Back to skill

Security audit

ontology

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for ontology modeling, but it needs Review because it can bulk-read business documents, save raw source content locally, and generate an injection-prone HTML visualization.

Install only if you are comfortable with the skill reading the specific Feishu or local documents you provide and saving a full raw-source copy under ontology/. Avoid pointing it at broad folders containing unrelated confidential data, delete raw_source files when no longer needed, and treat generated HTML visualizations as untrusted if the source documents came from other people.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
reference/visualization-template.html:226
Finding

DOM-Based Cross-Site Scripting in Generated Ontology Visualizations

Content
View full analysis

Vulnerability Details

File Location: reference/visualization-template.html, lines 226–235
Vulnerability Type: DOM-based cross-site scripting through unsafe innerHTML construction
Risk Level: High

Vulnerable Code

javascript
function showDetail(node) {
  const st = TYPE_STYLE[node.type];
  document.getElementById("hint")?.remove();
  document.getElementById("detail").innerHTML = `
    <div id="detail-name">${node.label.replace(/\n/g, " ")}</div>
    <span id="detail-tag" style="background:${st.fill};color:${st.text};border:1px solid ${st.stroke}">${st.label}</span>
    <div id="detail-desc">${node.desc || ""}</div>
    <div>${(node.props || []).map(p => `<div class="prop-row">${p}</div>`).join("")}</div>
  `;
}

The associated generation workflow is described in SKILL.md, where graph content can be extracted from local or Feishu documents and inserted into the visualization template.

Technical Analysis

The function inserts node.label, node.desc, and every entry in node.props directly into an HTML string assigned to innerHTML. These fields are not HTML-escaped or sanitized.

Because the skill instructs the agent to derive ontology graph data from user-selected documents, these graph fields may contain document-controlled content. If a document contains an HTML payload, that payload can become active markup when the generated visualization renders a node's details.

For example, a node description containing an element with an event handler could execute JavaScript after the node is selected:

html
<img src=x onerror="alert(document.domain)">

There is also a related embedding risk when replacing the template's GRAPH object. If values are inserted into JavaScript source without robust JSON serialization, specially crafted quotes, backslashes, closing script tags, or Unicode line separators could break out of the intended string context. The reviewed files do not define a safe serialization procedure.

Att

...[truncated 1487 chars]

Remediation
View remediation

Remediation Suggestions

  1. Eliminate innerHTML for all document-derived graph values. Construct elements using document.createElement() and assign untrusted strings through textContent.
javascript
function showDetail(node) {
  const st = TYPE_STYLE[node.type];
  const detail = document.getElementById("detail");
  detail.replaceChildren();

  const name = document.createElement("div");
  name.id = "detail-name";
  name.textContent = String(node.label || "").replace(/\n/g, " ");
  detail.appendChild(name);

  const tag = document.createElement("span");
  tag.id = "detail-tag";
  tag.textContent = st.label;
  tag.style.background = st.fill;
  tag.style.color = st.text;
  tag.style.border = `1px solid ${st.stroke}`;
  detail.appendChild(tag);

  const description = document.createElement("div");
  description.id = "detail-desc";
  description.textContent = String(node.desc || "");
  detail.appendChild(description);

  const properties = document.createElement("div");
  for (const property of node.props || []) {
    const row = document.createElement("div");
    row.className = "prop-row";
    row.textContent = String(property);
    properties.appendChild(row);
  }
  detail.appendChild(properties);
}
  1. If rich HTML is a strict requirement, sanitize it with a well-maintained allowlist sanitizer. Disallow scripts, event-handler attributes, dangerous URL schemes, SVG active content, and unsafe style constructs.

  2. Generate GRAPH using a proper JSON serializer rather than manual string interpolation. Before embedding serialized JSON in a script element, escape at least <, U+2028, and U+2029 to prevent script-context breakout.

  3. Prefer storing graph data in an application/json script block and parse it with JSON.parse, while still safely escaping closing script sequences.

  4. Validate graph structure before rendering:

    • Require known node types.
    • Coerce labels, descriptions, and properties to strings.
    • Reject unexpected object values ...[truncated 451 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
可视化时:基于 `reference/visualization-template.html` 生成交互 HTML,保存到 `ontology/concept_visualization.html`,告知用户用浏览器打开。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 119)May include surrounding context.

md
可视化时:基于 `reference/visualization-template.html` 生成交互 HTML,保存到 `ontology/concept_visualization.html`,告知用户用浏览器打开。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents the operational instructions almost entirely in Chinese and does not tell the agent to match the user's preferred language or offer a locale choice. Under the policy, a fixed language or locale without opt-in is a natural-language policy concern unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages reading Feishu links, folders, local files, PDFs, and images without any user-facing privacy notice or confirmation that the content may be sensitive. In this context, document ingestion can expose confidential enterprise data, so failing to warn or confirm scope increases the risk of over-collection and accidental processing of sensitive materials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs saving full raw document contents to a local file before processing, but does not require obtaining user consent, minimizing collected data, or warning about retention risks. Because the skill handles Feishu documents, local files, PDFs, and images that may contain sensitive business information, this creates unnecessary data persistence and expands exposure beyond the immediate modeling task.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Persisting full raw document contents before processing retains potentially sensitive user-provided data beyond the immediate task and enables later reuse or unintended disclosure. The danger is heightened here because the skill is designed to ingest business documents from Feishu and local storage, which commonly contain proprietary or personal information unrelated to ontology extraction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s instructional content is entirely in Chinese, beginning with the title on L01 and continuing throughout, with no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire markdown file is written in Chinese, including the title and all operational guidance, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents the skill guidance entirely in Chinese, including the title and all instructional content, with no indication that the user can choose another language or that the skill is intentionally region-specific. That can violate language/locale policy because it forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document sets lang="zh", and the visible interface text is also entirely in Chinese, which indicates a fixed language choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains all user-facing instructions and descriptions in Chinese, and there is no indication that the user can opt into another language or that the skill is intentionally region-specific. Under the language/locale policy check, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructional content in Chinese and does not offer an opt-in, alternative language, or a documented region-specific justification, which can amount to forcing a specific language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.