T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:53- Finding
Incorrect Unit Conversion Produces Solid Quantities 1,000 Times Too Large
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local lab buffer calculator, but its core recipe calculations are badly wrong and its declared file/tool permissions are broader than its documentation admits.
Review before installing or using in a lab. Do not rely on its recipe outputs without independent verification, and prefer a corrected version with fixed unit conversions, explicit reagent forms, input validation, and narrower tool permissions.
scripts/main.py:53Incorrect Unit Conversion Produces Solid Quantities 1,000 Times Too Large
scripts/main.py:25Ambiguous Reagent Forms and Percentage Units Can Generate Incorrect Chemical Instructions
scripts/main.py:43Unvalidated Numeric Inputs Permit Negative, Non-Finite, and Unrealistic Recipes
SKILL.md:4Skill Declares Filesystem and Command Capabilities Beyond Its Functional Requirements
Suspicious Unicode normalization or mixed-script content
The skill claims 'No file access' and presents a low-risk profile, but the manifest explicitly allows Write/Edit/Bash and the documentation describes creation of output files. This mismatch can mislead users or downstream policy systems into granting too much trust, increasing the chance that file-modifying behavior is used without appropriate scrutiny or restrictions.
The natural-language labels "上游" and "下游" introduce a locale-specific element in the skill description, but the document does not indicate that multilingual output is optional or user-selected. This can conflict with a language/locale policy requiring user opt-in before forcing a specific language.
No suspicious patterns detected.