T09 · Insecure Skill Coding Practices
- Location
scripts/auto_fix.py:82- Finding
Shell Command Injection in Generated Repair Script
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a real Markdown knowledge-base auditor, but its bundled fix generator can create executable scripts that delete or rewrite files and has unsafe input-handling flaws.
Install only if you are comfortable reviewing generated scripts before running them. Use the scanner/report modes on trusted local Markdown folders, do not treat auto_fix.py as a safe dry-run, and avoid feeding it untrusted results JSON or knowledge bases until the repair-script generation, path validation, and HTML escaping issues are fixed.
scripts/auto_fix.py:82Shell Command Injection in Generated Repair Script
scripts/auto_fix.py:181Python Code Injection in Generated Repair Script
scripts/auto_fix.py:46Documented Dry-Run Is Not Implemented and Generated Script Contains Active Deletions
scripts/report_generator.py:299Stored HTML Injection Through Unescaped Scan Path
The code substantially matches the core declared purpose of auditing Markdown knowledge-base health: it scans Markdown files, detects empty/placeholder content, checks broken wiki links, evaluates content density, builds a graph, identifies isolated notes, and computes health scores. However, the description overstates several capabilities that are not implemented. There is no stale-file detection, no remediation/fix-plan generation, and no richer graph-fragmentation analysis beyond isolated nodes and central nodes. Reporting is limited to JSON output rather than actionable repair plans. Also, the claimed broad platform support is only implicit through generic Markdown scanning, not through platform-specific handling. Because these omitted capabilities are explicitly advertised and material, this is a description-behavior mismatch, though the primary purpose is broadly aligned.
The skill explicitly instructs use of shell commands and bundled scripts that can read and write files, but it declares no tool scope or allowed-tools boundaries. That creates an authorization gap where an agent may execute broader filesystem or shell actions than the skill's stated safe workflow implies, increasing the chance of unintended mutation or misuse.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Avoid:
- equating more notes with better knowledge
- deleting or rewriting files without confirmation
- checking external URLs by default on large vaults
- treating all orphan notes as bad; some are intentionally private/draft
- creating huge reports with no prioritized next action
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
Avoid:
- equating more notes with better knowledge
- deleting or rewriting files without confirmation
- checking external URLs by default on large vaults
- treating all orphan notes as bad; some are intentionally private/draft
- creating huge reports with no prioritized next action
This markdown file presents the skill evaluation entirely in Chinese, and there is no indication that users can choose their preferred language or that the skill is intentionally limited to a Chinese-speaking context. The policy explicitly flags language or locale constraints when they are imposed without user opt-in or clear justification.
This code file contains natural-language docstrings and user-facing output entirely in Chinese, including the tool description and runtime messages. Under the policy for language/locale, forcing a specific language without opt-in is a violation unless the locale restriction is explicitly justified, which is not present here.
This file generates executable shell and Python repair scripts that can delete or modify knowledge-base files based on scan results. In an auditing skill, crossing from analysis into action increases risk because untrusted or mistaken scan output can be converted into destructive operations, leading to data loss or unsafe changes if a user runs the generated script.
The generated shell script includes destructive commands such as rm and in-place sed edits, which gives a knowledge-base checker the ability to perform irreversible filesystem changes. Although file paths are shell-quoted, the danger is capability-based: if scan results are wrong, manipulated, or overly broad, the emitted script can delete files or mass-rewrite content when executed by the user.
This Python file contains natural-language descriptions and runtime status messages in Chinese, which imposes a specific language on users without any opt-in or fallback. The policy only allows fixed language behavior when the skill offers language choice or the locale restriction is clearly documented and justified, which is not present here.
The script prints user-facing status output such as scan progress and completion messages exclusively in Chinese. Because there is no option to select another language or clear documentation that the tool is region/language-specific, this is a natural-language locale policy violation.
The module docstring and all user-facing report content are written in Chinese, and the generated HTML explicitly declares lang="zh-CN". For a general-purpose report generator, this imposes a specific language/locale without user opt-in or any documented justification, which matches the language/locale policy violation category.
The file defines an HTML-escaping helper but fails to apply it to several values interpolated directly into the main HTML template, including results['scan_path'] and multiple score/stat fields. If the JSON input is attacker-controlled or derived from untrusted markdown metadata/paths, opening the generated report in a browser can trigger stored XSS in the local report context.
The natural-language prompt values are written entirely in Chinese across multiple test cases, which indicates the skill/test corpus expects a specific language by default. There is no visible opt-in, fallback, or justification that this skill is intentionally region-specific, so this creates a language/locale policy concern.
The document is entirely written in Chinese, including the title and all section content, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.
SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all user-facing content in Chinese only, with no indication that the skill is region-specific or that users can opt into another language.
该 markdown 文件的标题、说明和操作指引全部以中文呈现,没有提供用户可选择的语言版本,也没有解释这是仅面向中文用户或特定区域的技能。根据规则,强制单一语言而无用户 opt-in 属于自然语言层面的语言/locale 策略风险。
The generated script docstring says it is a '知识库自动修复脚本' and fix_empty_files() is documented as deleting empty shell files, yet the actual deletion call is commented out and only prints what would be deleted. This is an active mismatch between the script's stated intent and what it really does.
No suspicious patterns detected.