557-558:

python
with open(file_path, 'w', encoding='utf-8') as f:
    f.write(content)

create_ai_team.py:623-624:

python
with open(file_path, 'w', encoding='utf-8') as f:
    f.write(content)

create_ai_team.py:671-672:

python
with open(ai_team_dir / 'PROJECT_PROGRESS.md', 'w', encoding='utf-8') as f:
    f.write(content)

create_ai_team.py:734-735:

python
with open(ai_team_dir / 'WORKFLOW.md', 'w', encoding='utf-8') as f:
    f.write(content)

create_ai_team.py:849-855:

python
# Logging
parser.add_argument('--log-file',
                    help='Path to log file')
parser.add_argument('--verbose', '-v', action='store_true',
                    help='Enable verbose output')

args = parser.parse_args()

# Setup logging
setup_logging(args.log_file)

error_handler.py:27-34:

python
if log_file:
    logging.basicConfig(
        level=logging.INFO,
        format=log_format,
        handlers=[
            logging.FileHandler(log_file, encoding='utf-8'),
            logging.StreamHandler(sys.stdout)
        ]
    )

error_handler.py:84-90:

python
def safe_create_directory(path):
    """Safely create directory with error handling"""
    try:
        Path(path).mkdir(parents=True, exist_ok=True)
        return True
    except Exception as e:
        raise AITeamError(f"Failed to create directory {path}: {str(e)}")

Technical Analysis

...[truncated 2869 chars]

Remediation
View remediation

Remediation Suggestions

  1. Resolve the project root once with Path.resolve(strict=True) and use it as the trusted filesystem boundary.
  2. Before every directory creation or file write, resolve the destination or its nearest existing parent and verify containment with Path.relative_to(trusted_root). Reject the operation if containment fails.
  3. Reject symbolic links in every component from the project root through the final destination. Check components with Path.is_symlink() or os.lstat() rather than relying on ordinary existence checks.
  4. Open output files using no-follow semantics. On supported platforms, use os.open() with O_NOFOLLOW and appropriate creation flags, then wrap the resulting descriptor with os.fdopen().
  5. Avoid blindly overwriting existing output files. Reject unexpected pre-existing files or require explicit user confirmation before replacement.
  6. Restrict --log-file to a location beneath the resolved project root, or remove the option and use a fixed project-local log path.
  7. If external log paths are intentionally supported, clearly document the broader write scope and require explicit confirmation before opening them.
  8. Apply the same canonicalization, containment, and symlink checks to safe_create_directory() and the project-specific error-log path in handle_error().
  9. Add regression tests using symlinked directories and output files to confirm that out-of-project writes are rejected.
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module docstring states this tool is 'completely offline', suggesting a narrow local directory-generation utility. However, later code writes configuration and progress/workflow files asserting 'AI team starts running automatically', 'scheduled tasks', 'event-triggered', 'runtime logs', and named AI models like GPT-4 and Claude, which represents documentation/content implying operational AI automation beyond what the code actually performs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The fallback progress file marks automation scripts as 'deployed' and runtime logs as 'enabled', and nearby workflow content describes scheduled tasks, event-triggered operation, and progress monitoring. In reality, this script only writes local files and does not create runnable automation, schedulers, log pipelines, or active monitoring, so the embedded documentation contradicts actual behavior.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_comprehensive.py (reported line 33)May include surrounding context.

python
project_path = os.path.join(self.test_dir, "test-generic-project")
        os.makedirs(project_path)
        
        result = subprocess.run([
            "python3", self.create_ai_team_script,
            "--project-path", project_path,
            "--project-type", "generic",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code expects the skill output to be in Chinese by asserting against the literal string "AI团队创建成功". The file does not indicate that the skill is region-specific or that users can opt into this locale, which creates a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_comprehensive.py (reported line 56)May include surrounding context.

python
project_path = os.path.join(self.test_dir, "test-generic-dual-project")
        os.makedirs(project_path)
        
        result = subprocess.run([
            "python3", self.create_ai_team_script,
            "--project-path", project_path,
            "--project-type", "generic",

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_comprehensive.py (reported line 79)May include surrounding context.

python
generic_project = os.path.join(self.test_dir, "my-generic-project")
        os.makedirs(generic_project)
        
        result = subprocess.run([
            "python3", self.create_ai_team_script,
            "--project-path", generic_project,
            "--auto-detect"

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_comprehensive.py (reported line 92)May include surrounding context.

python
"""Test error handling for invalid project path"""
        invalid_path = "/nonexistent/path"
        
        result = subprocess.run([
            "python3", self.create_ai_team_script,
            "--project-path", invalid_path,
            "--project-type", "generic"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The assertion on the literal string "错误" requires Chinese-language output for failures. Without documentation or a user-selectable language setting, this is a language/locale policy violation rather than a technical necessity.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_comprehensive.py (reported line 106)May include surrounding context.

python
project_path = os.path.join(self.test_dir, "test-progress-project")
        os.makedirs(project_path)
        
        subprocess.run([
            "python3", self.create_ai_team_script,
            "--project-path", project_path,
            "--project-type", "generic",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The test requires the generated file to contain the Chinese phrase "项目进展概览", which implies the skill emits Chinese content by default. Because no opt-in or locale justification appears in this file, the hard-coded language constraint is a policy issue.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · test_dual_team.py (reported line 19)May include surrounding context.

python
print(f"Testing dual team creation for {project_type} project...")
    
    # Run the skill
    result = subprocess.run([
        "python3", "create_ai_team.py",
        "--project-path", project_path,
        "--project-type", project_type,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The translation helper defaults to 'zh', and the CLI/config logic also defaults the language to Chinese. This creates a language/locale preference without user opt-in, which matches the policy category for forced language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template appears to require Chinese as the operating language for the skill content, headings, and field labels. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown template presents all headings and role descriptions only in Chinese, which can impose a specific language on users without any visible opt-in or alternative. The policy for this audit flags language or locale constraints when no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.