Back to skill

Security audit

UniSkill V4

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an AI decision-helper purpose, but it includes under-scoped prompt logging guidance, broad activation, release automation that can alter Git state, and overstated safety/model claims.

Review before installing or integrating. Do not run the release script in a real repository unless you intend to initialize, stage, commit, and tag the whole directory. If you use the integration guide, remove or redact raw prompt logging, and treat debate results as heuristic unless real model calls and resource limits are implemented.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
INTEGRATION.md:44
Finding

Unredacted User Prompts May Be Persisted in Plaintext Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
orchestrator_v4.py:62
Finding

Memory Limit Is Not Correctly Measured or Enforced

Content
View full analysis
bool: """Memory safety check""" import psutil mem = psutil.virtual_memory() used_mb = mem.used / 1024 / 1024 self.stats["memory_peaks"].append(used_mb) return used_mb < self.memory_limit * 1024 # Convert to MB def _gc_if_needed(self): """Force GC when necessary""" if not self._check_memory(): gc.collect() ``` The related tests verify only that the configured value is stored: ```python def test_orchestrator_memory_limit(self): """Test orchestrator memory limit""" orch = UniSkillOrchestratorV4(memory_limit_mb=100) assert orch.memory_limit == 100 ``` ### Technical Analysis The memory control has three independent weaknesses: 1. `psutil.virtual_memory().used` measures aggregate system memory usage rather than memory consumed by the current process. 2. `used_mb` is already expressed in MiB, but it is compared with `self.memory_limit * 1024`. A configured limit of 100 MiB therefore becomes a threshold of 102,400 MiB, approximately 100 GiB. 3. When the threshold is exceeded, the code merely requests garbage collection. It does not reject input, cancel work, raise an exception, or otherwise enforce a hard limit. Consequently, the documented memory-safety guarantee is not implemented. The `HighSpeedDebater` also stores a `max_memory` setting without using it to limit debate workloads. An untrusted caller able to provide a very large number of candidate solutions or issue repeated large requests may cause lists, task collections, score dictionaries, and input objects to consume increasing memory without being stopped by the configured limit. ### Attack Path 1. An application exposes the orchestrator or debate API to an untrusted or insufficiently rate-limited caller. 2. The caller su ...[truncated 1213 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (37)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · INTEGRATION.md (reported line 29)May include surrounding context.

python
if score < 0.7:
    # 追问
    return prompt
else:
    # 执行
    execute_task(user_input)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill’s true behavior includes Git initialization, staging, commits, identity changes, or release-tag workflows while the description only presents a lightweight reasoning framework, users and host agents may authorize it under false assumptions. That mismatch is dangerous because repository-modifying actions can alter local state, capture unrelated files into commits, and trigger downstream release or deployment processes unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

If the skill’s true behavior includes Git initialization, staging, commits, identity changes, or release-tag workflows while the description only presents a lightweight reasoning framework, users and host agents may authorize it under false assumptions. That mismatch is dangerous because repository-modifying actions can alter local state, capture unrelated files into commits, and trigger downstream release or deployment processes unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example logging block records raw user_input directly along with model and token metadata, with no minimization, redaction, consent, or retention guidance. In an agent framework, user input may contain credentials, personal data, proprietary prompts, or regulated information, so this creates a realistic privacy and data-exposure risk if logs are accessed, exported, or reused.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
77% confidence
Finding

The skill advertises executable/code-like usage but does not declare any explicit tool scope or permissions boundary, which creates ambiguity about what file access is expected or allowed. In agent environments, undeclared capabilities can lead to over-privileged execution, accidental file disclosure, or reviewers/users misunderstanding the skill’s operational reach.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language instructions and examples are entirely in Chinese, including the trigger phrases users are expected to say, with no indication that other languages are supported or that Chinese is a required, justified locale. This can violate language/locale policy when the skill effectively constrains interaction language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad everyday expressions like evaluation and comparison requests, making accidental activation likely in unrelated conversations. Over-broad triggering can cause the skill to seize control outside its intended scope, inject unsolicited workflow logic, or interfere with safer/default agent behavior in contexts where users did not intend to invoke it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains natural-language strings such as problem labels and output text in Chinese, and there is no indication that the skill is intentionally region-specific or that users can opt into another language. That creates a language/locale policy concern because the skill effectively forces a specific language in its interface and example usage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's natural-language examples, prompts, and displayed labels are all in Chinese, and there is no indication that users may choose another language or that the skill is intentionally region-specific. That creates a language/locale policy concern because the skill appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code includes user-facing natural-language content in Chinese, including the debate prompt and processing options, and the rest of the CLI output is also Chinese. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script initializes a Git repository, stages all files with 'git add .', and creates a commit in the current directory without any confirmation, safety check, or warning about modifying repository state. In an agent or automation context, this can unintentionally capture sensitive files, alter an existing workspace, or create commits/tags in the wrong directory, which makes it a real operational security risk even though it is not overtly malicious.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing natural-language content in Chinese in the module docstring, class/method docstrings, and prompt template, but does not indicate that the skill is Chinese-only or provide any language/locale opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The class docstring asserts asynchronous three-model execution with timeout and memory protections, but the implementation never enforces those controls and only performs local heuristic scoring. This is dangerous because downstream agents or operators may trust the component as providing bounded, model-backed evaluation when it actually provides fabricated results without the stated safety guarantees, enabling unsafe decision-making and control bypass by assumption.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

_call_model_async is documented as an asynchronous model invocation returning a model-generated score and rationale, but it instead fabricates both from deterministic heuristics. In an agent skill, this creates integrity risk: other components may treat outputs as independent model judgments, causing false confidence, auditability failures, and potentially harmful automated recommendations based on nonexistent analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON log contains multiple natural-language fields entirely in Chinese, including user input and descriptive metadata, without any indication that language choice is optional or region-specific. Under the policy, forcing or assuming a specific language without documented opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains core documentation and runtime output entirely in Chinese, including the main result string returned to users. Under the policy, forcing a specific language without opt-in is a natural-language locale violation unless the skill is clearly documented as region-specific or offers a language choice, which this file does not.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The orchestrator returns natural-language prompts and success output in Chinese, such as the clarity response path and the final execution message. Because there is no visible user opt-in, negotiation, or configuration for language, this behavior can force a specific locale on users in violation of the stated policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code returns a hard-coded Chinese follow-up prompt to the user, regardless of the user's language preference or input language. The file also presents its user-facing descriptions and outputs only in Chinese, with no opt-in or documented region-specific justification, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring presents usage, trigger phrases, and interaction examples entirely in Chinese, and the activation model relies on Chinese phrases only. This imposes a specific language/locale expectation without indicating that users may choose another language or that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a stripped-down framework centered on Socratic clarification and multi-model debate. In this file, however, the gateway embeds CNC/manufacturing-specific trigger logic and later returns a recommendation about being ready to execute a quotation flow, which is narrower and more operational than a generic minimal framework description suggests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

When clarity is sufficient, the gateway returns the recommendation "需求已锚定,准备执行报价", indicating the skill is preparing to execute a pricing/quotation task. The manifest only mentions preserving Socratic clarification and multi-model debate methodology, not a quotation-execution-oriented business workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This CONTRIBUTING guide is primarily written in English, but the closing slogan and note switch to Chinese without any opt-in, translation, or justification. That creates a language/locale policy inconsistency for contributors who may not understand the closing instructions or attribution text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example input is presented only in Chinese ("帮我加工10个TC4零件"), which can impose a specific language expectation on users without opt-in. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The author description includes Chinese-only text ("靠得住、能干事、在状态"), and the document also mixes languages without indicating whether users may choose their preferred language. This can conflict with language-choice policy when a specific language is presented without opt-in or a documented reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The closing notice is written in Chinese (with partial English transliteration) and does not explain whether the skill is intended for a Chinese-speaking audience or whether other languages are supported. This may be a language-policy issue because it introduces a locale-specific message without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.