T07 · Tool Hijacking and Spoofing
- Location
SKILL.md:104- Finding
Execution of an Unpackaged and Unverified Analytics Script
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its home-inspection purpose, but it tells the agent to run an analytics script that is not included for review.
Install only if you are comfortable with a Taiwan-focused Traditional Chinese inspection workflow. Do not let the agent run `skills/analytics.py` unless you can verify that script from the installed environment, and direct report output to a specific safe `.md` path to avoid overwriting important files.
SKILL.md:104Execution of an Unpackaged and Unverified Analytics Script
scripts/gen-report.py:51Unescaped Markdown Generation and Unrestricted Output File Overwrite
The skill instructs the agent to read references and generate reports via a script, implying file read/write behavior, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent or runtime may permit broader filesystem access than intended, increasing the chance of unintended file access or overwrite during skill execution.
This markdown template is entirely written in Traditional Chinese and presents a fixed-language report format, including headings, field labels, and conclusions. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is explicitly documented and justified, which is not present here.
Suspicious Unicode normalization or mixed-script content
Suspicious Unicode normalization or mixed-script content
The file's usage example, sample data, report labels, and generated conclusions are written entirely in Traditional Chinese, and the generated report text is also fixed to that language. This imposes a specific language/locale on users without any opt-in or documented justification that the skill is intended only for a Chinese-speaking or Taiwan-specific context.
The description specifies Taiwan residential properties and the document content heavily mixes or defaults to Traditional Chinese terminology and instructions. Under the stated policy, a skill that effectively forces a specific language/locale should either offer user choice or clearly document a justified locale constraint; this file does not explicitly present that opt-in or justification as a locale restriction policy.
The skill asks users to run an external analytics script unrelated to the core home-inspection function, which introduces unnecessary code execution. Even if benign, this expands the attack surface by encouraging execution of auxiliary code that may collect telemetry or perform actions the user does not expect as part of an inspection workflow.
This markdown checklist forces a specific language/locale for all users, and the file does not provide any opt-in, alternative language, or justification for the locale restriction. Under the stated policy, natural-language content that mandates a single language without user choice is a language/locale policy violation.
This markdown file presents all guidance in a single language/locale, which can be a natural-language policy issue if skills are expected not to force a specific language without user opt-in. There is no indication that the user can choose another language or that the Taiwan-specific language/locale scope is explicitly justified as a constraint.
No suspicious patterns detected.