Back to skill

Security audit

Cogniexec

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it bundles broad automation powers with several unsafe helper scripts that can execute code, mutate data, or expose credentials.

Review this skill before installing, and use it only in a sandbox or workspace where broad file, network, database, Git, and email actions are acceptable. Avoid running it on untrusted datasets, codebases, or archives until the eval, dynamic import, TAR extraction, SMTP TLS, debug redaction, Git hook, and crypto documentation issues are fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (8)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/data_processor.py:200
Finding

Unsafe Expression Evaluation Allows Python Sandbox Escape

Content
View full analysis
Any: """ Safe expression evaluation. Supports field references, comparisons, mathematics, logic, and strings. """ safe_dict = {'__builtins__': {}} safe_dict.update(cls.SAFE_FUNCS) safe_dict.update(context) expr = expr.strip() expr = re.sub(r'\bnull\b|\bNone\b', 'None', expr) try: result = eval(expr, safe_dict) return result except Exception as e: raise ValueError(f'Expression parsing failed: {expr} → {e}') ``` ### Technical Analysis The filter and transformation expression is passed directly to Python's `eval()`. Setting `__builtins__` to an empty dictionary is not a security boundary. Python expressions can still perform attribute access and traverse the runtime object graph through existing objects. There is no Abstract Syntax Tree allowlist restricting expressions to arithmetic, comparison, Boolean logic, field references, and approved function calls. Consequently, a crafted expression may access classes or other runtime objects and recover file-access or process-execution primitives. The issue affects every command that routes attacker-controlled expressions through `ExprEvaluator.eval()`, including filtering and data transformation operations. ### Attack Path 1. An attacker supplies a dataset and a malicious filter or transformation expression. 2. The user or Agent invokes a data-processing command with the expression. 3. `ExprEvaluator.eval()` inserts the expression into Python `eval()`. 4. The expression traverses accessible Python objects despite the empty builtins dictionary. 5. The payload obtains a useful runtime primitive and performs unauthorized file access or command execution. 6. The payload runs with the s ...[truncated 457 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/code_tools.py:1036
Finding

Dependency Analysis Imports and Executes Modules from Analyzed Projects

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/git_advanced.py:386
Finding

Git Hook Type Path Traversal Allows Arbitrary File Read and Permission Changes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/archive_tool.py:169
Finding

TAR Extraction Does Not Validate Link Targets or Special File Types

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/http_client.py:593
Finding

HTTP Debug Mode Prints Authentication Headers and Sensitive Request Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/email_sender.py:233
Finding

SMTP Authentication Can Occur Without TLS and Protocol Debugging May Log Secrets

Content
View full analysis
bool: try: if self.use_ssl: self.server = smtplib.SMTP_SSL( self.host, self.port, timeout=self.timeout ) else: self.server = smtplib.SMTP( self.host, self.port, timeout=self.timeout ) if os.environ.get('EMAIL_DEBUG'): self.server.set_debuglevel(2) if self.use_tls and not self.use_ssl: self.server.starttls() if self.username and self.password: self.server.login(self.username, self.password) ``` ### Technical Analysis Both TLS modes default to disabled. Nevertheless, the code performs SMTP authentication whenever a username and password are available. If neither TLS flag is set, authentication and email transmission can occur over an unencrypted connection. SMTP authentication mechanisms frequently encode credentials rather than encrypting them. A network observer can therefore recover credentials or message contents from plaintext SMTP traffic. Additionally, `EMAIL_DEBUG` enables verbose protocol logging before STARTTLS and authentication. Debug output can retain protocol commands, encoded authentication material, envelope ...[truncated 1099 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/crypto_utils.py:371
Finding

Repeating-Key XOR Is Presented as Encryption Despite Providing No Secure Protection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:304
Finding

Optional Dependency Installation Instructions Are Unpinned

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (110)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Terminal UI functionality is not inherently dangerous, but presenting it as part of a generic cognition/execution engine is misleading. The main risk is reduced review quality and overbroad approval due to inaccurate labeling rather than direct exploitation.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
| 级别 | 示例 | 处理方式 |
|------|------|----------|
| 🔴 高危 | `rm -rf /`、`format C:` | **必须用户确认** |
| 🟡 中危 | `pip uninstall`、`sudo` | 警告提示 |
| 🟢 低危 | `ls`、`cat`、`python script.py` | 直接执行 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
| `git_advanced.py` | Git高级操作(stash/blame/diff/cherry-pick/rebase/冲突解决/log图形化/hooks管理) | 纯标准库(subprocess+git) |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

md
| `data_processor.py` | 通用数据处理(过滤/排序/分组/聚合/统计/透视表/去重/合并/采样) | 纯标准库 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 287)May include surrounding context.

md
| `code_tools.py` | 代码工具集(语法校验/TODO扫描/API提取/行数统计/Git辅助/代码搜索/语言检测/导入检查) | 纯标准库 |

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring claims AES encryption support, but the implementation only performs Base64 encoding/decoding and a trivial XOR routine. In a skill explicitly described as combining cognition with code execution, this misleading claim can cause downstream users or agents to treat reversible encoding or weak obfuscation as real encryption, leading to exposure of secrets or unsafe automation decisions.

Content

No source excerpt is available for this finding.

eval() call detected

High
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

The expression evaluator passes user-controlled input directly into Python's eval() with a globals dictionary that still exposes Python object semantics. Even with builtins removed, attackers can often traverse object graphs and recover dangerous functionality, leading to arbitrary code execution in the context of the process. In this skill context, the danger is elevated because the skill explicitly supports automated code and command execution workflows, making unsafe expression handling especially risky.

Content

Scanner excerpt · scripts/data_processor.py (reported line 221)May include surrounding context.

python
# 处理字符串中的引号
        try:
            result = eval(expr, safe_dict)
            return result
        except Exception as e:
            raise ValueError(f'表达式解析失败: {expr} → {e}')

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The exec command accepts and executes arbitrary non-query SQL directly against any local SQLite database path supplied by the caller. In an agent skill context with code-execution/orchestration capabilities, this enables destructive schema changes, data deletion, or tampering with local application state without guardrails, making the skill more dangerous than a read-only database helper.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.insecure_tls_verification

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/data_processor.py:200

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/http_client.py:104