Back to skill

Security audit

Bug问题上报

Security checks for vulnerabilities and agentic risk

Overview

This bug-reporting skill is purpose-aligned, but it should go to Review because it auto-writes reports to a WeCom sheet using an exposed webhook secret and avoidable install/script risks.

Install only if this is intentionally tied to the specific WeCom smart sheet. The publisher should rotate the exposed webhook key, move it to protected configuration, remove or pin the unused npm dependency, use a safe JSON encoder and temporary-file handling, and require explicit user confirmation before submitting reports. Users should avoid putting credentials, personal data, or incident details into reports until those controls exist.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/add_bug.sh:7
Finding

Hardcoded WeCom Webhook Credential

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned and Unused npm Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/add_bug.sh:13
Finding

Predictable Shared Temporary File Enables Symlink and Concurrency Attacks

Content
View full analysis
/tmp/bug_request.json <
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/add_bug.sh:10
Finding

Unescaped User Input Permits JSON Structure Injection

Content
View full analysis
/tmp/bug_request.json <
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are overly broad, such as general expressions like '有xxx问题' or 'xxxBug', which can match ordinary conversation. Because the skill auto-submits content to an external webhook, accidental activation can exfiltrate user text and create unwanted records without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill automatically sends user-provided problem descriptions to an external enterprise webhook but does not warn users that their content will be transmitted outside the current chat context. This creates a privacy and data-governance risk, especially if users include sensitive internal details, personal data, or credentials in bug reports.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation contains a live WeCom webhook URL with its secret key embedded directly in the skill file. Anyone who can view or reuse this skill can send arbitrary records to the associated smart sheet, causing unauthorized data injection, spam, or abuse outside the intended bug-report workflow.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/add_bug.sh (reported line 46)May include surrounding context.

sh
-d @/tmp/bug_request.json)

# 清理
rm -f /tmp/bug_request.json

# 检查是否成功
if echo "$RESPONSE" | grep -q '"errcode":0'; then

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill appears capable of making outbound requests and installing/running a binary (mcporter) but does not declare a restrictive tool scope such as permissions or allowed-tools. In an agent environment, missing scope boundaries increases the chance the skill can invoke shell/network capabilities more broadly than intended, especially when combined with automatic triggering.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documentation does not clearly define when the automation should or should not trigger, leaving behavior ambiguous. In context, that ambiguity is risky because the action is not local-only; it performs an external write to a corporate system, so misfires have real operational and privacy consequences.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This curl call sends collected user content to an external webhook endpoint, creating a clear data exfiltration path. In the context of a bug-reporting skill, users may include secrets, internal URLs, credentials, or incident details, so silent external transmission increases confidentiality risk.

Content

Scanner excerpt · scripts/add_bug.sh (reported line 41)May include surrounding context.

sh
EOF

# 发送请求
RESPONSE=$(curl -s -X POST "$WEBHOOK_URL" \
  -H "Content-Type: application/json" \
  -d @/tmp/bug_request.json)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script automatically transmits user-provided bug descriptions to an external WeCom webhook, which is a third-party service boundary from the user's perspective. Bug reports often contain sensitive internal details, and there is no disclosure, consent step, or minimization before exfiltrating that content off the local system.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script's natural-language comments and user-facing output are presented in Chinese only, without offering any language selection or opt-in. This can violate language/locale policy when a skill forces a specific language on users regardless of preference.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script writes the bug report body into a predictable temporary path under /tmp, which can expose sensitive report contents to other local users or processes depending on system configuration and race conditions. Even though the file is deleted later, the data exists on disk temporarily without any warning or secure handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.