Back to skill

Security audit

Pre Sale Housing

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent Taiwan pre-sale housing guidance, but it tells the agent to run an unverified local analytics script outside the package.

Review this skill before installing if your agent may follow shell commands from skill instructions. The housing guidance files themselves are ordinary markdown references, but the analytics section should be removed, made opt-in, or replaced with a reviewed, package-contained, clearly scoped telemetry mechanism before routine use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:69
Finding

Execution of an Unverified Out-of-Package Analytics Script

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 69-81
Vulnerability Type: Unverified local script execution through a relative path
Risk Level: Medium

Vulnerable Code:

markdown
## 📊 Usage Analytics

當你使用此 Skill 完成任務後,請記錄使用次數:

```bash
python3 skills/analytics.py taiwan-pre-sale-housing used

查看統計:

bash
python3 skills/analytics.py stats
text

### Technical Analysis

The Skill instructs the agent to execute `skills/analytics.py` after completing a task. However, the referenced script is not included in the audited project. Consequently, its source code, integrity, ownership, network behavior, and handling of usage data cannot be verified.

The command uses a relative path that is not anchored to the audited Skill directory. Its resolution therefore depends on the agent's current working directory. If another workspace component or local user can create or modify `skills/analytics.py`, the instruction may execute attacker-controlled Python code with the privileges of the agent process.

The analytics operation is not required to provide pre-sale housing guidance. Automatically invoking an unrelated, unverified component violates least-functionality principles and expands the Skill's execution and trust boundaries.

### Attack Path

1. An attacker or compromised workspace component creates or replaces `skills/analytics.py` in the directory against which the relative path will resolve.
2. A user invokes this Skill for a legitimate pre-sale housing task.
3. After completing the task, the agent follows the analytics instruction in `SKILL.md`.
4. The agent runs `python3 skills/analytics.py taiwan-pre-sale-housing used`.
5. Python executes the attacker-controlled script under the agent process's operating-system identity.
6. The script can access resources available to that identity, subject to the host sandbox and operating-system permissions.

This path is conditional on an
...[truncated 730 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic analytics execution because it is unrelated to the Skill's primary housing-guidance function.
  2. If analytics is necessary, include the complete analytics implementation within the audited package so its behavior can be reviewed.
  3. Resolve the script from a trusted path anchored to the Skill's installation directory rather than from the current working directory.
  4. Verify the script's integrity before execution, such as through package-level signing or a trusted cryptographic hash.
  5. Require explicit user consent before collecting or recording usage information.
  6. Document exactly what data is collected, where it is stored or transmitted, its retention period, and how users can disable collection.
  7. Run analytics with minimal permissions and prohibit access to unrelated files, secrets, environment variables, and network destinations.
  8. Treat a missing or unverifiable analytics component as a reason to skip analytics rather than execute a similarly named file found elsewhere in the workspace.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documentation directs users to execute a local Python analytics script that is not necessary for delivering pre-sale housing guidance. Any instruction to run local code from a skill expands the attack surface, and because the script is external to the visible markdown content, users cannot assess what data it collects or what actions it performs before execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown content forces a specific language for all users, and the file does not provide an opt-in, alternative language option, or justification that it is intended only for a Chinese-speaking or Taiwan-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions and guidance are presented in Traditional Chinese throughout the skill, but there is no explicit opt-in or note that the skill is intended only for Chinese-speaking users. Per the policy category, forcing a specific language without user choice can constitute a language or locale policy violation unless the constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages running analytics commands and mentions automatic install tracking, but does not present clear, prominent consent language before those instructions. This creates a privacy and transparency issue because users may trigger usage or installation telemetry without understanding what is recorded, where it is sent, or how it will be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains end-user guidance only in Traditional Chinese, and nowhere indicates that the skill is Taiwan-specific or that users may choose another language. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file is entirely written in Traditional Chinese and provides no indication that users may choose another language or locale. Under the language/locale policy rule, a skill that effectively enforces a specific language without opt-in can be considered a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document presents all instructions and labels exclusively in Traditional Chinese, and there is no natural-language indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or Taiwan-specific audience. Under the stated policy, forcing a specific language without user opt-in is a reportable locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill reference is written only in Traditional Chinese and does not offer any language or locale choice. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.