Back to skill

Security audit

Chat Bus

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent file-based chat tool, but it needs Review because callers can claim other users and unvalidated paths can read, write, or delete outside the intended chat directory.

Install only in a trusted shared directory where all participants already have equivalent access and trust each other. Do not use it for private or adversarial multi-user chat until it validates path components, confines all file operations to the chat namespace, authenticates callers, enforces room membership, and adds confirmation for destructive actions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/rooms.py:9
Finding

Path Traversal Enables Filesystem Access Outside the Chat Namespace

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/common.py:93
Finding

Caller-Supplied Usernames Permit Identity Impersonation and Unauthorized Operations

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/send.py:59
Finding

Room Membership Is Not Enforced for Reading or Sending Messages

Content
View full analysis
= limit: break ``` ```python # scripts/history.py:25-39 if source == "inbox": if not user: output_error("inbox 模式需要 user 参数", EXIT_PARAM_ERROR) base_path = chat_root / "inbox" / user elif source == "room": if not room: output_error("room 模式需要 room 参数", EXIT_PARAM_ERROR) base_path = chat_root / "rooms" / room else: output_error(f"未知来源: {source}(支持: inbox, room)", EXIT_PARAM_ERROR) if not base_path.exists(): output_ok({"source": source, "messages": [], "total": 0}) all_files = list(base_path.glob("*.json")) + list(base_path.glob("*.json.read")) ``` ```python # scripts/rooms.py:82-98 elif action == "join": username = get_current_user(params) room = ...[truncated 2365 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code does not perform message sending, receiving, group/broadcast handling, or history queries. Instead, it manages user accounts and metadata stored in the shared directory. While this may be related to a broader chat system, the declared description for the skill focuses on messaging capabilities and does not mention registration/profile lifecycle operations. That makes this code chunk materially different from the declared purpose for this specific evaluation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file documents operations that can remove user or room state, but it does not include any warning about data loss, reversibility, or the need for confirmation. Under the markdown criteria for missing user warnings, destructive behaviors affecting user data or system state should be disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation presents room deletion as a normal action but gives no user-facing warning about its destructive effect on shared collaboration state. Markdown documentation should warn users when actions can affect system integrity or shared data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline/commented intent at L42 says messages are marked as read by renaming files to '.json.read', but the unread check at L35 uses f.suffix == ".read". For files named name.json.read, pathlib.Path.suffix returns '.read', so this code sets is_read true for read files; however the inbox scan at L27 only loads *.json, meaning renamed read files are excluded entirely and this unread/read status check is not aligned with the documented mechanism.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The unregister path performs a file deletion via profile_path.unlink() to remove the user's profile. Although there is a comment noting that the inbox is preserved, there is no confirmation prompt, explicit user-facing warning, or other disclosure around the irreversible profile deletion in this code path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The delete action invokes shutil.rmtree to remove the entire room directory, which is a destructive and irreversible operation. Although authorization is checked, this file provides no confirmation prompt, warning message, or other user disclosure before performing the deletion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file-level docstring and user-facing strings are written in Chinese, indicating the skill is designed around a fixed language/locale. There is no indication that users can opt into another language or that the Chinese-only behavior is a documented, justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs a bulk file-write operation across all registered users by iterating over every user and saving a message copy into each inbox. Although the inline comment says it broadcasts to all users, there is no confirmation prompt, explicit cautionary log, or other user disclosure around this potentially wide-impact action.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The top-level docstring is entirely in Chinese and presents the module description in a single fixed language. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file contains user-facing descriptions and error messages in Chinese, such as the module docstring and parameter errors, with no indication that the user can choose another language or that the skill is intentionally region-specific. This can violate a language/locale policy when a skill implicitly forces one language for interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The file-level docstring uses Chinese-only natural language (接收新消息) with no indication that language is configurable or chosen by the user. Under the stated policy, language-specific behavior or presentation should not be forced without opt-in unless clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This Python file performs a state-changing file operation by renaming message files to mark them as read. Although the behavior is implied by the parameter name and inline comment, there is no user-facing print/log statement, confirmation prompt, or broader disclosure in this file about modifying mailbox state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring, comments, and user-visible error messages are written in Chinese, which effectively fixes the skill's interaction language without any opt-in or language-selection mechanism. Under the stated policy, locale or language constraints should either be optional for the user or clearly justified and documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's docstrings, error messages, and output text are written in Chinese throughout, which imposes a specific language on users. There is no indication of user opt-in, configurable locale selection, or justification that this skill is intentionally limited to a Chinese-language environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The module docstring states this script sends messages for 'single chat/group chat' only, but the implementation also supports a 'broadcast' mode at L079-L100. This is a semantic mismatch between the file-level documentation and actual behavior, though it remains within the broader skill manifest's overall messaging scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.