Back to skill

Security audit

llm-text-correct

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a Chinese text-correction skill, but it automatically mutates Python environments, installs large unpinned remote dependencies, and can batch-process local files with limited user control.

Install only if you are comfortable with a local skill that can install and update Python packages, download models, inspect GPU state, create persistent logs, and write corrected copies of files or whole folders. Prefer running it in an isolated disposable environment and avoid giving it directories containing sensitive drafts until dependency pinning, logging disclosure, and confirmation controls are improved.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
scripts/ensure_package.py:27
Finding

Import-Time Installation of Unpinned Third-Party Packages

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/config.py:29
Finding

Shared Virtual Environment and Excessive Unpinned Dependency Installation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (51)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 29)May include surrounding context.

text
venv/
ENV/
env/
.env

# Logs
logs/*.log

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A text-correction skill that silently configures persistent logging, creates log directories, writes log files, and rotates backups can expose user-provided text and file-path metadata beyond the immediate interaction. Because users may submit sensitive drafts or documents for correction, undisclosed logging increases privacy and data retention risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A text-correction skill that silently configures persistent logging, creates log directories, writes log files, and rotates backups can expose user-provided text and file-path metadata beyond the immediate interaction. Because users may submit sensitive drafts or documents for correction, undisclosed logging increases privacy and data retention risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A text-correction skill that silently configures persistent logging, creates log directories, writes log files, and rotates backups can expose user-provided text and file-path metadata beyond the immediate interaction. Because users may submit sensitive drafts or documents for correction, undisclosed logging increases privacy and data retention risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A text-correction skill that silently configures persistent logging, creates log directories, writes log files, and rotates backups can expose user-provided text and file-path metadata beyond the immediate interaction. Because users may submit sensitive drafts or documents for correction, undisclosed logging increases privacy and data retention risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims to perform Chinese text correction, yet this file immediately mutates the Python environment by reinstalling packaging components. This mismatch is a strong indicator of overprivileged and potentially unsafe behavior because users would not reasonably expect a text-correction skill to alter system dependencies.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file exposes a generic package-management primitive that can install arbitrary packages from PyPI, git sources, and local archives. In this skill context, that capability is unnecessary and materially increases the risk of supply-chain compromise, arbitrary code execution, and persistent environment tampering.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill is presented as a Chinese text-correction capability, but this file acts as an environment bootstrapper that creates virtual environments, inspects hardware, and installs packages. That scope mismatch is dangerous because it hides privileged system-changing behavior behind a benign user-facing description, undermining informed consent and security review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Audio-processing dependencies such as audio-separator, librosa, and pydub are unrelated to Chinese text correction and significantly expand the skill's capability surface. This discrepancy increases supply-chain risk, attack surface, and the likelihood that the skill is over-privileged or behaving outside user expectations.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/env_manager.py (reported line 222)May include surrounding context.

python
sys.exit(1)

    # 传递环境变量防止递归
    env = os.environ.copy()
    env["RUNNING_IN_VENV"] = "true"

    logger.info(f"   当前Python: {sys.executable}")

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script dynamically installs Python packages at runtime using pip, which creates a significant supply-chain and code-execution risk because package resolution and install hooks execute arbitrary third-party code during skill invocation. This is especially dangerous in an agent skill because a simple text-correction request can trigger network access and installation of mutable dependencies without prior review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger examples are broad enough to overlap with normal conversational editing requests, making accidental invocation more likely. In an agent framework, ambiguous triggering can route benign chat into a tool that reads or modifies files, which creates unnecessary exposure to local data and unintended side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly instructs the agent/user to correct all .txt files in a directory, which expands the operational scope from correcting a supplied text or single file to performing bulk actions over user-controlled file paths. In an agent setting, this increases the chance of unintended mass modification of files, especially if triggered from ordinary language without a strong confirmation boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes bulk file correction over a directory but does not prominently warn that this may alter many user files. Without clear notice, preview, backup, or confirmation guidance, users may authorize destructive or hard-to-review changes to large sets of documents.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises shell execution, file read/write, and environment interaction but does not declare a restrictive tool scope such as explicit permissions or allowed-tools. In practice, this means a user-invocable skill can perform broader local actions than its manifest communicates, increasing the chance of unintended file access or command execution if the invoked script is altered or behaves unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary editing or rewriting requests, which can cause over-activation of a skill that also has shell and file capabilities. Overbroad activation is risky in this context because it increases the chance that a higher-privilege local skill runs when a normal LLM response would have been sufficient.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation rules mix precise correction requests with broad intents like polishing, optimizing, and '帮我看看', making invocation ambiguous. In a skill that may touch files and invoke Python scripts, ambiguity makes accidental execution more dangerous because ordinary editorial assistance may route into a privileged local workflow without clear user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s natural-language description explicitly presents the tool as a Chinese text-correction script, and the user-facing argument/help strings throughout the CLI are only in Chinese. Under the policy, forcing a specific language without user opt-in or a clearly documented justification is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest emphasizes correcting Chinese text from direct input, long text, or a provided text file path. However, the module docstring and main logic implement an additional bulk-processing mode for directories, recursively scanning files and creating a sibling output directory with corrected copies.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script can fetch model artifacts from Hugging Face at runtime, introducing unpinned remote supply-chain risk and unexpected network access for a skill presented as local text correction. If an attacker controls the referenced repository, a dependency path, or the network environment, users may download tampered model files or expose operational metadata through outbound requests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Installing Python packages at runtime is dangerous because it executes package-manager operations and runs arbitrary install-time code from external package sources inside the user's environment. This greatly expands the trust boundary beyond text correction and creates supply-chain, persistence, and environment-integrity risks if package versions are compromised or unexpectedly changed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file header documents a package installation utility rather than text-correction logic, contradicting the skill's stated identity. This inconsistency is suspicious because it suggests hidden or unrelated operational behavior that may escape user scrutiny and increases the chance of unsafe privilege use.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
95% confidence
Finding

This code invokes pip to forcibly reinstall setuptools and wheel during module execution, mutating the Python environment without explicit user consent. Even though the command is hardcoded, automatic dependency changes at import time can downgrade security-sensitive tooling, break other packages, and create a supply-chain attack surface through package retrieval.

Content

Scanner excerpt · scripts/ensure_package.py (reported line 31)May include surrounding context.

python
"""专门为老项目(使用 pkg_resources 的 setup.py)修复 setuptools 版本"""
    logger.info("🔧 正在修复 setuptools 版本(兼容旧 GitHub 包构建)...")
    try:
        subprocess.check_call([
            sys.executable, "-m", "pip", "install",
            "--quiet", "--force-reinstall", "setuptools<=81.2.0", "wheel"
        ])

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module performs package-management actions immediately upon import by calling fix_setuptools_for_legacy_packages at top level. Import-time side effects are dangerous because merely loading the module triggers network/package operations and environment mutation without an explicit user action or consent boundary.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

The function dynamically imports a module name derived from parameters, which can trigger import-time code execution from attacker-controlled or malicious local modules. In this file the import is framed as an installation check, but it still executes arbitrary module top-level code if import_name is influenced by untrusted input.

Content

Scanner excerpt · scripts/ensure_package.py (reported line 81)May include surrounding context.

python
# 第一步:尝试 import 检查(最快)
    try:
        parts = import_name.split('.')
        mod = __import__(parts[0])
        for part in parts[1:]:
            mod = getattr(mod, part)
        if sub_import:

Static analysis

No suspicious patterns detected.