T09 · Insecure Skill Coding Practices
- Location
scripts/automation_update.py:94- Finding
Command Injection in Generated Windows Scheduled-Task Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill openly provides powerful agent tools, but its shell, filesystem, network, installer, memory, and scheduled-task features are too broad and under-guarded for automatic installation.
Install only if you intentionally want to give an agent broad local toolbox powers. Prefer host-provided tools with approval controls, use this only in trusted workspaces, review every shell/delete/install/automation action before running it, avoid custom API endpoints with real keys, and do not generate or install scheduled tasks from untrusted prompts.
scripts/automation_update.py:94Command Injection in Generated Windows Scheduled-Task Command
scripts/web_fetch.py:79Server-Side Request Forgery Through Unrestricted URL Fetching
scripts/web_search.py:111API Key Disclosure Through Caller-Controlled Request URL
scripts/install_binary.py:151Downloaded Runtime Archives Are Installed Without Integrity Verification
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
if not work_dir.is_dir():
output_error(f"工作目录不存在: {work_dir}", EXIT_EXEC_ERROR)
env = os.environ.copy()
env["PYTHONIOENCODING"] = "utf-8"
if env_vars:
if isinstance(env_vars, dict):
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
if not work_dir.is_dir():
output_error(f"工作目录不存在: {work_dir}", EXIT_EXEC_ERROR)
env = os.environ.copy()
env["PYTHONIOENCODING"] = "utf-8"
if env_vars:
if isinstance(env_vars, dict):
The custom API mode sends both the user's query and an API key to an arbitrary externally supplied URL, which materially raises the risk beyond ordinary web search. If the URL is misconfigured, attacker-controlled, or logged by intermediaries, it can expose sensitive queries and credentials, enabling data leakage and API key compromise.
The skill advertises broad capabilities including shell execution, file read/write, network access, and persistent/task automation, but the manifest shown here does not declare any explicit tool scope or permission boundaries. In an agent ecosystem, this mismatch increases the risk that a host or reviewer underestimates the skill's effective privileges, enabling unsafe invocation of highly sensitive operations such as command execution and filesystem modification.
The description prominently includes destructive and system-affecting operations such as command execution, file deletion/modification, runtime installation, persistence, and scheduled task management, but it does not provide explicit user-facing warnings about the risks of these actions. In this context, the skill is especially dangerous because it is designed as a self-bootstrapping toolbox that can extend an agent's reach well beyond a limited host platform.
该 markdown 文件为 write_file.py、replace_in_file.py 和 delete_file.py 提供接口说明,但仅列出参数,没有任何用户警告说明这些操作会直接修改或删除文件内容。根据规则,markdown 文件若描述会影响用户数据或系统完整性的行为而未给出警示,应报告缺失用户警告。
The module description explicitly presents the skill in Chinese, and user-facing strings throughout the file are also fixed in Chinese. This indicates a language policy constraint without any opt-in, fallback, or justification that the skill is region-specific.
This script manages persistent automations and can generate system-level scheduled task instructions via cron/schtasks, which is a real persistence-enabling capability. In this skill context, persistence is part of the advertised functionality, so the intent appears benign, but the feature is still security-relevant because an attacker who can create or modify automation configs could establish recurring execution or long-lived reminders/commands.
return cmd
else:
# Unix: cron
return f'# 添加到 crontab: crontab -e\n# {parse_rrule(schedule)}\n# {prompt}'
def main():
The module header describes a common layer for JSON/protocol/path handling, but the file also embeds arbitrary shell execution capability. Hiding powerful execution behavior inside a broadly reusable helper increases the chance that other scripts import it without appreciating the risk, enabling unsafe transitive access to command execution throughout the skill.
A generic shared utility containing unrestricted shell execution violates least functionality and broadens the blast radius of any bug in consuming scripts. Because this skill is a cross-platform 'builtin-tools' bundle intended to fill missing platform capabilities, placing arbitrary execution in the common layer makes abuse easier and increases the odds that unrelated file/network/task features can be chained into full system command execution.
The code invokes a platform shell (/bin/sh -c or PowerShell -Command) with a caller-supplied script string, which creates a direct command-injection sink if any upstream component passes untrusted input into run_shell. In this skill's context, the module is a shared helper for many tools and the package description explicitly advertises command dispatch/self-bootstrapping, so exposing arbitrary shell execution from a common library materially increases attack surface and makes downstream misuse likely.
cmd = ["/bin/sh", "-c", full_script]
try:
result = subprocess.run(
cmd,
capture_output=True,
text=True,
The script performs irreversible file or directory deletion, including recursive directory removal, immediately based on input parameters and without any confirmation, dry-run mode, or policy restriction beyond a small hardcoded denylist. In the context of a general-purpose agent toolset that exposes filesystem primitives, this increases the risk of accidental destructive actions, prompt-injection-driven deletion, or misuse against sensitive paths not covered by the root/home checks.
The skill exposes arbitrary shell execution without any built-in warning, confirmation, or friction, making accidental or socially engineered destructive actions much more likely. In an agent context, users may not realize the full impact of a requested operation, so absence of disclosure materially increases misuse risk.
The code copies the current process environment and allows caller-supplied overrides to be injected into subprocesses without disclosure or restriction. This can alter execution behavior, redirect credentials/configuration, or enable abuse of sensitive inherited variables in downstream commands.
This path executes attacker-controlled shell text via PowerShell on Windows or /bin/sh -c on Unix, which enables arbitrary OS command execution if any untrusted input reaches the command parameter. In an agent skill, this is especially dangerous because it provides a general-purpose escape hatch to run destructive commands, exfiltrate data, or install persistence beyond the agent's intended scope.
cmd = ["/bin/sh", "-c", command]
try:
result = subprocess.run(
cmd,
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd.append(str(script_params))
try:
result = subprocess.run(
cmd,
capture_output=True,
text=True,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
cmd.append(current_input)
try:
result = subprocess.run(
cmd,
capture_output=True,
text=True,
The script downloads an archive from the network and extracts it directly into install_dir, which creates and overwrites files on disk. While the code reports status after download, it does not provide a user-facing warning or confirmation before performing the installation write operation into the target path.
The skill's docstring and all user-facing messages are hard-coded in Chinese, which imposes a specific language choice on users without any opt-in or fallback. This is a language-policy issue because the file provides no mechanism for locale selection or indication that the skill is intentionally region-specific.
This Python skill performs an in-place file write with p.write_text(...), which can overwrite user data. While the script reports errors and success, it does not display any explicit warning or confirmation before modifying the file, and the docstring does not disclose that it changes file contents.
This code reads arbitrary files under a user-supplied path and returns matching lines plus optional surrounding context, which can expose sensitive local data. The file contains no confirmation prompt, user-facing log/print, or inline warning/comment disclosing that file contents may be read and surfaced in output.
User-facing docstrings and error/status messages in this file are presented exclusively in Chinese, with no indication that the user can choose another language. That creates a language-policy issue because the skill implicitly forces one locale rather than offering an opt-in or documenting a justified regional scope.
This code writes JSON data to disk and can target a user-supplied path via the earlier path parameter, but there is no confirmation prompt, print/log disclosure, or explicit warning comment/docstring describing that user files may be created or overwritten. Because the operation affects filesystem state and may overwrite an arbitrary file path, it should be disclosed to the user.
The read action returns the full contents of any file name supplied under the chosen memory directory, and the memory_dir itself may be caller-controlled via parameters. In the context of a persistence/memory tool, this can expose sensitive stored notes, prompts, secrets, or prior conversation data without access controls, filename restrictions, or even limiting reads to expected daily memory files.
Multiple docstrings and user-facing strings in this file are exclusively in Chinese, such as the module description and error messages. This creates an implicit language/locale constraint without offering the user a choice or documenting a justified region-specific limitation.
No suspicious patterns detected.