Back to skill

Security audit

AI Act Check - 欧盟 AI Act 合规检查工具

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed EU AI Act checklist tool that sends answers to a fixed cloud service for scoring, with some non-blocking security and quality issues to consider.

Install only if you are comfortable sending your checklist answers, and either an API key or anonymous trial id, to compliancehub.cn for scored runs. Prefer the offline preview for sensitive projects, and treat generated HTML reports cautiously until remote fields are escaped.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ai-act-check.py:408
Finding

Unescaped Remote Content in Generated HTML Reports

Content
View full analysis
{current_cat}\n' icon = "✅" if r.get("passed") else "❌" cls = "pass" if r.get("passed") else "fail" sev = r.get("severity") or "" sev_badge = "" if sev: color = sev_cls.get(sev, "#64748b") sev_badge = f'{sev_label.get(sev, sev)}' rec = r.get("recommendation") or "Keep it up" meta = r.get("meta") or {} rt = meta.get("remediation_template") if not r.get("passed") and rt: rec = f"🔧 {rt.get('summary', '')}(整改期限约 {rt.get('deadline_days', '')} 天)" case_html = "" case_keys = (r.get("meta") or {}).get("related_case_keys") or [] if case_keys and cases_by_ref: shown = 0 li = [] for ck in case_keys: for line in cases_by_ref.get(ck, []): li.append(f"
  • {line}
  • ") shown += 1 if shown >= 3: break if shown >= 3: break if li: case_html = f'
    📚 关联执法案例
      {"".join(li)}
    ' rows += f"""{icon}{r.get('name')}{r.get('legal_ref') or ''}{sev_badge}{cls.upper()}{rec}{case_html}\n""" ``` The generated report is subsequently written to a user-selected file: ```python if args.output: with open(args.output, "w", encoding="utf-8") as f: f.write(report) ``` ### Technical Analysis The HTML renderer inserts values obtained from clou ...[truncated 2807 chars]
    Remediation
    View remediation
    ``` Output encoding remains required because a CSP does not prevent all markup injection or report manipulation. 6. Add regression tests covering all remotely sourced fields with payloads such as: ```html </td><form>...</form> ``` Tests should verify that these strings appear only as encoded text and cannot create DOM elements or executable handlers. 7. Consider generating the report through a template system with automatic HTML escaping rather than manually concatenating HTML strings. ]]>
    Vulnerability Patterns
    • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
    • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
    Findings (3)

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The file’s user-facing description and prompts are predominantly in Chinese, and the generated HTML explicitly sets lang="zh-CN". The skill does not present this as an opt-in or region-specific requirement, so it effectively imposes a specific language/locale on users.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    89% confidence
    Finding

    The manifest states a fixed locale preference of zh-CN and says interaction and prompts are primarily in Chinese, while English is only provided on demand. This creates a language-policy concern because the default language is imposed unless the user proactively requests otherwise, rather than being offered as an explicit choice up front.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    Low
    Category
    Not specified by scanner
    Confidence
    97% confidence
    Finding

    The module and surrounding code clearly implement an EU AI Act compliance checker, using RULES_URL derived from this skill's slug. The docstring's reference to "pipl-check items" describes a different skill/domain, so it actively misstates what the function is retrieving.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.