T09 · Insecure Skill Coding Practices
- Location
scripts/skills_audit.py:369- Finding
Skill instruction files are excluded from effective security analysis
- Content
View full analysis
Vulnerability Details
File Location:
scripts/skills_audit.py:236-238,scripts/skills_audit.py:369-375, andscripts/skills_audit.py:482-503
Vulnerability Type: Security detection bypass through excluded instruction files
Risk Level: MediumVulnerable Code
python # Skip low-signal config/rule files from high-risk string scanning. if rel == "config/risk-rules.json" or rel.endswith("/risk-rules.json") or is_low_signal_file(skill_dir, p): continuepython LOW_SIGNAL_FILES = { "SKILL.md", "SKILL_zh-CN.md", "log-template.json", "config/risk-rules.json", "config/semantic-patterns.json", }python low_signal = is_low_signal_file(skill_dir, p) code_weight = p.suffix.lower() in HIGH_CONFIDENCE_CODE_EXTS and not low_signal if code_weight: if p.name == "skills_audit.py": dangerous_signals.extend(_semantic_real_execution_signals(rel, text, shell_markers)) else: for name, severity, needles in dangerous_patterns: for needle in needles: if needle in text: dangerous_signals.append({ "name": name, "severity": severity, "file": rel, "snippet": needle, }) if severity in {"high", "extreme"} and name not in {"subprocess_controlled", "network_fetch", "file_write"}: malicious_indicators.append({ "name": name, "severity": severity, "file": rel, "snippet": needle, }) breakTechnical Analysis
The general risk scanner completely skips every file identified by
is_low_signal_file(). This exclusion includesSKILL.mdandSKILL_zh-CN.md. The semantic analyzer reads these files for capability tags, but dangerous-pattern and malicio ...[truncated 2130 chars]- Remediation
View remediation
Remediation Suggestions
- Remove
SKILL.mdand localized Skill instruction files from the unconditional exclusion list. - Introduce a dedicated instruction-security analyzer that detects:
- Agent safety-constraint overrides.
- Requests to retrieve and execute remote content.
- Credential or secret collection.
- Persistence installation.
- Sensitive-path access.
- Tool invocation and shell execution directives.
- Preserve context classifications such as
doc_example, but use them to adjust confidence rather than discard findings. - Distinguish fenced examples from imperative instructions using surrounding text, command context, and directive language.
- Always retain raw evidence in the audit record, even when context reduces the final severity.
- Add regression tests containing dangerous instructions in:
SKILL.md- Localized Skill files
- Nested README files
- Mixed documentation and executable-code blocks
- Require manual review whenever a Skill document instructs an Agent to perform privileged, persistent, credential-related, or remote-execution behavior.
- Remove
