Back to skill

Security audit

Mysteel_MarketAnalysis

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent market-analysis purpose, but it uses a raw shell command template with user input and asks users to store an API key in a plaintext project file.

Review this skill before installing. Use it only if you trust the Mysteel endpoint and are comfortable sending the full market-analysis query to that service. Do not store a production API key in the checked-in references/api_key.md file; prefer an environment variable or protected local secret outside the skill tree. The exec command template should be changed to pass arguments without shell interpolation before use with untrusted query text.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:44
Finding

Shell Command Injection Through Direct Query Interpolation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 44-53
Vulnerability Type: Shell command injection
Risk Level: High

Relevant code snippet:

json
{
  "tool": "exec",
  "command": "python3 scripts/analyze.py --query \"<user query>\"",
  "yieldMs": 150000,
  "timeout": 300,
  "background": false
}

The placeholder above is the English rendering of the user-query placeholder in the source instruction.

Technical Analysis

The Skill instructs the agent to insert a user-derived query directly into a command string delimited by double quotes. If the exec implementation passes this string through a command shell, an attacker can include a double quote followed by shell operators to terminate the intended argument and append arbitrary commands.

Argument parsing in scripts/analyze.py does not prevent this vulnerability. Shell metacharacters are interpreted before Python starts and before argparse receives the resulting arguments.

The vulnerable data flow is:

  1. An untrusted user supplies the market-analysis query.
  2. The agent interpolates that query into the documented command template.
  3. The exec tool submits the resulting command string to a shell.
  4. Shell syntax embedded in the query may be interpreted as additional commands.

Attack Path

  1. An attacker submits a query containing a closing double quote, shell separator, command, and comment marker, following the conceptual pattern:
    text
    benign text"; attacker-command; #
    
  2. The agent substitutes the complete query into the required command field.
  3. The closing quote terminates the --query value.
  4. The shell separator starts an additional attacker-selected command.
  5. The comment marker suppresses the trailing quote or other remaining command text.
  6. The injected command executes under the same operating-system identity and permissions as the agent or exec process.

...[truncated 750 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not construct shell command strings using direct interpolation of user-controlled input.
  • Invoke the program with an argument array and disable shell processing. The logical invocation should be equivalent to:
    python
    ["python3", "scripts/analyze.py", "--query", query]
    
  • If the execution interface accepts only command strings, change the interface or transfer the query through a safely generated input file or standard input.
  • Do not rely on manual replacement, simple quote escaping, regular expressions, or a metacharacter blacklist as the primary defense.
  • Apply input length limits and reject control characters as defense-in-depth measures.
  • Run the script under a restricted account with minimal filesystem and network permissions.
  • Add automated tests using quotes, command separators, command substitutions, newlines, and redirection operators to verify that query content is always handled as one literal argument.

T09 · Insecure Skill Coding Practices

Warning
Location
references/api_key.md:1
Finding

API Credential Stored in a Plaintext Project File

Content
View full analysis

Vulnerability Details

File Location: references/api_key.md, lines 1-2; credential-loading implementation in scripts/analyze.py, lines 53-76
Vulnerability Type: Insecure plaintext secret storage
Risk Level: Medium

Relevant configuration snippet:

text
# Mysteel API key configuration file
YOUR_API_KEY_HERE

Relevant credential-loading code:

python
with open(api_key_file, 'r', encoding='utf-8') as f:
    content = f.read()

lines = [line.strip() for line in content.split('\n') if line.strip()]

if len(lines) < 2:
    raise Exception(
        f'API key file format error, requires at least 2 lines\n'
        f'Current valid lines: {len(lines)}'
    )

api_key = lines[1]

if not api_key or api_key == 'YOUR_API_KEY_HERE':
    raise Exception(
        'API key not configured\n'
        'Please replace YOUR_API_KEY_HERE with actual MYSTEEL_CLAW_APIKEY in references/api_key.md'
    )

return api_key

No live credential was present during the audit. However, the documented workflow requires replacing the placeholder in a file located inside the project tree. The script then reads the resulting secret directly from that plaintext file.

This design exposes the credential to accidental source-control commits, project archives, artifact packaging, backups, broad filesystem permissions, and any process or user able to read the project directory. The project structure does not show an ignore rule, packaging exclusion, permission check, or secret-manager integration protecting the file.

The credential is sent in the token header only to the fixed HTTPS Mysteel endpoint. That network transmission is declared and necessary for the Skill’s stated API-backed functionality. The principal issue is local storage and lifecycle management rather than the expected API transmission.

Attack Path

  1. A user replaces YOUR_API_KEY_HERE with a valid Mysteel API key as instructed ...[truncated 1156 chars]
Remediation
View remediation

Remediation Suggestions

  • Retrieve the API key from a managed secret store or a protected environment variable rather than a tracked project file.
  • Keep secret-bearing local files outside the project tree.
  • If local file storage is unavoidable, use a non-versioned file with restrictive owner-only permissions and verify those permissions before reading it.
  • Add the secret path to source-control ignore rules and artifact/package exclusion rules.
  • Retain only a separate example file containing the placeholder.
  • Prevent the credential from appearing in logs, exception messages, command-line arguments, or generated reports.
  • Use a narrowly scoped API key with expiration, usage monitoring, rate limits, and a documented rotation and revocation process.
  • Rotate any real key that may previously have been committed, archived, or distributed with the project.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill directs the agent to read a local credential file and invoke a networked analysis script, but it does not declare any explicit tool/permission scope. That weakens sandboxing and reviewability, making it easier for the skill to access files or external services without clear least-privilege boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language instructions, prompts, and examples are all presented in Chinese, and the skill does not indicate that users may choose another language or that the Chinese-only behavior is a required regional constraint. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger conditions are broad enough to match many ordinary market-analysis questions, which can cause unintended invocation of a skill that reads credentials and transmits queries to an internal service. This increases the chance of accidental data handling or external calls when the user did not clearly consent to using this specific integration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to read an API key from disk and send user-derived queries to an internal interface, but it provides no user-facing notice about credential use, remote transmission, or handling of potentially sensitive prompts. This creates a transparency and data-handling risk, especially if users are unaware their requests are being sent to a third-party/internal backend.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

This code performs an outbound HTTP POST containing the full query and an API token to an external/internal service. Although this is core functionality, the transmission boundary is real and risky because the skill handles free-form user input that may contain confidential commercial information; the lack of minimization, warning, or validation makes accidental data leakage more likely.

Content

Scanner excerpt · scripts/analyze.py (reported line 110)May include surrounding context.

python
}
    
    try:
        response = requests.post(
            url,
            json=payload,
            headers=headers,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sends the user-provided query directly to a remote Mysteel endpoint without any user-facing notice, consent step, or data classification guard. In a market-analysis skill, queries can easily contain sensitive business context, trading intent, supplier/customer names, or proprietary analysis questions, so silent transmission creates a real confidentiality and privacy risk even though network access is expected for the skill’s function.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

Line L1 presents the skill-related content entirely in Chinese, with no indication that language selection is optional or that the file is intended only for a specific locale. This can conflict with organizational language/locale policy when users are not offered a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language comment and code explicitly enforce UTF-8 output for stdout and stderr regardless of user environment. This is a locale/encoding policy choice applied automatically, and the file does not offer a user choice or opt-in mechanism.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.