T09 · Insecure Skill Coding Practices
- Location
scan_skills.py:244- Finding
Attacker-Controlled Paths Can Bypass Security Scanning
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed local skill scanner, but its broad automatic activation and unreliable install-safety recommendations warrant review before installation.
Install only if you want a lightweight local heuristic scanner and will treat its results as advisory. Do not rely on its allow-install output as proof that a skill is safe, and prefer explicit invocation with a reviewed target path or manual review of any files it skips.
scan_skills.py:244Attacker-Controlled Paths Can Bypass Security Scanning
scan_skills.py:104Exact-Substring Detection Is Trivially Evaded and Produces Unsafe Risk Scores
scan_skills.py:69Spoofable Filename Whitelist Mislabels Untrusted Files and Does Not Apply Its Intended Score Reduction
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
("chattr ", "chattr 修改文件属性,需 root 权限"),
(".bashrc", ".bashrc 涉及 Shell 配置,确认来源可信"),
("/etc/passwd","读取系统账户文件,确认用途"),
("/etc/shadow","读取密码哈希文件,禁止在外部传输"),
(".ssh/", "涉及 SSH 密钥目录,确认用途后使用"),
],
"低危": [
The trigger phrases are broad enough that ordinary requests such as asking for a security audit or risk analysis could invoke this skill unintentionally. In an agent environment, unintended activation can cause unnecessary scanning of workspace content, disclosure of file metadata, or interference with the user's intended task.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
|------|--------|------|
| 严重 | `eval(`, `exec(`, `os.system`, `subprocess.call`, `subprocess.run`, `__import__`, `importlib`, `pty.spawn` | -25 |
| 高危 | `requests.get`, `requests.post`, `urllib.request`, `http.client`, `socket.create_connection`, `curl`, `wget` | -20 |
| 中危 | `chmod`, `chown`, `sudo`, `chattr`, `ACL`, `passwd`, `shadow`, `/etc/passwd`, `.bashrc`, `.ssh/` | -15 |
| 低危 | `open(`, `write`, `base64`, `gzip`, `zlib`(单独出现不扣分,组合出现-5) | -5 |
### 评分标准
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
|------|--------|------|
| 严重 | `eval(`, `exec(`, `os.system`, `subprocess.call`, `subprocess.run`, `__import__`, `importlib`, `pty.spawn` | -25 |
| 高危 | `requests.get`, `requests.post`, `urllib.request`, `http.client`, `socket.create_connection`, `curl`, `wget` | -20 |
| 中危 | `chmod`, `chown`, `sudo`, `chattr`, `ACL`, `passwd`, `shadow`, `/etc/passwd`, `.bashrc`, `.ssh/` | -15 |
| 低危 | `open(`, `write`, `base64`, `gzip`, `zlib`(单独出现不扣分,组合出现-5) | -5 |
### 评分标准
The file forces a specific language/locale for the skill description and usage instructions, and there is no indication that users may opt into another language or that the skill is intentionally region-specific. This can violate organizational language-choice policy when a skill is presented to a broader audience.
The listed trigger phrases are very broad generic requests for scanning, auditing, and risk analysis, so they are likely to overlap with normal user language and cause accidental or unintended invocation of the skill. In an agent environment, overly broad activation can route unrelated user requests into this skill and expose workspace contents or produce unexpected autonomous scanning behavior.
This code file contains natural-language strings that force a specific language/locale for the script description and generated report path. The policy for SQP-3 applies to all file types and flags language constraints when the skill does not provide user opt-in or justify the locale restriction.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
"中危": [
("chmod ", "chmod 修改权限,生产环境谨慎操作"),
("chown ", "chown 修改所有者,需 root 权限"),
("sudo ", "sudo 提权命令,确认必要性"),
("chattr ", "chattr 修改文件属性,需 root 权限"),
(".bashrc", ".bashrc 涉及 Shell 配置,确认来源可信"),
("/etc/passwd","读取系统账户文件,确认用途"),
All user-facing instructions, trigger phrases, and output examples are defined only in Chinese, with no indication that the user may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.
L89声明该技能“仅提示风险,不自动禁止”,表述上强调不做阻断性处置;但L90又规定风险分<40时“不输出任何安装指引”,同时前文评分标准明确包含“禁止安装”“立即删除”等强烈处置建议。这些文档表述对技能是否只做提示、还是会产生实际阻断/劝阻性决策存在明显矛盾。
Detected: suspicious.dynamic_code_execution