Back to skill

Security audit

CNC Quote System

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local CNC quoting demo, but it substantially overstates its RAG, accuracy, material coverage, and risk-control capabilities, so it should be reviewed before business use.

Review this carefully before installing for real quoting work. It appears to be a small local prototype rather than the production RAG quoting system it advertises; do not rely on its prices, accuracy, material coverage, or risk labels without validation. Install only in an isolated environment with pinned dependencies, and add input validation and clear language/scope documentation before operational use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:2
Finding

Mutable and Unverified Third-Party Dependencies

Content
View full analysis
=1.7.4 numpy>=1.21.0 pandas>=1.3.0 ``` The documented installation command is: ```bash pip install -r requirements.txt ``` ### Technical Analysis All dependencies use open-ended minimum-version constraints. Consequently, installation may resolve to any future compatible release rather than a specific version that has been reviewed and tested. No lock file or package hashes are supplied to authenticate downloaded artifacts. Python package installation can execute package build and installation logic. If an allowed dependency release or its distribution channel is compromised, following the documented installation procedure could execute attacker-controlled code. The `pandas` dependency is not imported by any audited Python module, so it unnecessarily expands the supply-chain attack surface. This finding does not establish that any currently listed package is malicious. It identifies an unsafe dependency-management practice that creates exposure to future upstream compromise. ### Attack Path 1. An attacker compromises an upstream package account, release process, or distribution artifact for one of the dependencies. 2. The attacker publishes a malicious version satisfying the open-ended `>=` constraint. 3. A user follows the installation instructions in `SKILL.md`. 4. `pip` resolves and downloads the malicious release because no exact version or trusted hash is required. 5. Malicious build or installation code executes with the permissions of the user running `pip`. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the privileges of the installing user. The resulting scope could include access to files, environment variables, credentials, and network resour ...[truncated 204 chars]
Remediation
View remediation
=`. 3. Generate and commit a reproducible lock file for the supported Python environment. 4. Record trusted hashes and install with hash enforcement, such as `pip install --require-hashes`. 5. Perform dependency vulnerability and provenance scanning in CI. 6. Install dependencies in an isolated, least-privileged virtual environment rather than as an administrative user. 7. Review and deliberately update locked dependencies on a controlled schedule. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
cnc_quote_engine.py:78
Finding

Unvalidated Dimensions and Quantity Permit Invalid Quotes and Processing Failures

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
case_retriever.py:127
Finding

Zero-Volume Dimensions Cause Division by Zero During Case Matching

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
risk_control.py:87
Finding

Zero Average Historical Price Causes Risk-Assessment Failure

Content
View full analysis
0: avg_price = sum(historical_prices) / len(historical_prices) deviation = abs(unit_price - avg_price) / avg_price if deviation > self.thresholds["price_deviation"]: ``` ### Technical Analysis The code verifies only that the historical-price list is nonempty. It does not ensure that its elements are numeric, finite, or positive. A list whose average is zero, such as `[0]` or `[-10, 10]`, causes division by zero when calculating price deviation. Non-finite values can also propagate through the calculation and undermine risk classification. Because historical prices may originate from external records or caller-provided data, the method should treat them as untrusted business inputs. ### Attack Path 1. A caller supplies a nonempty historical-price list whose arithmetic mean is zero. 2. `RiskController.assess()` computes `avg_price` as zero. 3. The deviation formula divides by `avg_price`. 4. An unhandled `ZeroDivisionError` terminates risk assessment. 5. The quote workflow loses its expected risk report and may fail entirely if the exception is not isolated. ### Impact Assessment The vulnerability grants no additional privileges. It affects availability and integrity of the risk-assessment stage. A malformed history list can suppress completion of safety checks, interrupt quote generation, or repeatedly cause request failures in a service deployment. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The skill description materially overstates its capabilities by claiming RAG-based retrieval, material knowledge lookup, and robust risk warning, while the implementation reportedly uses only hardcoded data and a minimal low-price check. This mismatch is dangerous because users or downstream agents may rely on the tool for pricing and safety/risk decisions under false assumptions, leading to incorrect quotes, missed risk conditions, or unsafe automation decisions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises code-backed functionality and references local files/modules, but it does not declare any explicit tool scope such as permissions or allowed-tools. In an agent environment, missing scope boundaries can allow broader-than-intended file access or make reviewers unable to verify what filesystem capabilities the skill requires, increasing the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents its title in Chinese ("案例检索器") and later uses Chinese user-facing output and docstrings, but there is no indication that the skill supports multiple languages or that Chinese is a justified fixed locale. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The printed output shown to users is hardcoded in Chinese, including the summary label and tagline, and the code does not offer any locale selection. This can violate language policy when users are forced into a specific language without consent or configuration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This Python file uses natural-language descriptions in Chinese in the module docstring and throughout user-facing output, with no indication that language selection is optional or configurable. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The main entrypoint prints all user-visible results in Chinese, and the file provides no mechanism for choosing another language or confirming the user's preferred locale. This creates a language policy issue because the skill implicitly forces Chinese output on all users.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are generic manufacturing/quoting terms and lack clear scope constraints, so the skill could activate for loosely related requests and intercept conversations unintentionally. In an agent-worker context, overbroad activation can cause unnecessary retrieval, quoting actions, or context exposure even if the skill itself is not overtly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This markdown file uses Chinese throughout the skill title, section headings, and descriptions, but does not indicate that the skill is Chinese-only or provide any user opt-in for language/locale. Under the policy for natural-language violations, forcing a specific language without user choice can be a locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The docstrings and most user-facing descriptions are written in Chinese, while some labels and output remain in English, and the file does not state any user-selectable language preference. Under the policy rule for language/locale constraints, this effectively fixes the skill’s interaction language without an explicit opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This requirements file contains natural-language comments only in Chinese (e.g. '核心依赖', '可选依赖', '向量嵌入(可选)'). Under the policy, a skill should not force a specific language or locale without opt-in or a clearly documented justification, and no such justification appears here.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Using an open-ended version specifier for faiss-cpu allows future builds to resolve to different releases, which weakens reproducibility and can silently introduce vulnerable or malicious upstream versions. In a RAG-based quoting system, this could affect indexing and retrieval components in production without code changes in the repository.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
# 核心依赖
faiss-cpu>=1.7.4
numpy>=1.21.0
pandas>=1.3.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The unpinned numpy dependency means installations may pull different versions over time, making it impossible to guarantee that deployed environments avoid known vulnerable releases. Because numpy is a foundational package used widely by data-processing code, an unsafe version could expose memory-safety or file-handling flaws inherited by the application.

Content

Scanner excerpt · requirements.txt (reported line 3)May include surrounding context.

text
# 核心依赖
faiss-cpu>=1.7.4
numpy>=1.21.0
pandas>=1.3.0

# 可选依赖

Unverifiable Dependency: numpy has 16 known advisory(ies) (CVE-2014-1859 (Numpy arbitrary file write via symlink attack); CVE-2021-41495 (NumPy NULL Pointer Dereference); CVE-2021-33430 (NumPy Buffer Overflow (Disputed)) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The manifest references numpy without pinning to a known-safe release, while known advisories exist for some numpy versions. This does not prove the project is currently vulnerable to a specific CVE, but it is a real supply-chain risk because the installed version cannot be verified from the manifest.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The unpinned pandas requirement permits non-deterministic installs and may allow deployment of versions affected by known advisories. In a quoting system handling tabular cost and material data, a vulnerable or compromised pandas release could affect data ingestion and processing paths.

Content

Scanner excerpt · requirements.txt (reported line 4)May include surrounding context.

text
# 核心依赖
faiss-cpu>=1.7.4
numpy>=1.21.0
pandas>=1.3.0

# 可选依赖
# ollama>=0.1.0  # 向量嵌入(可选)

Unverifiable Dependency: pandas has 1 known advisory(ies) (CVE-2020-13091 (** DISPUTED ** pandas through 1.0.3 can unserialize and execute commands from an)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The pandas dependency is not pinned, so the project cannot demonstrate that deployed installations avoid versions with known advisories. Although the cited advisory may be disputed and exploitability depends on application behavior, the inability to verify a safe version is still a legitimate dependency-management weakness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code prints all user-facing runtime output in Chinese, including the final status text, with no indication that another language can be selected. Because SQP-3 applies to all file types and covers language or locale policy violations, this is a natural-language policy issue when users are not given an opt-in or choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.