Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md python scripts/skill_visibility.py <命令> [开关]
Security audit
Security checks for vulnerabilities and agentic risk
The skill makes disclosed WorkBuddy visibility/restoration changes and includes higher-impact options, but they are scoped, documented, and user-directed.
Before installing, confirm you want a skill that can copy/delete WorkBuddy skill directories and, if explicitly invoked, patch WorkBuddy's renderer bundle. Use list/status first, review restore --dry-run output before deletion, and avoid the bundle command unless you accept the higher risk and have verified the target paths.
Referenced artifact was not completely inspected
python scripts/skill_visibility.py <命令> [开关]
The script reads environment variables (WORKBUDDY_APP_ROOT, WORKBUDDY_CONFIG_DIR, LOCALAPPDATA, ProgramFiles, ProgramFiles(x86)) to influence filesystem targeting, but the capability is not declared by the skill metadata. In a security-sensitive agent environment, undeclared environment access reduces transparency and can let execution context unexpectedly steer which installation or config paths are modified, especially because this script can delete directories and patch application assets.
This code file embeds its primary natural-language documentation and user-visible CLI messages in Chinese, which effectively forces a specific language on users. The file does not offer any language selection, fallback, or justification that the skill is intended only for a Chinese-speaking or region-specific audience.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
try:
with open(tmp, "wb") as handle:
handle.write(text.encode("utf-8"))
proc = subprocess.run([node, "--check", tmp], capture_output=True, text=True, timeout=300)
if proc.returncode != 0:
detail = (proc.stderr or proc.stdout or "").strip()
if detail:
No suspicious patterns detected.