Back to skill

Security audit

法律维权草拟虾

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese legal-letter drafting aid with a document conversion script; it has legal-use and renderer-safety risks, but no hidden persistence, credential use, exfiltration, or destructive behavior was found.

Use this only for Chinese/PRC-law-oriented draft letters, verify all facts, amounts, dates, contract clauses, legal citations, and jurisdiction before relying on it, and have legal counsel or a qualified reviewer approve any letter before sending. For PDF/Word conversion, only convert Markdown you trust or have sanitized, especially if it contains HTML, images, stylesheets, or external links.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate-legal-letter.sh:58
Finding

Untrusted Markdown Processed by Active Document Renderers

Content
View full analysis
/dev/null; then pandoc "$INPUT" \ --pdf-engine=wkhtmltopdf \ --variable margin-top=2cm \ --variable margin-bottom=2cm \ --variable margin-left=3cm \ --variable margin-right=2cm \ --metadata title="法律函件" \ -o "$OUTPUT" elif command -v weasyprint &>/dev/null; then pandoc "$INPUT" \ --pdf-engine=weasyprint \ -o "$OUTPUT" else ``` ### Technical Analysis The script accepts an arbitrary Markdown file through `--input` and passes it directly to Pandoc with either `wkhtmltopdf` or `weasyprint` as the PDF rendering engine. It does not sanitize raw HTML, external resource URLs, embedded images, stylesheets, scripts, or unsafe URI schemes before rendering. Markdown processed by Pandoc can contain raw HTML and references to remote resources. Depending on the installed renderer and its security configuration, document conversion may cause the renderer to make HTTP requests to attacker-selected or internal network addresses. Some wkhtmltopdf configurations may also execute embedded JavaScript or permit access to local resources. The shell variables are quoted, so this code does not establish shell command injection. The risk instead arises inside the document-rendering pipeline, where untrusted document content is interpreted by feature-rich third-party renderers. ### Attack Path 1. An attacker supplies dispute details or Markdown content containing raw HTML or a reference to a controlled resource, such as an image or stylesheet URL. 2. That content is saved into the Markdown input fi ...[truncated 1244 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a substantive legal-document generation capability: recognizing legal enforcement scenarios and automatically drafting legal notices from user-provided descriptions or structured datasets. The actual code does none of that. It assumes a Markdown letter already exists and merely converts the file into output formats using pandoc and optional PDF engines. While output conversion to PDF/Word is consistent with part of the stated output formats, the primary advertised functionality—legal analysis and drafting—is absent from this code chunk. Therefore, this code chunk materially under-implements and does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s natural-language content mandates a single language/locale experience by presenting the skill entirely in Chinese and giving no indication that users may choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all guidance and case references exclusively in Chinese, which can constitute a language/locale policy violation when no user opt-in or documented regional scope is provided. The content does not indicate that the skill is limited to a China-specific audience or that users may select another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This template library is designed to generate formal legal rights-enforcement letters, but it does not warn users to verify factual accuracy, legal citations, contractual predicates, or jurisdictional applicability before sending. In this skill context, that omission is dangerous because users may send legally inaccurate or unsupported demands, creating defamation, wrongful-claim, compliance, or adverse-litigation risk for both the sender and downstream users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire skill content is presented only in Chinese, beginning with the title at L01 and continuing throughout the file. For a general-purpose reference file, this imposes a specific language/locale without any visible opt-in, alternative language option, or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

Natural-language content throughout the file assumes Chinese as the only language, and there is no indication that the skill is intentionally limited to Chinese-speaking users or a China-specific compliance context. Under the language/locale policy, forcing a single language without opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments and generated document title use Chinese text such as "将生成的函件 Markdown 转换为 PDF" and "法律函件", indicating a fixed language/locale assumption. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.