Back to skill

Security audit

Chart Generator

Security checks for vulnerabilities and agentic risk

Overview

This chart-generation skill is broadly coherent and local-only, with documentation and hardening issues users should understand before installing.

Install this only in an environment where installing unpinned Python packages is acceptable. Treat generated HTML/Markdown as trusted-output only unless titles, captions, and width values are escaped or validated, and be aware that the skill documentation overstates language support and mentions web data despite presenting itself as local-only.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:7
Finding

Unpinned Third-Party Dependencies Create a Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:376
Finding

HTML Injection Through Unescaped Chart Metadata

Content
View full analysis
{f'

{title}

' if title else ''} {title} ''' return html ``` ### Technical Analysis The `embed_in_html` method inserts `title` and `width` directly into an HTML fragment without contextual escaping or validation. The `title` value is placed both in HTML element content and inside a double-quoted attribute. An attacker can therefore supply markup or terminate the `alt` attribute and introduce additional attributes or elements. The `width` value is inserted into an inline CSS declaration and can terminate or alter the intended style context. Base64 conversion at `SKILL.md:350-360` is not itself an exfiltration mechanism. It encodes an in-memory chart into a local `data:image/...` URI for embedding and performs no network transmission. The security issue is the unsafe interpolation of metadata surrounding that image. ### Attack Path 1. An attacker controls or influences a chart title or width value, such as through imported data, a shared chart request, or an upstream application. 2. The application calls `embed_in_html` with the attacker-controlled value. 3. The method returns an HTML fragment containing the value without escaping or validation. 4. A downstream application inserts or renders the generated fragment as active HTML. 5. The crafted value breaks out of its intended context and injects HTML, attributes, event handlers, or unsafe styling. 6. If the rendering environment lacks effective sanitization or Content Security Policy controls, injected active content may execute in th ...[truncated 588 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description states a narrower feature set: five chart types and PNG/SVG output only. However, the file documents support for area/stacked charts, CSV/Excel/JSON/directory/text extraction inputs, and PDF/Word/Excel/Markdown/HTML-style embedding, which materially exceeds the stated behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The file claims support for Chinese, English, Japanese, and Korean, yet the requirements-gathering prompt is written only in Chinese and does not instruct the agent to ask the user which language they prefer. This can effectively force a language choice without user opt-in, which conflicts with the locale-policy requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes generic phrases such as "Create a chart," "Data visualization," and "Chart analysis," which can appear in ordinary conversation and many unrelated contexts. The file does not provide exclusion conditions or narrower context constraints, so it is unclear when the skill should activate versus when a general assistant response would be more appropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Step 1 presents the entire interaction template in Chinese only, despite the skill being described as multi-language. Because no opt-in or language-selection step is provided, users may be forced into a specific language regardless of preference.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The feature list advertises 'web' as a supported data source, implying network-based acquisition, while the security notes explicitly claim 'No network calls' and 'Local file processing only.' The code shown contains no network retrieval logic, so the documentation contradicts itself about intended capability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.