T09 · Insecure Skill Coding Practices
- Location
scripts/game_data_parser.py:83- Finding
CSV Formula Injection in Exported Game Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill appears to be a local game-development helper, with some broad and risky build/export capabilities that users should control carefully.
Install only if you are comfortable with a skill that can guide local project reads/writes and Unity builds. Ask the agent to confirm before editing saves, changing versioned project files, signing, uploading, or opening exported CSVs from untrusted data in spreadsheet software.
scripts/game_data_parser.py:83CSV Formula Injection in Exported Game Data
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
"-logFile", "build.log"
]
env = os.environ.copy()
env["UNITY_OUTPUT_PATH"] = str(output_path)
result = subprocess.run(cmd, env=env, capture_output=True, text=True)
if result.returncode == 0:
The skill advertises capabilities that clearly imply shell execution, file read/write, and environment access, but it does not declare any explicit tool scope or permissions boundaries. In an agent environment, this can cause the skill to be invoked with overly broad ambient authority, enabling unintended file modification, build/sign/upload actions, or execution of local commands without clear user-facing constraints.
The trigger description is extremely broad and covers many common game-development workflows, increasing the chance the skill will auto-match in contexts where sensitive actions are not expected. Because the skill includes risky operations like build automation, save editing, and packaging/signing, overbroad routing can lead to the wrong skill handling a task and exercising unnecessary privileges.
The skill description mentions modifying save files, asset packaging, version updates, signing, and uploads, but it does not provide a prominent warning that these operations can be destructive, irreversible, or security-sensitive. Users or upstream agents may treat the skill as routine project assistance and unintentionally permit actions that alter project artifacts, credentials-backed release flows, or player data.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if Path(p).exists():
return p
# 尝试从 PATH 查找
result = subprocess.run(['where', 'Unity'], capture_output=True, text=True)
if result.returncode == 0:
return result.stdout.strip().split('\n')[0]
return None
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
]
print(f"[INFO] 构建命令: {' '.join(cmd[:6])} ...")
result = subprocess.run(cmd, capture_output=True, text=True)
if result.returncode == 0:
print(f"[OK] 构建成功: {output}")
return True
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
env = os.environ.copy()
env["UNITY_OUTPUT_PATH"] = str(output_path)
result = subprocess.run(cmd, env=env, capture_output=True, text=True)
if result.returncode == 0:
print(f"[OK] 构建成功: {output_path}")
return True
This code file contains natural-language strings that force a specific language for the interface, beginning with the module docstring. Under the policy, language constraints should not be imposed without user opt-in or clear justification that the tool is region-specific.
The script presents operational messages and CLI help text only in Chinese, and this pattern continues throughout the file. Because no language selection mechanism or locale justification is provided, this is a natural-language policy violation.
This code file contains natural-language descriptions and user-facing messages in Chinese, beginning with the module docstring. Because the skill does not offer a language/locale choice or justify being region-specific, it violates the policy against forcing a specific language without user opt-in.
The argparse description, subcommand help, and argument help strings are all presented only in Chinese. Users are not given any opt-in or alternative locale, so the skill enforces a specific language in its interactive interface.
No suspicious patterns detected.