Back to skill

Security audit

HTML Mender

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently creates a local browser-editable copy of an HTML file and does not show hidden network, credential, destructive, or persistence behavior.

Install only if you want a local HTML visual editor. Use it on files you choose, keep the generated editable copy with its assets, and do not run it against live or authenticated webpages; pass --lang en if you prefer English UI.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
node scripts/inject-html-editor.mjs <input.html> \

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The runtime clearly operates on the current page DOM, uses location.href in draft metadata, injects UI into document.documentElement, and auto-starts without enforcing that the target is a local/saved HTML file. That creates a scope violation: if this skill is invoked on an arbitrary page, it can inspect and modify live page content despite the metadata promising local-only behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The runtime sets DEFAULT_LANG to zh-CN, and the language normalization logic falls back to that default for any non-en value. This means the skill imposes a specific locale unless the caller explicitly overrides it, which is a natural-language locale policy issue because users are not offered a neutral default or explicit opt-in before the language is chosen.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Draft saving stores the full current page URL together with page content patches, which can expose sensitive paths, query parameters, document locations, or identifiers unrelated to the editor’s stated purpose. In the context of a supposedly local HTML editor, persisting full URLs expands data collection beyond what is necessary and can leak browsing or file-location metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

On startup, the code writes htmlSlideMenderLanguage as zh-CN whenever options.lang is not exactly en, which silently forces a locale preference into storage. This is a policy concern because the skill selects and persists a specific language without explicit user choice or opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sets the default editor language to "zh-CN" when no language is provided. This is a natural-language locale choice imposed by default rather than offering a neutral default or requiring explicit user selection, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The normalizeLanguage function silently maps every value other than "en" to "zh-CN". This enforces a specific locale without user opt-in and may override user intent when they provide another language value.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown explicitly states --lang zh-CN|en with a default of zh-CN, which imposes a language choice unless the user or caller overrides it. The policy allows locale constraints when they are opt-in or clearly justified; here an alternative exists, but the default still forces a specific locale by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.