Back to skill

Security audit

JSON数据处理工具

Security checks for vulnerabilities and agentic risk

Overview

The skill is a JSON utility, but it asks for shell execution and suggests administrator use without enough limits, so it should be reviewed before installation.

Install only if you are comfortable granting this skill command execution in the agent environment. Prefer running it in a low-privilege sandbox and avoid administrator sessions; treat all JSON/text/Markdown inputs as untrusted and do not provide broad API keys or sensitive files unless necessary.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:30
Finding

Unnecessary Arbitrary Command-Execution Capability

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 30-34 and 141-143
Vulnerability Type: Excessive tool permissions
Risk Level: Medium

Vulnerable Configuration

yaml
tools:
  - read
  - exec
  - write

The skill is additionally classified as an execution-enabled Markdown skill:

markdown
- **Category**: MD+execute()

Technical Analysis

The skill is documented as a JSON parsing, cleaning, transformation, validation, and export utility. These functions may require file-reading and file-writing capabilities, but the document does not define a concrete operation that requires unrestricted command execution.

Declaring the exec tool gives the skill authority beyond its documented functional requirements and violates the principle of least privilege. This is particularly risky when the skill processes attacker-controlled JSON, text, Markdown, file paths, or processing instructions. If such input is interpreted as agent instructions rather than inert data, the unnecessary execution capability can provide a path from untrusted content to local command execution.

The audited package contains no script implementing a direct command-injection payload. Exploitation therefore depends on the hosting agent allowing the skill to invoke its declared tools and on attacker-controlled content influencing tool selection or command arguments.

Attack Path

  1. A user loads the JSON-processing skill in an agent that grants the tools declared in SKILL.md.
  2. The agent grants the skill access to read, write, and exec.
  3. An attacker supplies crafted JSON, Markdown, processing instructions, or a malicious data file.
  4. The crafted content induces the agent to treat embedded instructions as operational directions.
  5. The agent invokes exec, despite command execution not being necessary for JSON processing.
  6. Commands run with the permissions of the agent process and can access res ...[truncated 627 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the declared tool list unless a specific, indispensable command-execution use case is documented.
  2. Change the skill classification from MD+execute() to a non-executing skill classification.
  3. Implement JSON processing through native, structured agent operations rather than shell commands.
  4. If execution is genuinely required, define a narrow allowlist of permitted executables and subcommands.
  5. Pass arguments as structured values rather than constructing shell command strings.
  6. Reject shell metacharacters and untrusted executable paths.
  7. Run permitted commands in a restricted sandbox with no network access and minimal filesystem access.
  8. Require explicit user confirmation before every execution request.
  9. Treat all processed JSON, text, and Markdown as untrusted data and prevent it from being interpreted as skill instructions.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:232
Finding

Generic Recommendation to Run the Agent with Administrator Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 232
Vulnerability Type: Unsafe privilege-escalation guidance
Risk Level: Medium

Vulnerable Documentation

The source troubleshooting entry states, translated into English:

markdown
| Insufficient permissions | The current user lacks read/write permissions | Check file permissions and run as administrator |

Technical Analysis

The troubleshooting guidance recommends running as an administrator whenever the current user lacks file read or write permissions. This is an overly broad response to a narrowly scoped filesystem permission problem.

Administrator execution grants the entire agent process—and every capability available to it—substantially greater access. This is especially dangerous because the same skill declares the exec tool. Rather than correcting ownership or access controls for one required input or output path, the recommendation can elevate unrelated operations and untrusted instructions.

The documented instruction does not itself perform privilege escalation automatically. Exploitation requires a user or operator to follow the recommendation and restart or rerun the execution-capable agent with elevated privileges.

Attack Path

  1. An attacker-controlled input or processing request causes the skill to access a path unavailable to the current user.
  2. The operation fails with a permission error.
  3. The operator follows the troubleshooting documentation and reruns the agent as an administrator or equivalent privileged account.
  4. The skill retains its declared command-execution capability in the elevated session.
  5. Malicious or incorrectly interpreted input causes the agent to invoke a command or access a sensitive path.
  6. The operation runs with administrator privileges rather than the limited permissions originally available to the agent.

Impact Assessment

If the recommendation is followed, affected operat ...[truncated 547 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to run the agent as an administrator.
  2. Advise users to identify the exact file or directory for which access is required.
  3. Correct ownership and grant only the minimum read or write permission needed for that specific path.
  4. Use a dedicated, non-privileged workspace for input and output files.
  5. Refuse access to system directories and paths outside the approved workspace.
  6. Run the agent under a dedicated low-privilege operating-system account.
  7. If elevated access is unavoidable, isolate the operation, require explicit confirmation, remove command-execution access, and drop privileges immediately afterward.
  8. Add documentation warning users never to run the complete agent session as an administrator merely to resolve a file-access error.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill advertises generic exec access even though its stated purpose is JSON processing, API integration, and serialization, which do not inherently require arbitrary shell execution. In an agent setting, exposing exec broadens the attack surface substantially: prompt-influenced inputs or malformed workflow steps could trigger filesystem access, secret exfiltration, or execution of destructive commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The display name and summary are presented primarily in Chinese, and the rest of the document continues in Chinese without stating that users may choose another language. This creates a locale/language default that is not documented as optional or region-specific, which matches the language-policy concern for natural-language policy violations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims command execution is limited to a whitelist, but the manifest exposes a generic exec capability and this file provides no enforceable allowlist, wrapper, or validation details. That mismatch can cause operators or downstream agents to trust unsafe execution paths, increasing the risk of arbitrary shell command use under the false assumption that controls exist.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.