Back to skill

Security audit

节点

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a connection-diagnostics helper, but it asks for broad read, write, and command-execution authority without clear boundaries.

Review this skill before installing. It is not clearly malicious, but only use it in a sandboxed agent session where file access, writes, and command execution are restricted to the specific logs, configs, and diagnostic commands needed for SkillHub node troubleshooting.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:15
Finding

Unscoped High-Privilege Tool Access

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15–18
Vulnerability Type: Excessive and unrestricted tool permissions
Risk Level: Medium

yaml
tools:
  - read
  - exec
  - write

Technical Analysis

The Skill requests filesystem reading, arbitrary command execution, and filesystem writing. Its documented connection-diagnostic workflow does not demonstrate a legitimate need for unrestricted write access and does not define enforceable restrictions for readable paths, writable paths, executable commands, or command arguments.

Although the document recommends sandboxing and command allowlisting, those controls exist only as advisory prose. No actual allowlist, path boundary, argument validation policy, or sandbox configuration is included. Granting all three tools therefore violates the principle of least privilege.

The reviewed project contains no executable scripts or direct malicious command instructions. This finding concerns the permissions exposed to the Skill rather than confirmed malicious execution.

Attack Path

  1. An Agent loads SKILL.md and grants the declared read, exec, and write capabilities.
  2. A user supplies untrusted troubleshooting content, logs, configuration data, or diagnostic parameters.
  3. That content influences the Skill's diagnostic actions or command selection.
  4. Because no enforceable path or command restrictions are specified, the Skill can potentially read unrelated files, execute commands outside the diagnostic scope, or modify filesystem contents.
  5. The resulting access may extend beyond what is legitimately required to diagnose node connectivity.

Impact Assessment

Successful abuse could obtain the privileges made available by the hosting Agent:

  • Read access to unrelated files available to the Agent process.
  • Execution of local commands with the Agent process's operating-system privileges.
  • Creation, modification, or deletion ...[truncated 469 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the write capability unless the Skill has a documented requirement to generate a specific output artifact.
  2. Replace unrestricted exec access with an enforceable allowlist containing only the fixed diagnostic commands required for supported platforms.
  3. Validate command arguments against strict schemas and never concatenate untrusted user input, logs, paths, hostnames, or configuration values into shell commands.
  4. Restrict read access to explicitly approved diagnostic files and directories.
  5. If writing is necessary, restrict it to a dedicated output directory and prevent path traversal, symbolic-link following, and overwriting of existing sensitive files.
  6. Run diagnostic commands in a sandbox with minimal operating-system privileges, no unnecessary network access, and explicit resource limits.
  7. Convert prose-only safeguards into enforceable Agent or tool configuration.
  8. Document the exact commands, paths, inputs, outputs, and permissions needed by each diagnostic step so that undeclared access is denied by default.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill manifest presents a narrowly scoped node-connection diagnostic tool, but the body expands its role into generic file handling, API integration, and command execution. This scope inflation weakens least-privilege expectations and can cause an agent or user to authorize broad capabilities under the guise of a benign troubleshooting skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises system command execution despite being framed as a node-connection diagnostic helper, and the file does not define strict command boundaries. In an agent ecosystem, generic exec access can be repurposed for arbitrary local actions, privilege abuse, or data access far beyond the declared use case.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description mixes node diagnostics with broad API integration, webhook configuration, and general system connectivity scenarios, making activation scope ambiguous. Overbroad routing increases the likelihood that the skill is invoked in contexts where its powerful tools (read/write/exec) are unnecessary, expanding exposure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

L194-L195 state that the skill's configuration is fixed and does not support user customization. This directly conflicts with the documented input parameters at L057-L063 and setup/configuration sections that expose selectable mode, retry counts, skipped steps, and API-key/environment configuration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document claims only whitelisted commands are executed and that user input is not concatenated, but it provides no mechanism showing those controls are real. Unsupported security assurances are dangerous because they encourage trust in exec behavior that may in practice accept broader or unsafe command patterns.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill promotes broad file read/parse/write behavior not clearly tied to node-pairing diagnosis. Unnecessary file access increases the chance of reading sensitive local data or overwriting files when a user expects only connection troubleshooting behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The summary fields combine Chinese and English text directly, and the document continues with mixed-language instructions. This can impose a language/locale experience without explicit user opt-in or a documented language-selection mechanism.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.