Back to skill

Security audit

COPPA Check - COPPA合规检查

Security checks for vulnerabilities and agentic risk

Overview

This COPPA checker mostly matches its stated cloud-scoring purpose, but it needs review because the advertised offline preview still contacts the cloud and HTML reports trust cloud-provided text too much.

Review before installing if you require a truly offline preview or will generate HTML reports. Use the skill only when you are comfortable sending questionnaire answers, an API key or anonymous trial ID, and normal network metadata to compliancehub.cn; avoid opening HTML reports from untrusted cloud responses until output escaping is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/coppa-check.py:358
Finding

Advertised offline preview performs an undisclosed network request

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/coppa-check.py:317
Finding

Cloud-controlled report fields are embedded into HTML without escaping

Content
View full analysis
= 80 else "#ff9800" if score >= 60 else "#f44336" rows = "" current_cat = "" for r in items: if r.get("category_name") != current_cat: current_cat = r.get("category_name", "") rows += f'{current_cat}\n' icon = "✅" if r.get("passed") else "❌" cls = "pass" if r.get("passed") else "fail" rec = r.get("recommendation") or "Keep it up" rows += f"""{icon}{r.get('name')}{r.get('legal_ref') or ''}{cls.upper()}{rec}\n""" ``` ### Technical Analysis The HTML renderer directly interpolates remotely supplied values, including `category_name`, `name`, `legal_ref`, and `recommendation`. No HTML escaping is applied, and the cloud response is not validated against a restrictive schema. If any of these fields contains HTML markup, event-handler attributes, or script-capable elements, the content is written verbatim into the generated report. The resulting file becomes an HTML-injection or stored cross-site-scripting payload when opened in a browser. Exploitation requires control over the service response. This could arise through compromise of the cloud service, unauthorized modification of its rule data, or another serv ...[truncated 1369 chars]
Remediation
View remediation
``` 6. Add regression tests containing payloads such as `
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code presents important user-facing disclosures about anonymous trial mode and cloud submission only in Chinese, while the rest of the skill is largely English. That creates a language/locale policy issue because users are forced into a specific language for critical notices without any opt-in or alternative locale selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill title and overview switch between English and Chinese, and later usage guidance continues using Chinese terms like '检查' without stating a language preference or offering an opt-in choice. This can violate language/locale policy when a skill imposes mixed or specific language output on users without consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.