Back to skill

Security audit

图谱

Security checks for vulnerabilities and agentic risk

Overview

This Markdown-only skill is not overtly malicious, but it asks for broad read/write/command powers and its documentation conflicts with its blockchain-data purpose.

Install only if you are comfortable granting a Markdown skill broad local read/write and command-execution authority. Prefer a revised version that removes exec/write unless strictly needed, narrows file access, defines approved Graph endpoints, and aligns the output format with blockchain data routing.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:24
Finding

Overprivileged Filesystem and Command-Execution Capabilities

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–27
Vulnerability Type: Excessive tool permissions violating least privilege
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec
- write

Related capability descriptions at lines 241–243:

markdown
- **File processing**: Supports reading, parsing, and writing multiple file formats
- **API integration**: Calls external services through standardized interfaces and processes responses
- **Command execution**: Executes system commands in a secure sandbox and collects results

Technical Analysis

The Skill's declared purpose is to route blockchain data questions to appropriate Graph Protocol services. That task does not inherently require unrestricted local file reads, file writes, or system-command execution.

Nevertheless, the manifest requests the general-purpose read, write, and exec tools. The document does not specify:

  • Filesystem paths that may be accessed
  • Commands or executable binaries that may be invoked
  • An enforceable command allowlist
  • Argument-validation rules
  • Graph Protocol endpoint allowlists
  • Restrictions protecting credentials and unrelated local data

Although the document recommends sandboxing and command allowlisting at line 234, these are advisory statements rather than implemented restrictions. The resulting capability set exceeds the minimum permissions needed for API request routing.

Attack Path

  1. An Agent loads the Skill and grants its declared read, write, and exec capabilities.
  2. An attacker submits a blockchain-themed request containing a local path, crafted command argument, or instruction to process a local file.
  3. Because the Skill provides no enforceable path, command, or argument restrictions, the Agent may use the broad tools while attempting to satisfy the request.
  4. The Agent could read unrelated local information, overwrite accessible files, or run commands unrelated to Graph Protocol routing. 5 ...[truncated 1060 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove read, write, and exec from the tool declaration unless each capability is demonstrably required.
  2. Replace general-purpose tools with a narrowly scoped HTTPS or Graph Protocol API client.
  3. Allowlist specific HTTPS endpoints and reject redirects or requests to unapproved hosts.
  4. If local file access is essential, restrict it to a dedicated workspace directory, reject path traversal and symbolic-link escapes, and use read-only access where possible.
  5. If command execution is unavoidable, use a fixed executable allowlist, pass validated arguments without shell interpolation, disable shell metacharacters, and run commands in a low-privilege sandbox with network and filesystem restrictions.
  6. Prevent access to environment variables, credential stores, home-directory secrets, and unrelated project files.
  7. Define explicit input schemas for question and chain, including strict length and character constraints.
  8. Enforce output filtering so secrets, tokens, environment contents, and unrelated file data cannot be returned.
  9. Convert the advisory security statements into controls enforced by the hosting Agent or implementation.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description repeatedly says the skill should be used to 'Route any blockchain data question' and also broadly for 'data analysis, report generation, statistical insights, data visualization' without clearly defining invocation boundaries or exclusions beyond one narrow non-applicability note. This makes the trigger scope ambiguous and could cause unintended activation for many generic analytics requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description states '支持中文交互,无需复杂配置即开即用' and the document presents the skill as oriented to Chinese interaction, but it does not clearly offer a user-selectable language or explain a justified locale restriction. This can violate language/locale policy when users have not opted into Chinese-only behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is described throughout the file as routing blockchain data questions to Graph Protocol services and returning live data or service suggestions, but the documented JSON response is a code-review style grading report with fields like overall_grade, total_score, and security/compliance comments. This is an active contradiction in the documentation about what the skill returns, not just an omission or implementation detail.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file’s main description frames the skill as a blockchain data router for Graph Protocol services, but the later feature and workflow sections state broad capabilities including file reading/writing, command execution, and generic file processing. Those statements contradict the earlier intent by presenting the skill as a multipurpose automation/file/command tool rather than a Graph-focused query router.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.