Back to skill

Security audit

Report Expert

Security checks for vulnerabilities and agentic risk

Overview

This report-publishing skill does what it claims, but it needs review because its URL fetching, Cloudflare deployment, and remote sync paths are powerful and under-scoped.

Install only if you are comfortable reviewing and controlling every URL, source HTML file, and Cloudflare deployment action. Use a least-privilege Cloudflare token for one Pages project, avoid running sync against an untrusted or shared site, do not publish untrusted HTML or Markdown without separate sanitization, and avoid exposing broad environment secrets while deploying.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
lib/adapter.py:156
Finding

Server-Side Request Forgery and Publication of Fetched Internal Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
lib/html_lint.py:380
Finding

Stored Cross-Site Scripting in Published Report Pages

Content
View full analysis
]*>(.*?)', html, re.DOTALL) found = [] for script_content in scripts: for pattern, label in self.DANGEROUS_PATTERNS: if re.search(pattern, script_content): found.append(label) inline_handlers = re.findall( r'on(?:click|error|load|mouseover|focus|blur)\s*=\s*["\'](.*?)["\']', html, re.IGNORECASE ) for handler in inline_handlers: for pattern, label in self.DANGEROUS_PATTERNS: if re.search(pattern, handler): found.append(label) def fix(self, html): removed = 0 for pattern, _ in self.DANGEROUS_PATTERNS: def should_remove(m): return '' if re.search(pattern, m.group(0)) else m.group(0) new_html = re.sub( r']*>.*?', should_remove, html, flags=re.DOTALL ) if new_html != html: html = new_html removed += 1 return html, f"Removed {removed} dangerous scripts" ``` ```python # lib/page.py:148
{body}
``` ### Technical Analysis The report body is treated as trusted HTML and inserted into the generated page without contextual escaping or robust sanitization. The `ScriptSafety` rule is a denylist that recognizes only five JavaScript patterns. Scripts remain executable if they avoid those exact strings. Examples include co ...[truncated 1777 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
lib/site.py:58
Finding

Arbitrary File Write and Deletion Through Unvalidated Remote Index Paths

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
lib/remote_deploy.py:31
Finding

Unpinned Wrangler Execution Receives Cloudflare Credentials and the Full Process Environment

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
lib/page.py:39
Finding

Mutable Third-Party CDN Scripts Execute in Published Report Origins

Content
View full analysis
\n' ) if needs_chartjs: cdn_tags += ( ' \n' ) mermaid_script = "" if needs_mermaid: mermaid_script = ''' ``` ### Technical Analysis Generated reports load ECharts, Chart.js, and Mermaid from jsDelivr using mutable major-version ranges. The script tags do not include Subresource Integrity hashes. A later compatible release under the same major version can therefore change the code executed by previously generated pages. The dependencies are enabled by keyword checks against report body content. Consequently, untrusted body text can trigger third-party script loading even when the report does not require the corresponding chart engine. Because these scripts execute without browser isolation, compromise of an upstream package, CDN account, or delivery path results in JavaScript execution under the report site’s origin. ### Attack Path 1. A report body contains a chart-related marker, either legitimately or deliberately. 2. Page generation adds a mutable jsDelivr script URL. 3. A compromised or malicious dependency release is served under the accepted major-version range, or the CDN delivery path is compromised. 4. A visitor opens the generated report. 5. The third-party script executes with the privileges of the Cloudflare Pages origin. ### Impact Assessment A compromised dependency can modify reports, capture user-entered data, perform same-origin requests, redi ...[truncated 319 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (53)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch is more security-relevant because the skill explicitly includes arbitrary URL fetching while the declared purpose frames the tool mainly as report generation and CF deployment. Hidden or under-emphasized network retrieval can cause users to unintentionally authorize outbound requests to attacker-controlled URLs, potentially exposing metadata, internal network access patterns, or importing untrusted HTML into the publishing pipeline.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This mismatch is more security-relevant because the skill explicitly includes arbitrary URL fetching while the declared purpose frames the tool mainly as report generation and CF deployment. Hidden or under-emphasized network retrieval can cause users to unintentionally authorize outbound requests to attacker-controlled URLs, potentially exposing metadata, internal network access patterns, or importing untrusted HTML into the publishing pipeline.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This mismatch is more security-relevant because the skill explicitly includes arbitrary URL fetching while the declared purpose frames the tool mainly as report generation and CF deployment. Hidden or under-emphasized network retrieval can cause users to unintentionally authorize outbound requests to attacker-controlled URLs, potentially exposing metadata, internal network access patterns, or importing untrusted HTML into the publishing pipeline.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This mismatch is more security-relevant because the skill explicitly includes arbitrary URL fetching while the declared purpose frames the tool mainly as report generation and CF deployment. Hidden or under-emphasized network retrieval can cause users to unintentionally authorize outbound requests to attacker-controlled URLs, potentially exposing metadata, internal network access patterns, or importing untrusted HTML into the publishing pipeline.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
templates/index.html — 首页模板

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · lib/remote_deploy.py (reported line 31)May include surrounding context.

python
token = CLOUDFLARE_API_TOKEN
    project = REPORT_CF_PROJECT

    env = {**os.environ, "CLOUDFLARE_API_TOKEN": token}
    cmd = [
        "npx", "wrangler", "pages", "deploy", str(deploy_dir),
        "--project-name", project,

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes capabilities that imply access to environment variables, local file reads/writes, network fetching, and shell-based deployment, but it does not declare any explicit tool scope or permission boundaries. In a skill that can publish to Cloudflare Pages and sync remote/local content, missing scope declarations increases the chance of over-broad execution, accidental destructive actions, or credential misuse without user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description and all user-facing instructions are presented exclusively in Chinese, indicating a language constraint without any stated option for other languages or user preference. SQP-3 applies to natural-language policy violations where a specific language is imposed without opt-in or clear justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to configure a Cloudflare API token but gives no warning about credential sensitivity, storage, scope minimization, or risk of leakage through logs and shell commands. Because the skill can perform deployment actions, mishandling this token could allow unauthorized site modification or broader Cloudflare account compromise depending on token scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow includes commands that write to dist, rebuild indexes, sync from the live site, update all pages, and publish to Cloudflare Pages, but the skill does not prominently warn that these operations mutate local state and a production-like remote site. In a deployment skill, lack of upfront mutation/publishing warnings can cause accidental overwrites, data loss, or unauthorized live changes when a user expects a dry-run style helper.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring and all user-facing CLI help text are written in Chinese, presenting the skill as a Chinese-language interface by default. There is no indication that users may choose another language, nor any documented justification that the skill is intended only for a Chinese-specific region or audience.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module promises 'pure HTML' without script content, but _url_to_html preserves arbitrary remote body HTML after only limited tag stripping, and markdown/text conversion also injects unescaped title/body content into HTML. In a report-generation and publishing skill, this can lead to stored XSS or malicious active content being deployed to Cloudflare Pages and served to end users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The _url_to_html function performs outbound network requests using curl and urlopen to fetch arbitrary URLs. Although the docstring states that it fetches web content, there is no confirmation prompt, user-facing log/print, or explicit warning that providing a URL will trigger network access and transmit request metadata to external hosts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code invokes an external subprocess (curl) to retrieve remote content. This is a safety-relevant operation under the rule, and the file provides no user-facing notice, confirmation, or logging around that shell/tool execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is described as generating and deploying HTML report pages, and this module is documented as an input-adaptation layer. While fetching a URL is within scope, invoking an external program via subprocess is a broader execution capability that is not justified by the manifest's stated purpose and goes beyond ordinary content adaptation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · lib/adapter.py (reported line 158)May include surrounding context.

python
# Try curl first
    import subprocess
    try:
        result = subprocess.run(
            ['curl', '-sL', '--max-time', '30', url],
            capture_output=True, text=True
        )

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file contains natural-language documentation and console output in Chinese, including the top-level module docstring and later status/error messages, but there is no indication that the skill is intentionally region-specific or that users can opt into another language. This can violate language/locale policy when a skill forces one language by default.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code scans both the user's home directory and a workspace-level TOOLS.md file to extract configuration, including CLOUDFLARE_API_TOKEN. While deploying to Cloudflare requires credentials, harvesting them from arbitrary documentation-style files in broader filesystem locations is not an obvious or declared part of a report publishing skill's purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The check_config function prints all validation failures and setup instructions in Chinese only. Because these are user-facing operational messages and no alternative locale or explicit regional scope is provided, the skill appears to enforce a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template always emits <html lang="zh-CN">, which forces a specific locale for all generated pages. The file does not provide a language selection mechanism or explain that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and function docstring are written entirely in Chinese, and the script's user-facing status/error messages are also Chinese-only. This imposes a specific language/locale on users without offering a choice or documenting a justified region-specific constraint, which matches the language policy violation criteria.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · lib/remote_deploy.py (reported line 47)May include surrounding context.

python
for attempt in range(1, MAX_RETRIES + 2):
        try:
            result = subprocess.run(cmd, capture_output=True, text=True, env=env, timeout=120)
        except subprocess.TimeoutExpired:
            print(f"❌ 部署超时(120秒),尝试 {attempt}/{MAX_RETRIES+1}")
            if attempt <= MAX_RETRIES:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill's purpose is to generate and publish HTML reports to Cloudflare Pages, and networked deployment itself is expected. However, implementing that by spawning npx wrangler introduces a general external-process execution capability, which is broader and more dangerous than the manifest's stated functional scope and not explicitly justified in the description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code contains natural-language strings exclusively in Chinese in the module docstring and later user-facing status/error messages, which effectively imposes a specific language on users and operators. The file does not indicate that Chinese is optional, configurable, or required for a region-specific purpose, so it conflicts with the policy against forced language/locale without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

manifest将技能定位为生成并部署报告到 Cloudflare Pages,且明确排除纯上传/下载类操作;但这里的 sync_from_cf 会从远端站点拉取 index、页面和静态资源回写到本地 dist,并合并本地索引。这不是部署流程中显而易见的必要实现细节,而是额外的远程恢复/镜像能力。

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
lib/html_lint.py:387