Back to skill

Security audit

萤火虫空压机节能评估助手

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent branded compressor energy-report skill, but its HTML report instructions can place user-provided text directly into web output without requiring sanitization.

Install only if you want Chinese-language, Firefly-branded compressor energy reports. Prefer Markdown output or ensure all user-supplied fields are HTML-escaped before generating HTML; do not host generated reports in an authenticated or privileged web origin without sanitization and isolation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:17
Finding

Mandatory Commercial Content Alters Report Output

Content
View full analysis
萤火虫空压机  |  广州市萤火虫智能装备技术有限公司
服务热线:13825202084(邹先生) |  网址:www.fireflies.net.cn
邮箱:aifirefly@163.com  |  地址:广州市
本报告由 AI 辅助生成,仅供参考。精确数据以现场检测为准。
© {{CURRENT_YEAR}} 广州市萤火虫智能装备技术有限公司 版权所有 ``` ### Technical Analysis The Skill instructs the agent to always assume a fixed commercial identity and requires generated reports to include predetermined company branding, contact information, and a lead-generation path. These directives are not limited to cases where the user explicitly asks for a company-branded proposal. Consequently, loading the Skill changes the agent's output objective from neutral energy analysis to commercial promotion for a specific organization. The fixed footer also propagates the promotional content into reports that may subsequently b ...[truncated 1152 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:310
Finding

Unescaped Placeholder Substitution Permits HTML Injection in Generated Reports

Content
View full analysis
` 行,每年含节省/累计/净收益 - `{{CASE_REFERENCES_HTML}}` → 从案例库选择 2-3 个案例格式化为 HTML `
` 块 - `{{CURRENT_YEAR}}` → 当前年份 - `{{ROI_GAUGE_POS}}` → 回收期落在仪表盘的位置百分比 ``` Relevant substitution sinks in `assets/audit-report-template.html`: ```html
项目名称:{{PROJECT_NAME}}
``` ```html {{WARNING_CALLOUT}} ``` ```html

{{PRIMARY_SOLUTION_DESC}}

``` ```html {{CASHFLOW_ROWS}} ``` ```html

以下为萤火虫已完成类似项目的节能量化参考(客户信息已匿名处理):

{{CASE_REFERENCES_HTML}} ``` ### Technical Analysis The report-generation instructions require direct placeholder replacement but do not require HTML contextual encoding, validation, or sanitization. Some values, including the project or company name and compressor parameters, may originate from user input. Other placeholders intentionally accept complete HTML fragments. If literal replacement is used, attacker-controlled text can terminate the intended element and introduce arbitrary markup. For example, a malicious project name could contain: ```html
``` After direct substitution, the browser would parse the injected element as report markup. Event-handler attributes could execute JavaScript where the report viewer permits it. Even when script execution is restricted, an attacker ...[truncated 2190 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/audit-report-template.html (reported line 362)May include surrounding context.

html
</head>
<body>

  <!-- ========== COVER ========== -->
  <div class="cover">
    <div class="cover__logo"><span>萤</span>火虫空压机</div>
    <div class="cover__title">空压机系统节能审计报告</div>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/audit-report-template.html (reported line 422)May include surrounding context.

html
</div>
    </div>

    <!-- ========== 2. 现状分析 ========== -->
    <div class="section">
      <h2 class="section__title">二、现状分析</h2>

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L396 explicitly instructs the assistant to use '全中文输出' for all responses. This imposes a fixed language policy on users without offering a choice or documenting a necessary region-specific compliance reason, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The HTML root explicitly sets the document language to zh-CN, which imposes a specific locale on all rendered output. The file does not offer a language/locale choice or explain that the template is intentionally limited to a China-specific compliance or regional use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file is entirely presented in Chinese, and the usage instructions assume that language without any opt-in or alternative locale. Under the natural-language policy category, forcing a specific language without user choice can be a policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.