Back to skill

Security audit

图解

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Mermaid diagram helper, but it asks for broad file and command powers that are not clearly limited to diagram generation.

Install only if you are comfortable granting this skill file read/write and command execution authority, or run it in a tightly sandboxed environment. For ordinary Mermaid diagram generation, prefer a version limited to producing diagram text or a narrowly scoped renderer/export tool.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:19
Finding

Excessive Tool Permissions for Diagram Generation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19–22, with supporting capability declarations at lines 115 and 202–204
Vulnerability Type: Excessive filesystem and command-execution permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec
- write

Supporting declarations:

markdown
- **Category**: MD+execute()
markdown
- **File processing**: Supports reading, parsing, and writing multiple file formats
- **API integration**: Calls external services through standardized interfaces
- **Command execution**: Executes system commands in a secure sandbox and collects results

Technical Analysis

The Skill's stated purpose is to generate Mermaid diagram source, which can ordinarily be returned directly as text without arbitrary command execution or unrestricted filesystem access. Nevertheless, the Skill requests read, write, and exec tools and advertises file processing, external API integration, and system-command execution.

No specific commands, permitted arguments, filesystem boundaries, approved network destinations, or enforcement mechanisms are defined. The document recommends command allowlisting and sandboxing elsewhere, but it does not implement or specify such controls. Consequently, the declared capability set exceeds the minimum permissions needed for the stated task and creates a least-privilege violation if the hosting Agent grants these tools.

The audited file does not contain instructions that explicitly abuse these permissions. Exploitation therefore depends on the host granting the declared tools and on attacker-controlled or misinterpreted input causing the Agent to invoke them outside the legitimate diagram-generation workflow.

Attack Path

  1. A host loads the Skill and grants the declared read, write, and exec capabilities.
  2. An attacker supplies diagram content containing adversarial instructions or content designed to be interpreted as operational Agent ins ...[truncated 1120 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove exec, read, and write from the tool declaration when the Skill only needs to produce Mermaid source as model-generated text.
  2. If image rendering is required, replace arbitrary exec access with a dedicated Mermaid-rendering tool that accepts validated diagram text and fixed rendering options.
  3. If file export is required, grant only a narrowly scoped write operation restricted to a user-approved output directory. Prevent path traversal and reject absolute or parent-relative paths.
  4. Avoid unrestricted read access. Where input files are necessary, require explicit user selection and restrict reads to those approved files.
  5. Define an enforceable command allowlist, fixed executable path, permitted arguments, execution timeout, resource limits, and a sanitized environment if command execution cannot be removed.
  6. Require user confirmation before filesystem changes, command execution, or network access.
  7. Define approved API destinations and prohibit arbitrary outbound requests.
  8. Treat all user-supplied diagram content as untrusted data and prevent it from being interpreted as tool-use instructions.
  9. Ensure that sandboxing and least-privilege controls are implemented by the host rather than merely described in documentation.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says to use the skill for broad activities such as data analysis, report generation, statistical insights, and data visualization, which are much wider than Mermaid diagram generation. It does not clearly distinguish when the skill should activate versus when a more general analytics or reporting skill should be used, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description states '支持中文交互,无需复杂配置即开即用,' which presents Chinese-language interaction as a built-in default behavior. There is no accompanying statement that users may choose another language, so this may violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill declares exec capability even though its stated purpose is only to generate Mermaid diagrams. Unnecessary command execution materially expands the attack surface because user-controlled content in a diagram-generation workflow could be routed into shell commands by an agent runtime or future implementation, enabling command injection or arbitrary local actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation advertises file processing and external API integration capabilities unrelated to simple Mermaid diagram generation, which suggests over-privileged and potentially multi-purpose behavior. This mismatch increases the chance that the skill will be invoked in broader contexts with access to local files or network resources, creating opportunities for data exfiltration, misuse of credentials, or unsafe secondary actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.