Back to skill

Security audit

AI Persona Check - AI 拟人化互动服务合规检查

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent and purpose-aligned, but its HTML report can render cloud-supplied text without escaping, which creates a review-worthy browser/report integrity risk.

Review before installing. Use --non-interactive if you want an offline preview, and only run scored mode if you are comfortable sending compliance answers plus an API key or anonymous trial ID to compliancehub.cn. Avoid HTML output or treat generated HTML reports as untrusted until dynamic report fields are escaped.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ai-persona-check.py:385
Finding

Unescaped Cloud-Controlled Data in Generated HTML Report

Content
View full analysis
= 80 else "#ff9800" if score >= 60 else "#f44336" rows = "" current_cat = "" for r in items: if r.get("category_name") != current_cat: current_cat = r.get("category_name", "") rows += f'{current_cat}\n' icon = "✅" if r.get("passed") else "❌" cls = "pass" if r.get("passed") else "fail" rec = r.get("recommendation") or "继续保持" rows += f"""{icon}{r.get('name')}{r.get('legal_ref') or ''}{cls.upper()}{rec}\n""" ``` ### Technical Analysis The HTML renderer directly interpolates report values into HTML without context-appropriate escaping. The affected values include: - `category_name` - `name` - `legal_ref` - `recommendation` During cloud-scored operation, these fields may originate from responses returned by `compliancehub.cn`. They therefore cross a remote trust boundary before being inserted into a locally generated HTML document. An attacker who compromises the cloud service, its rule data, or the response delivery path could place HTML markup or executable browser content in these fields. Because the generated document has no escaping or restrictive Content Security Policy, the browser will interpret injected markup when the user opens the report. The pinned HTTPS endpoint reduces redirection and network interception risks, but it does not protect against malicious or compromised upstream data. ### Attack Path 1. The user starts a scored assessment and requests HTML output, such as: ```bash python3 scripts/ai-persona-check.py --format ...[truncated 1350 chars]
Remediation
View remediation
' f'{category}' f'\n' ) rows += ( f'{icon}{name}' f'{legal_ref}{cls.upper()}' f'{recommendation}\n' ) ``` 2. Prefer a maintained template engine with automatic HTML escaping if third-party dependencies are acceptable. 3. Validate cloud response schemas and reject values with unexpected types or excessive lengths. Validation should supplement, not replace, output escaping. 4. Add a restrictive Content Security Policy to generated reports, for example: ```html ``` 5. Add regression tests using payloads such as ``, ``, quotes, and malformed tags. Verify that the generated document contains escaped text and no executable elements or event-handler attributes. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest explicitly advertises cloud-based 'real scoring,' anonymous trial usage, API key handling, and local filesystem writes, but it does not clearly disclose what user data will be transmitted to the remote service or what local state will be created. In a compliance-checking skill, users may paste sensitive policy text or business data, so undisclosed network transmission and persistence materially increase privacy and trust risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents the skill as a general-purpose compliance checker, but the title and all user-facing interaction are hard-coded in Chinese. Under the policy rule for language/locale, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The interactive flow requires users to read and respond to Chinese prompts, and the report generation functions also emit Chinese-only content. Because the skill does not offer a language choice and is not clearly scoped in code comments or interface text as a justified locale-specific tool, this violates the language/locale policy criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The only natural-language description provided is in Chinese, and the skill name/display name are also Chinese-oriented, with no indication that users can choose another language or that the locale restriction is intentional. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The module docstring asserts that outbound network calls are limited and that no other data leaves the machine. However, the skill also constructs account/registration URLs with attribution and optional anon_id parameters for user handoff, which broadens the described data-sharing behavior beyond the narrow statement in the docstring. This is a documentation-to-code inconsistency rather than a clear malicious capability.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.