Back to skill

Security audit

Java代码

Security checks for vulnerabilities and agentic risk

Overview

This Java review skill is not clearly malicious, but it asks for command execution and file-writing authority while giving broad development and deployment-oriented activation language.

Install only if you are comfortable granting a Java review assistant command execution and file-writing ability. Use it in a sandboxed repository, avoid exposing unrelated files or credentials, and review any command execution or generated file changes before trusting the output.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:19
Finding

Excessive Execution and Write Permissions Violate Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:19-24
Vulnerability Type: Excessive agent tool permissions
Risk Level: Medium

Vulnerable Configuration:

yaml
tools:
- read
- exec
- write
- glob
- grep

Technical Analysis

The skill is intended to perform static review of Java source files and Git diffs. This workflow ordinarily requires only repository reading and searching through tools such as read, glob, and grep.

The configuration additionally grants exec and write capabilities without defining command allowlists, path restrictions, user-confirmation requirements, or other authorization boundaries. These capabilities exceed the minimum privileges required for static code review. In particular:

  • exec can permit operating-system command execution under the privileges of the agent process.
  • write can permit modification or creation of files accessible to the agent process.
  • The skill does not limit these operations to a designated repository or report-output directory.
  • The skill does not require explicit approval before invoking privileged tools.

This excessive authority creates a privilege boundary violation. When reviewing attacker-controlled source code, comments, diffs, or documentation, adversarial content could attempt to influence the agent into invoking these tools for actions unrelated to code review.

No instructions in the audited file explicitly direct the agent to perform malicious command execution or file modification. Exploitation therefore depends on the hosting agent making the declared tools available and being susceptible to instructions embedded in untrusted review material.

Attack Path

  1. A user loads the skill in an agent environment that enables every tool declared in SKILL.md.
  2. The user asks the skill to review an attacker-controlled Java repository, source file, or Git diff.
  3. The supplied material contains adversarial inst ...[truncated 1371 chars]
Remediation
View remediation

Remediation Suggestions

Apply least privilege to the skill configuration:

  1. Remove exec and write from the default tool list. Retain only the read-oriented tools required for static review:
    yaml
    tools:
    - read
    - glob
    - grep
    
  2. If Git inspection requires command execution, expose only narrowly allowlisted, read-only operations such as git diff, git show, and git status.
  3. Prohibit shell interpretation, command chaining, redirection, substitutions, and arbitrary executable paths.
  4. Require explicit user confirmation before any command execution or filesystem modification.
  5. If report creation requires write, restrict it to a dedicated output directory and prevent overwriting existing source or configuration files.
  6. Constrain all file access to the repository root after canonicalizing paths and rejecting traversal, symlink escapes, and absolute paths outside the workspace.
  7. Treat source code, comments, diffs, and repository documentation as untrusted data rather than agent instructions.
  8. Run the skill in a sandbox with minimal operating-system permissions, no unnecessary credentials, and no network access unless explicitly required.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The listed scenarios suggest multiple use cases, but the boundaries for when the skill should or should not activate are not clearly defined. Ambiguous scope can lead to accidental invocation in workflows that involve repository operations or broader development actions beyond safe code review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the skill as a Java code review report generator, but the description broadens it into generic code generation, debugging, testing, and deployment assistance. That mismatch can cause over-activation in unrelated development contexts, giving a more privileged skill access in situations where a narrower reviewer skill should not run.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation text is overly broad, including common development scenarios such as code generation and programming assistance. Broad triggers increase the probability this skill is selected for routine requests, exposing users and systems to tools and behaviors that exceed the minimum needed for the task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description states '支持中文交互' and the display name is also localized, but the file does not offer an explicit user opt-in or alternative language choice. This can violate language/locale policy when a skill defaults users into a specific language experience without choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill declares the exec tool and also documents command-execution workflows, even though its stated purpose is generating Java code review reports. This expands the skill from passive analysis into active system interaction, increasing the chance that untrusted repository content or user-supplied paths could trigger unnecessary command execution and expose the host environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.