Back to skill

Security audit

Kiri Engine

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for KIRI Engine 3D scanning, but its image upload path can unintentionally send non-image local files to the external service if a wildcard or file path is used incorrectly.

Install only if you are comfortable sending the selected media to KIRI Engine. Use dedicated folders or explicit image-only wildcards, avoid broad wildcards, do not point the image option at mixed project folders, and treat the stored API key file as a secret. Review downloaded ZIP contents before using extracted files in another workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/kiri-engine.ps1:182
Finding

Incomplete image-path validation can upload unintended files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/kiri-engine.ps1:43
Finding

API credential is stored in an unencrypted profile file without enforced restrictive permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README advertises automatic download and extraction of ZIP assets to a user-specified directory but does not warn about local file creation, overwrite behavior, or archive extraction risks. In a skill that retrieves remote content from an external service, silent extraction can lead to unexpected filesystem changes and, depending on implementation, could expose users to overwrite or path traversal issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented workflow instructs users to upload local videos and image sets to a remote API, but the README does not clearly and prominently warn that potentially sensitive local media will leave the device and be processed by a third party. This can cause unintentional disclosure of private or regulated content, especially because the skill is centered around local media processing.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 131)May include surrounding context.

md
## API 文档

- Base URL: `https://api.kiriengine.app/api/`
- 官方文档: https://gentlebandit.feishu.cn/wiki/PsHawWV0gi2jePkmRoycwMwXnIc

## License

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
## API 文档

- Base URL: `https://api.kiriengine.app/api/`
- 官方文档: https://gentlebandit.feishu.cn/wiki/PsHawWV0gi2jePkmRoycwMwXnIc

## License

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This script is designed to transmit local videos, image sets, API credentials, and task identifiers to an external third-party service at api.kiriengine.app. In the context of an agent skill, that is a real data exfiltration surface because local user files are uploaded off-host and later a remote archive is downloaded and extracted, so compromise, misuse, or unexpected content from the service could affect confidentiality and downstream safety.

Content

Scanner excerpt · scripts/kiri-engine.ps1 (reported line 49)May include surrounding context.

text
)

$ConfigPath = Join-Path $env:USERPROFILE '.kiri-engine-config.json'
$BaseUrl = 'https://api.kiriengine.app/api/v1/open'

# ── 读取 API Key ──────────────────────────────────────────
function Get-ApiKey {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The download workflow does more than fetch a model: it automatically extracts the downloaded ZIP into a directory and then deletes the original archive. While the code prints progress messages during execution, the top-level synopsis/description does not warn users that running the download action will write files, unpack content, and remove the ZIP, which is a material filesystem side effect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language instructions and operational guidance are presented exclusively in Chinese. Under the language/locale policy, forcing a single language without opt-in or justification can be a policy issue because users are not offered a language choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The user-facing synopsis, description, and parameter help are entirely in Chinese, which effectively forces a specific language for interaction and documentation. There is no opt-in, alternate locale, or documented justification that this skill is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.