Back to skill

Security audit

再再测试一下

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only Tencent Cloud TI-ONE query helper, with expected cloud credential use and no evidence of hidden execution, persistence, or destructive behavior.

Install only if you intend to let the skill read TI-ONE resource metadata, logs, events, and service details from your Tencent Cloud account. Use a virtual environment or otherwise controlled package source for tccli, and provide credentials restricted to the required read-only Describe* actions and intended regions/resources.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Unpinned Tencent Cloud CLI Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:23-27
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

json
{
  "id": "pip-tccli",
  "kind": "pip",
  "package": "tccli",
  "bins": ["tccli"],
  "label": "Install tccli (Tencent Cloud CLI)"
}

The documentation also recommends an unpinned installation at SKILL.md:64-69:

bash
# tccli (Tencent Cloud command-line tool, used internally)
pip3 install tccli

# jq (JSON processing)
apt install jq    # Ubuntu/Debian
brew install jq   # macOS

The resulting executable is invoked at scripts/common.sh:74-89:

bash
call_tione_api() {
    local action="$1"
    local region="$2"
    shift 2
    local extra_args=("$@")

    check_dependencies
    check_credentials

    log_info "Calling API: tione ${action} --region ${region}"
    log_debug "Additional arguments: ${extra_args[*]:-none}"

    local result
    local exit_code=0

    result=$(tccli tione "$action" --region "$region" "${extra_args[@]}" 2>&1) || exit_code=$?

Technical Analysis

The tccli package is installed without a fixed version, lock file, or cryptographic integrity hash. Consequently, the installed code depends on whatever artifact the package repository resolves at installation time. The project then executes the resulting tccli binary while Tencent Cloud credentials are present in the process environment.

An unpinned package is not inherently malicious, and the audit found no evidence that the named tccli package is currently compromised. Nevertheless, the configuration creates a supply-chain exposure: a compromised publisher account, package repository, release process, or unexpectedly incompatible future release could introduce code that executes during installation or whenever tccli is invoked.

Attack Path

  1. An attacker compromises the package publisher, distribution repositor ...[truncated 1375 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin tccli to a specifically reviewed version in both metadata and documentation, for example:

    bash
    python3 -m pip install "tccli==<reviewed-version>"
    
  2. Generate a requirements lock file containing cryptographic hashes and install with hash verification:

    bash
    python3 -m pip install --require-hashes -r requirements.lock
    
  3. Explicitly configure the trusted official package index rather than relying on ambient or user-controlled index settings. Review PIP_INDEX_URL, PIP_EXTRA_INDEX_URL, and related configuration before installation.

  4. Install the dependency in a dedicated virtual environment rather than into the system or user-wide Python environment.

  5. Avoid running dependency installation or Skill execution as root or another privileged account.

  6. Use short-lived Tencent Cloud credentials whenever supported. Apply an IAM policy that permits only the required TI-ONE read-only Describe* actions and required regions/resources.

  7. Record and periodically review the pinned package's provenance, checksums, release notes, and transitive dependencies before upgrading.

  8. If the platform supports it, distribute a reviewed, signed artifact or container image whose dependency versions and digests are immutable.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (14)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains natural-language interface text such as the header comments, usage output, option descriptions, and examples only in Chinese. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

All visible comments, usage text, and error/help messaging are written in Chinese, which imposes a specific language on users. Under the policy, forcing a language without user opt-in or a clearly justified regional constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and all user-facing help text are written in Chinese, including usage, options, and error/help messaging. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments, usage text, examples, and error/help output are entirely in Chinese, which imposes a specific language on users. Under the policy, a language constraint should either be optional via user choice or clearly documented as a justified locale-specific tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language. This shell script presents its descriptions, usage text, option explanations, and examples only in Chinese, with no indication of language selection or justification for a Chinese-only locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

All user-facing natural-language strings in the script, including comments, usage text, errors, and logs, are in Chinese. Under the stated policy, forcing a specific language without opt-in or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文档从标题到正文均固定为中文,没有说明这是面向特定中文用户群体的受限文档,也没有提供其他语言选项或用户选择机制。根据规则,强制特定语言且无用户选择属于自然语言层面的语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's header, usage text, option descriptions, and examples are presented exclusively in Chinese. This imposes a fixed language on users without any opt-in or indication that the skill is intentionally limited to a Chinese-speaking or region-specific audience, which matches the locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script's comments, usage text, and error/help messages are entirely in Chinese, which imposes a specific language on users. Under the policy, locale or language constraints should be optional or clearly justified as region-specific; this file provides no such opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script’s comments, usage text, option descriptions, and error/help messages are all presented in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments, usage text, examples, and error/help output are all presented in Chinese, which imposes a specific language on users. The file does not offer an alternative language, user opt-in, or a documented justification that this skill is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s user-facing descriptions, help text, and error messages are entirely in Chinese, including the usage output and operational log strings. For a general-purpose CLI skill, this imposes a specific language without any opt-in, fallback, or documented region-specific justification, matching the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments, usage text, and examples are entirely in Chinese, which imposes a specific language on users without any visible opt-in or alternative locale support. Under the policy, language restrictions should either offer user choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

All user-facing natural-language strings in comments, help text, and error messages are in Chinese, and the script provides no option to select another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.