Back to skill

Security audit

KAIFASKILLFZ01

Security checks for vulnerabilities and agentic risk

Overview

This development workflow is transparent overall, but its quick mode can automatically skip security review while still guiding code changes.

Install only if you are comfortable with a workflow that can use a lighter quick mode. For sensitive work such as authentication, payment, production code, filesystem handling, command execution, or network services, require standard or strict mode and ensure security review is performed even for small changes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/workflow-variants.md:37
Finding

Quick Mode Explicitly Disables Security Review

Content
View full analysis

Vulnerability Details

File Location: references/workflow-variants.md:37-51
Vulnerability Type: Security review bypass caused by unsafe workflow configuration
Risk Level: Medium

Vulnerable Code Snippet

markdown
## Variant: quick(快速开发)

- Review 快速(只检查逻辑正确性和 Plan 一致性,跳过安全和风格)
- 适用: 单文件功能、简单脚本、工具类小功能

### 触发
- 用户说"快速开发"/"简单开发"/"小功能"
- Assess 阶段判定复杂度为"简单"
- 用户说"不用太正式"

The relevant statement translates to: “The quick review checks only logical correctness and Plan consistency, skipping security and style.”

Technical Analysis

Quick mode explicitly instructs the Reviewer to omit security checks. It may be activated by ordinary user wording or automatically when the assessment classifies a task as simple.

Task complexity and file count are not reliable indicators of security risk. A single-file script or small utility may still contain command injection, path traversal, authorization failures, exposed credentials, unsafe deserialization, or improper input validation. Consequently, this workflow can mark an implementation as reviewed even though no security analysis occurred.

This behavior conflicts with the security controls defined in references/review-checklist.md:83-88, which require checks for injection, secret exposure, path traversal, input validation, and authorization.

Attack Path

  1. A user requests quick or informal development, or the agent classifies the task as simple.
  2. The skill selects the quick workflow.
  3. The Developer produces code containing a security flaw, whether accidentally or through attacker-controlled requirements or inputs.
  4. The Reviewer checks only logical correctness and Plan consistency.
  5. The security flaw is not examined because the workflow explicitly excludes security review.
  6. The implementation proceeds to the final report and may be presented as reviewed.
  7. If deployed or executed, an attacker may exploit the omitted flaw according to the affected implementation’s runtime privil ...[truncated 627 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction to skip security review in quick mode.
  2. Define a mandatory security baseline for every workflow variant, including checks for:
    • Command, SQL, template, and cross-site scripting injection
    • Hardcoded or logged credentials, tokens, and other secrets
    • Path traversal and unsafe file operations
    • Input validation and output encoding
    • Authentication and authorization enforcement
    • Unsafe dependency additions
  3. Allow quick mode to reduce review depth or style analysis, but never eliminate security coverage.
  4. Require escalation to the standard or strict workflow when code handles credentials, untrusted input, filesystem access, command execution, network services, authentication, authorization, payment data, or other sensitive operations.
  5. Ensure the final report distinguishes between a baseline review and a full security review so users do not receive a misleading assurance.
  6. Add regression tests or workflow assertions verifying that every review variant includes the mandatory security checklist.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description and primary instructions are written as mandatory Chinese-language operational content, while the skill does not state that the user may choose another language or that the workflow is region-specific. This can violate a language/locale policy when users or organizations require language neutrality or explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template title explicitly requires output in Chinese ("Plan 输出模板"), which imposes a specific language on users of the skill. The policy for this audit flags language or locale constraints when they are not presented as an opt-in choice or otherwise justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written entirely in Chinese, including the required review instructions and output template, but it does not indicate that Chinese is optional or that the skill is intended only for a Chinese-speaking context. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file defines all role instructions and outputs in Chinese, effectively imposing a specific language on downstream agent interactions. Under the policy, language constraints should either be optional, user-selected, or explicitly justified; no such opt-in or justification appears here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level variant selection uses broad intent labels like '快速开发', '简单', '核心', and '审查', which can match normal user wording without reliably capturing actual risk or scope. Because variant choice controls whether planning, approval, architecture, and deep review occur, ambiguous routing can send requests into an unsafe or incomplete workflow path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The quick variant can be triggered by vague phrases such as '简单' or '不用太正式', which are common conversational shortcuts rather than explicit risk acceptance. In this workflow, quick mode reduces review depth and explicitly skips security checks, so broad triggers can silently downgrade safeguards for development tasks that may still affect sensitive code.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill content is presented primarily in Chinese, with trigger examples also centered on Chinese phrasing, but there is no statement offering a language choice or clarifying a justified locale restriction. That can imply a fixed language behavior without explicit user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.