Back to skill

Security audit

Builtin Tools

Security checks for vulnerabilities and agentic risk

Overview

This skill openly provides powerful agent tools, but its shell, filesystem, network, installer, memory, and scheduled-task features are too broad and under-guarded for automatic installation.

Install only if you intentionally want to give an agent broad local toolbox powers. Prefer host-provided tools with approval controls, use this only in trusted workspaces, review every shell/delete/install/automation action before running it, avoid custom API endpoints with real keys, and do not generate or install scheduled tasks from untrusted prompts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/automation_update.py:94
Finding

Command Injection in Generated Windows Scheduled-Task Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/web_fetch.py:79
Finding

Server-Side Request Forgery Through Unrestricted URL Fetching

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/web_search.py:111
Finding

API Key Disclosure Through Caller-Controlled Request URL

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/install_binary.py:151
Finding

Downloaded Runtime Archives Are Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (45)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/common.py (reported line 74)May include surrounding context.

python
if not work_dir.is_dir():
            output_error(f"工作目录不存在: {work_dir}", EXIT_EXEC_ERROR)

    env = os.environ.copy()
    env["PYTHONIOENCODING"] = "utf-8"
    if env_vars:
        if isinstance(env_vars, dict):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/execute_command.py (reported line 22)May include surrounding context.

python
if not work_dir.is_dir():
            output_error(f"工作目录不存在: {work_dir}", EXIT_EXEC_ERROR)

    env = os.environ.copy()
    env["PYTHONIOENCODING"] = "utf-8"
    if env_vars:
        if isinstance(env_vars, dict):

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The custom API mode sends both the user's query and an API key to an arbitrary externally supplied URL, which materially raises the risk beyond ordinary web search. If the URL is misconfigured, attacker-controlled, or logged by intermediaries, it can expose sensitive queries and credentials, enabling data leakage and API key compromise.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises broad capabilities including shell execution, file read/write, network access, and persistent/task automation, but the manifest shown here does not declare any explicit tool scope or permission boundaries. In an agent ecosystem, this mismatch increases the risk that a host or reviewer underestimates the skill's effective privileges, enabling unsafe invocation of highly sensitive operations such as command execution and filesystem modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description prominently includes destructive and system-affecting operations such as command execution, file deletion/modification, runtime installation, persistence, and scheduled task management, but it does not provide explicit user-facing warnings about the risks of these actions. In this context, the skill is especially dangerous because it is designed as a self-bootstrapping toolbox that can extend an agent's reach well beyond a limited host platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文件为 write_file.py、replace_in_file.py 和 delete_file.py 提供接口说明,但仅列出参数,没有任何用户警告说明这些操作会直接修改或删除文件内容。根据规则,markdown 文件若描述会影响用户数据或系统完整性的行为而未给出警示,应报告缺失用户警告。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module description explicitly presents the skill in Chinese, and user-facing strings throughout the file are also fixed in Chinese. This indicates a language policy constraint without any opt-in, fallback, or justification that the skill is region-specific.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

This script manages persistent automations and can generate system-level scheduled task instructions via cron/schtasks, which is a real persistence-enabling capability. In this skill context, persistence is part of the advertised functionality, so the intent appears benign, but the feature is still security-relevant because an attacker who can create or modify automation configs could establish recurring execution or long-lived reminders/commands.

Content

Scanner excerpt · scripts/automation_update.py (reported line 127)May include surrounding context.

python
return cmd
    else:
        # Unix: cron
        return f'# 添加到 crontab: crontab -e\n# {parse_rrule(schedule)}\n# {prompt}'


def main():

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module header describes a common layer for JSON/protocol/path handling, but the file also embeds arbitrary shell execution capability. Hiding powerful execution behavior inside a broadly reusable helper increases the chance that other scripts import it without appreciating the risk, enabling unsafe transitive access to command execution throughout the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

A generic shared utility containing unrestricted shell execution violates least functionality and broadens the blast radius of any bug in consuming scripts. Because this skill is a cross-platform 'builtin-tools' bundle intended to fill missing platform capabilities, placing arbitrary execution in the common layer makes abuse easier and increases the odds that unrelated file/network/task features can be chained into full system command execution.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

The code invokes a platform shell (/bin/sh -c or PowerShell -Command) with a caller-supplied script string, which creates a direct command-injection sink if any upstream component passes untrusted input into run_shell. In this skill's context, the module is a shared helper for many tools and the package description explicitly advertises command dispatch/self-bootstrapping, so exposing arbitrary shell execution from a common library materially increases attack surface and makes downstream misuse likely.

Content

Scanner excerpt · scripts/common.py (reported line 90)May include surrounding context.

python
cmd = ["/bin/sh", "-c", full_script]

    try:
        result = subprocess.run(
            cmd,
            capture_output=True,
            text=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script performs irreversible file or directory deletion, including recursive directory removal, immediately based on input parameters and without any confirmation, dry-run mode, or policy restriction beyond a small hardcoded denylist. In the context of a general-purpose agent toolset that exposes filesystem primitives, this increases the risk of accidental destructive actions, prompt-injection-driven deletion, or misuse against sensitive paths not covered by the root/home checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill exposes arbitrary shell execution without any built-in warning, confirmation, or friction, making accidental or socially engineered destructive actions much more likely. In an agent context, users may not realize the full impact of a requested operation, so absence of disclosure materially increases misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code copies the current process environment and allows caller-supplied overrides to be injected into subprocesses without disclosure or restriction. This can alter execution behavior, redirect credentials/configuration, or enable abuse of sensitive inherited variables in downstream commands.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

This path executes attacker-controlled shell text via PowerShell on Windows or /bin/sh -c on Unix, which enables arbitrary OS command execution if any untrusted input reaches the command parameter. In an agent skill, this is especially dangerous because it provides a general-purpose escape hatch to run destructive commands, exfiltrate data, or install persistence beyond the agent's intended scope.

Content

Scanner excerpt · scripts/execute_command.py (reported line 49)May include surrounding context.

python
cmd = ["/bin/sh", "-c", command]

    try:
        result = subprocess.run(
            cmd,
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/execute_command.py (reported line 101)May include surrounding context.

python
cmd.append(str(script_params))

    try:
        result = subprocess.run(
            cmd,
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/execute_command.py (reported line 167)May include surrounding context.

python
cmd.append(current_input)

        try:
            result = subprocess.run(
                cmd,
                capture_output=True,
                text=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script downloads an archive from the network and extracts it directly into install_dir, which creates and overwrites files on disk. While the code reports status after download, it does not provide a user-facing warning or confirmation before performing the installation write operation into the target path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's docstring and all user-facing messages are hard-coded in Chinese, which imposes a specific language choice on users without any opt-in or fallback. This is a language-policy issue because the file provides no mechanism for locale selection or indication that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This Python skill performs an in-place file write with p.write_text(...), which can overwrite user data. While the script reports errors and success, it does not display any explicit warning or confirmation before modifying the file, and the docstring does not disclose that it changes file contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code reads arbitrary files under a user-supplied path and returns matching lines plus optional surrounding context, which can expose sensitive local data. The file contains no confirmation prompt, user-facing log/print, or inline warning/comment disclosing that file contents may be read and surfaced in output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

User-facing docstrings and error/status messages in this file are presented exclusively in Chinese, with no indication that the user can choose another language. That creates a language-policy issue because the skill implicitly forces one locale rather than offering an opt-in or documenting a justified regional scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code writes JSON data to disk and can target a user-supplied path via the earlier path parameter, but there is no confirmation prompt, print/log disclosure, or explicit warning comment/docstring describing that user files may be created or overwritten. Because the operation affects filesystem state and may overwrite an arbitrary file path, it should be disclosed to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The read action returns the full contents of any file name supplied under the chosen memory directory, and the memory_dir itself may be caller-controlled via parameters. In the context of a persistence/memory tool, this can expose sensitive stored notes, prompts, secrets, or prior conversation data without access controls, filename restrictions, or even limiting reads to expected daily memory files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Multiple docstrings and user-facing strings in this file are exclusively in Chinese, such as the module description and error messages. This creates an implicit language/locale constraint without offering the user a choice or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.