Back to skill

Security audit

Domain Payload Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent skill generator, but its templates require generated skills to automatically install and load an unpinned UTOS dependency without clear user approval.

Review this before installing. The main risk is not hidden code in this package, but that skills produced from it are instructed to automatically install and load `universal-task-os`. Only use it where dependency installation is user-approved, sourced from a trusted registry or publisher, version-pinned, and safe-path file generation rules are enforced.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
references/structure-template.md:34
Finding

Generated Skills Mandate Automatic Installation of an Unverified Dependency

Content
View full analysis

Vulnerability Details

File Location: references/structure-template.md:34-54; enforced by references/utos-interface-checklist.md:13
Vulnerability Type: Unattended installation and loading of an unpinned third-party skill
Risk Level: Medium

Vulnerable Code Snippet

The following is an English translation of the complete relevant source segment from references/structure-template.md:34-54:

markdown
**Load-check process** (executed on every activation):

1. Detect whether the `universal-task-os` skill is installed
2. **Not installed** → Automatically install the `universal-task-os` skill
3. **Installation succeeds** → Load UTOS at the same time and execute according to this skill's usage rules
4. **Installation fails** → Degrade to **read-only reference mode**:
   - Allowed: Consult the catalog, requirements, and exemplar index
   - Refused: Any task involving output generation, pipeline orchestration, or content generation, with a prompt stating that Universal Task OS must first be installed

**Task-mode determination**:

| Task type | Without UTOS | With UTOS |
|-----------|--------------|-----------|
| Consult catalogs, requirements, or exemplars | Read-only reference | Full access |
| Produce deliverables using the methodology | Refused | UTOS-orchestrated execution |
| Derive pipelines from dependency topology | Refused | UTOS execution axis |
| Insert compliance or quality checkpoints | Refused | UTOS guard unit |

## Usage Rules

1. **Dependency check**: On activation, detect and install UTOS according to the process above

The behavior is made mandatory by references/utos-interface-checklist.md:13:

markdown
| A3 | Complete load-check process | Check for a four-step process: detect → install → load → degrade | All four steps are mandatory |

Technical Analysis

The skill is a generator whose templates are propagated into newly created skills. Its template ...[truncated 2971 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove automatic installation from the activation path. If UTOS is unavailable, default immediately to read-only mode.
  2. Require explicit, informed user approval before installing any dependency. Display its source, publisher, version, requested permissions, and expected behavior.
  3. Define one authoritative dependency source and reject resolution from untrusted registries, arbitrary URLs, or environment-dependent fallback sources.
  4. Pin the dependency to an immutable version and cryptographic digest. Avoid floating tags such as latest.
  5. Verify a trusted publisher signature or package signature before installation and again before loading.
  6. Perform installation with the minimum permissions necessary and isolate the dependency from unrelated files, credentials, network resources, and tools.
  7. Separate installation from loading so the dependency can be reviewed before execution.
  8. Update references/utos-interface-checklist.md so validation requires safe dependency handling rather than mandatory automatic installation.
  9. Recommended replacement behavior:
markdown
1. Detect whether the approved, pinned UTOS version is installed.
2. If unavailable, enter read-only mode and provide installation instructions.
3. Install only after explicit user approval and verification of source, publisher, signature, version, and digest.
4. Load UTOS only after successful integrity and permission checks.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Automatic installation of universal-task-os gives a reference/template skill an unnecessary ability to modify the environment and pull in additional code or instructions without an explicit trust decision. If abused, this can be used for stealthy capability escalation, supply-chain exposure, or policy bypass by disguising active behavior as a prerequisite check.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises broad trigger phrases like '知识参考库', '技能生成', and '新领域技能', which can overlap with ordinary requests for help creating knowledge resources. In an agent environment, this can cause unintended invocation of a meta-skill that generates artifacts and changes workflow behavior when the user may have only wanted normal assistance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation rule '用户请求创建新的领域知识参考库/领域负载物技能时激活' is ambiguous because 'knowledge reference library' is a common request category that does not necessarily imply permission to invoke a generator skill. This ambiguity increases the chance of overreach, where the agent may switch from advisory behavior to artifact-generation behavior without clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to 'write the generated skill into the specified directory' describes file modification behavior without any user-facing warning, confirmation, or safety constraints. In a tool-enabled agent, this can lead to unexpected filesystem writes, overwriting existing content, or placement into sensitive paths if the directory is user-controlled or inferred unsafely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase example uses a very broad natural-language pattern (e.g., '帮我做一个XX领域知识参考库'), which can match many ordinary user requests and cause this meta-skill to activate when the user did not explicitly intend to invoke a skill generator. In a meta-skill that creates new domain payload skills, over-broad activation increases the chance of unintended scope capture, policy bypass via misrouting, and generation of sensitive or higher-risk artifacts without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

该文档将输入描述为“从用户输入'帮我做一个XX领域知识参考库'到完整技能产出”的标准流程,其中“帮我做一个...”属于常见日常请求句式,缺少更具体的触发边界或限定上下文。文档也没有提供负例、排除条件或明确说明仅在特定工具/命令环境下激活,因此存在触发范围过宽的问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The placeholder name {技能中文名} explicitly requires a Chinese skill name, which imposes a language choice in the generated skill template. The file does not provide an opt-in mechanism or explain that this template is limited to a Chinese-language or region-specific context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template presents generated skills as non-executing reference repositories, but it also specifies behavior that causes the skill to install and load another skill at activation time. This creates a hidden capability boundary violation: consumers may trust the skill as passive documentation while it actually initiates dependency changes and expands runtime privileges.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template contains contradictory security-significant semantics: it claims the skill is limited to reference lookup without UTOS, yet also instructs installation attempts during activation. Such inconsistency undermines user expectations and reviewability, making it easier to smuggle active side effects into ostensibly passive skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The checklist is written entirely in Chinese and includes prescriptive wording such as requiring specific Chinese field names and rejecting Chinese in certain mapping fields, but it does not state that the skill is region-specific or provide any user language opt-in. This can violate language/locale policy when used in broader environments where users are not expected to operate in Chinese only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

整份技能工作流文档以中文固定描述生成与交付流程,但未说明是否允许用户选择其他语言,也未将中文限定解释为特定地区或合规要求。按照语言/locale 政策,若技能隐含强制特定语言而无用户选择或合理说明,可能构成自然语言策略问题。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.