Back to skill

Security audit

JavaScript开发工具

Security checks for vulnerabilities and agentic risk

Overview

This JavaScript helper is not malicious, but it asks for broad command-execution and file-write authority without clear limits or user-control rules.

Install only if you are comfortable with the agent potentially reading project files, modifying files, and running shell commands for JavaScript tasks. Prefer using it in a sandboxed project workspace, review proposed commands and edits before approval, and avoid exposing sensitive environment variables unless clearly required.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:24
Finding

Excessive Execution and File-Write Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24-27
Vulnerability Type: Excessive tool permissions violating least privilege
Risk Level: Medium

Complete Code Snippet:

yaml
tools:
  - read
  - exec
  - write

Technical Analysis

The skill declares exec and write capabilities even though its documented purpose is to review JavaScript source code and return recommendations or generated code. No documented workflow requires shell-command execution or filesystem modification.

These unnecessary capabilities increase the consequences of malicious, adversarial, or misinterpreted input. If the hosting agent grants the declared tools without an additional authorization boundary, attacker-controlled content submitted for review could influence the agent into executing commands or changing files. No explicit malicious command or automatic exploitation behavior was found in the audited file; the risk arises from the excessive permission configuration.

Attack Path

  1. The skill is loaded by an agent that grants its declared exec and write tools.
  2. An attacker supplies JavaScript or accompanying review instructions containing adversarial content.
  3. The content attempts to persuade or confuse the agent into treating shell execution or file modification as part of the review.
  4. Because the skill possesses permissions beyond those needed for analysis, the agent may invoke exec or write.
  5. Commands could run with the agent process's operating-system privileges, or files accessible to that process could be modified.

Exploitation depends on the hosting agent allowing tool use and failing to require independent authorization or enforce command and path restrictions.

Impact Assessment

Successful exploitation could permit command execution with the privileges of the agent process and modification of files writable by that process. The scope may include the current workspace ...[truncated 299 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec and write from the declared tool list; retain only read if repository inspection is required.
  2. If future functionality legitimately needs file changes, require explicit user confirmation for each write and constrain writes to an approved workspace.
  3. If execution is later required, use a sandbox with a strict command allowlist, limited filesystem access, no inherited secrets, restricted network access, resource limits, and a non-privileged operating-system identity.
  4. Treat reviewed source code and user-supplied instructions as untrusted data rather than executable agent directives.
  5. Record and expose all command and file-modification operations for user review.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The claim that risky code and external dependencies were cleaned up creates a false sense of safety while the skill still advertises risky primitives like exec and environment-based API key handling elsewhere. Such contradictory assurances are dangerous because they may cause users or agents to trust the skill more than warranted and overlook its ability to execute commands or interact with secrets.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is presented as a JavaScript coding/review assistant, but its declared capabilities include generic file read/write and command execution, which materially expand what the agent can do beyond the stated purpose. That mismatch increases the chance of prompt-driven abuse, unintended shell access, or filesystem modification under the guise of routine code assistance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest exposes write and exec capabilities without an upfront, prominent warning that the skill may modify files or run system commands. In an agent setting, weak disclosure makes dangerous actions more likely to occur without informed consent, especially when users expect only passive JavaScript assistance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Command execution is a high-risk capability and is not justified by the stated use case of writing/reviewing JavaScript code in this manifest. If exposed to untrusted user input or over-broad instructions, it could be used to run arbitrary commands, access secrets, modify the environment, or pivot beyond code analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill presents user-facing fields such as displayName and summaries in a mixed Chinese/English form, and the document continues with substantial Chinese-language content. This can impose a language/locale experience on users without any explicit opt-in or stated language selection behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.