T09 · Insecure Skill Coding Practices
- Location
scripts/schedule_intel.py:29- Finding
Shell Command Injection in Cron Task Creation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches an industry-intelligence assistant, but its scheduling helper can execute user-controlled shell input and create persistent cron tasks, so it needs careful review before installation.
Review this skill before installing. Use it only in an isolated environment, avoid the scheduling script until shell execution is fixed, prefer TAVILY_API_KEY over passing keys on the command line, do not use --break-system-packages, and confirm all recipients before sending or scheduling reports.
scripts/schedule_intel.py:29Shell Command Injection in Cron Task Creation
references/intro.md:3Unpinned Dependency Installation Bypasses System Package Protections
scripts/tavily_industry_search.py:65API Keys Accepted Through Process-Visible Command-Line Arguments
声明描述的是一个较完整的行业情报助手,包含自动监控、热点抓取、结构化简报生成、多渠道推送和定时编排。实际代码只覆盖其中一部分:Tavily 搜索和结构化简报生成。它没有看到任何企业微信、飞书、钉钉相关接口调用,也没有定时任务、调度器、后台监控、数据库持久化或分发逻辑。因此,代码行为是声明功能的一个子集,且缺少声明中较关键的自动化与推送能力,属于描述与实际行为不完全一致。未发现额外的未声明高风险能力;问题主要在于声明明显超出了该代码片段实际实现范围。
声明描述的是一个较完整的行业情报平台型技能,涵盖监控、分析、简报生成、分发和定时编排等多项能力。但提供的代码块只包含单一的 Tavily 搜索功能,没有看到任何定时执行、数据持久化、监控逻辑、结构化简报生成模板、或企业微信/飞书/钉钉推送代码。代码与声明中的“核心功能(1) Tavily搜索获取行业资讯”一致,但其余核心功能均未在该代码块中体现。因此,该描述相对于此代码块明显夸大了能力范围,构成描述与实际行为不匹配。
The subprocess invocation grants the user indirect control over a powerful system tool through shell evaluation. Because this is an industry-intelligence assistant, shell-level scheduling is not inherently required for end users, so the mismatch between capability and business purpose makes abuse more dangerous and easier to overlook.
f'--enabled'
)
print(f"执行命令: {cmd}")
result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
return result
The skill advertises shell execution, environment-variable use, and file-writing behavior through its documented commands, but it does not declare any explicit tool scope or permissions. This creates a least-privilege failure: operators and enforcement layers cannot clearly constrain what the skill may access, increasing the chance of unintended command execution, secret exposure, or filesystem modification.
The skill promotes automated pushing of collected reports to enterprise messaging platforms and recurring scheduled delivery without clearly warning that content will leave the local workflow and may be sent unattended. This can lead to accidental disclosure of sensitive internal research, competitor tracking notes, or misrouted reports to external recipients or large internal groups.
The push instructions tell users how to deliver a report file to WeCom/Feishu/DingTalk but omit any warning that the entire file contents will be transmitted to configured enterprise recipients. In an intelligence-collection context, reports may contain proprietary summaries, sensitive URLs, or internal commentary, so silent delivery behavior materially raises data-leak risk.
The scheduling instructions allow creation of recurring unattended push tasks but do not warn users that automation may repeatedly collect and distribute content without further review. In this skill context, that increases the risk of persistent misconfiguration, repeated sensitive-data disclosure, spam, or unnoticed distribution to the wrong audience.
The report is entirely framed in Chinese, including the title and section labels, with no indication that language choice is optional or limited to a China-specific use case. This creates a natural-language locale policy concern because the skill appears to enforce a specific language without user opt-in.
The script exposes a --language zh|en option, but all user-facing descriptions, progress messages, section headers, and saved-report labels are hardcoded in Chinese. This creates a language/locale policy issue because users are not actually given a functioning language choice despite the apparent opt-in mechanism.
The payload message explicitly instructs the downstream agent to output results in Chinese. This is a natural-language locale constraint, and the file does not offer the user any language choice or explain why Chinese is mandatory.
The script builds a shell command by interpolating user-controlled values such as query, schedule, channel, and timezone into a single string, then executes it with shell=True. This enables command injection if an attacker supplies shell metacharacters or crafted quoting, and the scheduled-task context can persist the malicious payload for repeated execution.
f'--enabled'
)
print(f"执行命令: {cmd}")
result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
return result
This helper exposes a broader-than-necessary execution surface by dynamically constructing and executing shell commands for scheduling. In this skill's context, the danger is elevated because untrusted input is used to create persistent cron jobs, so a single injection can both execute immediately and install recurring malicious behavior.
Natural-language strings such as the title, usage text, argument descriptions, and output labels are all Chinese-only. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless a locale restriction is explicitly documented and justified.
The manifest description is entirely in Chinese and frames the skill's use cases in that language, which can amount to an implicit locale/language constraint. Although one script later exposes a zh|en parameter, the top-level natural-language description does not clearly state that users may choose their preferred language.
The guide instructs users to set a Tavily API key directly in configuration but does not state that the key is a sensitive secret or recommend secure handling practices. This can lead to accidental exposure through shell history, shared configs, screenshots, or commits, enabling unauthorized use of the API and possible data/account abuse.
The documentation encourages scheduled push delivery to WeCom/Feishu/DingTalk without warning that collected intelligence content may be transmitted to third-party messaging platforms. In an enterprise-intelligence context, this can cause unintentional external distribution of sensitive summaries, competitor tracking data, or proprietary analysis.
This Python file performs an external API call with client.search(...), sending the supplied query to a third-party service. Although the script name implies search behavior, there is no explicit warning in code comments, docstrings, or runtime output that user-provided search terms are transmitted off-box to Tavily.
No suspicious patterns detected.