Back to skill

Security audit

SDF COM Bridge

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a chat-bridge prototype, but it asks to use an existing SSH session and local workspace queues while leaving important message-sending, translation, and file-write behavior under-scoped.

Review before installing. Use only in an isolated account or environment, avoid system or sudo Python installs, and do not run it against a sensitive SSH session. Treat `com:` and `s:` inputs as outbound messages to another chat system, and fix the translation-result path validation before enabling the queue processor.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/translation_handler.py:39
Finding

Unvalidated Translation Request ID Allows Arbitrary JSON File Overwrite

Content
View full analysis
list: """获取待翻译的请求""" ensure_dirs() requests = [] for f in QUEUE_DIR.glob("*.json"): try: with open(f, 'r', encoding='utf-8') as fp: data = json.load(fp) data['file_path'] = str(f) requests.append(data) except: pass return requests def submit_translation_result(request_id: str, translated_text: str): """提交翻译结果""" result_file = RESULT_DIR / f"{request_id}.json" with open(result_file, 'w', encoding='utf-8') as f: json.dump({ "translated": translated_text, "timestamp": datetime.utcnow().isoformat() }, f, ensure_ascii=False) ``` ```python def mark_translated(request: dict, translation: str): """ 标记翻译完成 Args: request: 请求字典(来自 check_and_translate) translation: 翻译后的文本 """ submit_translation_result(request['request_id'], translation) if 'file_path' in request: cleanup_request(request['file_path']) ``` ### Technical Analysis Translation queue files are parsed as JSON without validating their structure or the `request_id` field. The attacker-controlled value is then interpolated directly into a filesystem path: ```python result_file = RESULT_DIR / f"{request_id}.json" ``` A `request_id` containing traversal components such as `../../...` can cause the resolved output path to escape `RESULT_DIR`. More importantly, if `request_id` is an absolute path, Python's `pathlib` discards the preceding `RESULT_DIR` component when joining the paths. The resulting file is opened in write mode, which creates the file if it does not exist and truncates it if it does. The implementation also does not reject symbolic links, use exclusiv ...[truncated 1467 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unnecessary Unhashed Third-Party Dependency Increases Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code chunk encapsulates command-level interaction with the SDF COM system via callbacks for sending input and waiting for output. Its functions are limited to COM-side operations such as room navigation, posting messages, private messaging, history lookup, and other COM commands. The declared description claims a cross-platform bridge to Feishu/Lark with translation and real-time synchronization, but none of those platform-bridge or translation capabilities appear in this code. While 'command execution' on the COM side is partially consistent, the primary declared purpose is much broader and materially different from the actual behavior shown here.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a messaging bridge with real-time synchronization, translation, and command execution across SDF COM chat and Feishu/Lark. The provided code chunk does none of those things. It only checks for the presence of Python dependencies, specifically pyte, and prints installation guidance. This is a materially different primary purpose from the declared behavior, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a full messaging bridge with translation and real-time bidirectional synchronization between SDF COM and Feishu/Lark. The supplied code chunk is much narrower: it parses incoming text into command types and stores callback references, but never invokes the callbacks, performs network/service interaction, translates content, or synchronizes messages. This is a material description-behavior mismatch because the implemented behavior is only a command-parsing helper, not the described bridge functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The supplied code is a terminal parsing component, not a complete chat bridge. It uses pyte to interpret terminal output and regexes to extract chat-related events from COM output. While this could be a supporting part of the declared system, the declared description emphasizes cross-platform bridging, translation, command execution, and real-time synchronization with Feishu/Lark. None of those capabilities appear in this code chunk. Therefore, the description does not accurately represent what this specific code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a full messaging bridge between SDF COM and Feishu/Lark with translation, command execution, and real-time synchronization. The supplied code chunk is much narrower: it only manages translation requests via local JSON files in workspace directories and records translated results. While translation is related to one stated feature, the primary described behavior of cross-platform chat bridging is absent from this code. Therefore the code chunk does not accurately represent the declared purpose and is a material mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a full bridge service connecting two chat platforms with real-time synchronization, translation, and command execution. The supplied code chunk does not implement any platform connectivity, message relay, synchronization loop, or command handling. Its actual role is much narrower: a translation request wrapper that communicates with another agent via local JSON files in queue/result directories. Translation support is consistent with part of the description, but the primary declared purpose and major capabilities are not represented in this code chunk.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/error_recovery.py (reported line 159)May include surrounding context.

python
print("   b. Check COM availability: com")
        print("   c. Restart bridge: python main.py")
        print()
        print("4. Clear state and start fresh:")
        print(f"   rm {STATE_FILE}")
        print("   python main.py")
        print()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents capabilities that imply shell access, network communication, and likely file access, but it declares no tool scope or permission boundaries. In an agent environment, missing explicit restrictions increases the chance the skill can be invoked with broader-than-expected privileges and makes user review harder.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Automatic English-to-Chinese translation without user opt-in can expose private or sensitive content to a translation subsystem and alter message meaning before transmission. In this skill context, that risk is amplified because translated content is then shared across external chat platforms in real time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill does not clearly warn users that messages with the "com:" prefix are transmitted to an external chat system and potentially relayed to another platform. This can cause accidental disclosure of sensitive information because users may mistake the command for a local action or status operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The send_private method transmits a user-supplied message to another user, which is a network/chat transmission affecting privacy, but the code provides no confirmation prompt, user-visible log/print, or cautionary comment/docstring warning beyond the bare function name. Under the missing-warning rule for code files, this kind of outbound messaging should include some explicit disclosure to the user.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/dependency_checker.py (reported line 45)May include surrounding context.

python
for package_name, import_name in DependencyChecker.REQUIRED_PACKAGES:
            try:
                __import__(import_name)
                installed.append(package_name)
            except ImportError:
                missing.append(package_name)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/dependency_checker.py (reported line 70)May include surrounding context.

python
print(f"    pip3 install {' '.join(missing)}")
        print()
        print("  Method 2: pip (system)")
        print(f"    sudo pip3 install {' '.join(missing)}")
        print()
        print("  Method 3: apt (Debian/Ubuntu)")
        print(f"    sudo apt-get install python3-pyte")

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/dependency_checker.py (reported line 73)May include surrounding context.

python
print(f"    pip3 install {' '.join(missing)}")
        print()
        print("  Method 2: pip (system)")
        print(f"    sudo pip3 install {' '.join(missing)}")
        print()
        print("  Method 3: apt (Debian/Ubuntu)")
        print(f"    sudo apt-get install python3-pyte")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file contains its primary descriptive text in Chinese, including the module docstring and many user-facing comments/instructions, with no indication that language selection is optional or tied to a justified region-specific requirement. That can violate a language/locale policy when users or maintainers are not given an opt-in choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing natural-language descriptions in Chinese (module docstring and command/help text context) but does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level docstring is entirely in Chinese and presents the skill as operating in that language by default, with no indication that users may choose another language or locale. This is a natural-language policy concern because it imposes a language expectation without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The bridge automatically starts relaying and translating chat content once started, without any explicit consent, warning, or confirmation gate visible in this flow. Because this skill connects a public UNIX chatroom to Feishu/Lark and forwards content across systems, it can expose private or sensitive chat data to another platform and to translation processing without users being clearly informed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest and module/class documentation describe real-time bilingual translation as a supported bridge capability. However, the translation loop explicitly uses simulated placeholder strings and marks requests as translated, so the implemented behavior in this file does not match the claimed translation functionality.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments state that translation 'should' be completed by the main agent and imply this section is only a temporary handoff point. In contrast, the code immediately fabricates placeholder output and calls mark_translated, which contradicts the documented intent by finalizing fake translations as if they were complete.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/ssh_connection.py (reported line 40)May include surrounding context.

python
return False
        try:
            # 验证套接字是否可用
            result = subprocess.run(
                ["ssh", "-O", "check", f"{self.user}@{self.host}"],
                capture_output=True,
                timeout=5

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The function connects to a real remote system and may execute commands without any user-facing confirmation, approval gate, or safety interlock. In a bi-directional chat bridge skill, this materially increases the chance that messages, mistranslations, or prompt-influenced inputs trigger remote actions unexpectedly, resulting in unauthorized command execution or account misuse.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
83% confidence
Finding

This code launches an SSH session and can execute a caller-supplied remote command with no validation, restriction, or policy check. While Popen is used without shell=True, the bridge context is more dangerous because untrusted chat-originated input could be forwarded into command, enabling unauthorized remote command execution on the SDF host under the configured account.

Content

Scanner excerpt · scripts/ssh_connection.py (reported line 63)May include surrounding context.

python
cmd.extend(command.split() if isinstance(command, str) else command)
        
        try:
            self.process = subprocess.Popen(
                cmd,
                stdin=subprocess.PIPE,
                stdout=subprocess.PIPE,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring includes Chinese-only operational text ('由大鱼(主 agent)运行,处理 COM Bridge 触发的翻译请求'), which imposes a specific language for important usage information. There is no accompanying multilingual explanation or indication that users can choose another language, creating a language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language comments and behavior indicate this translator is specifically oriented around Chinese and English, and the auto-target logic defaults to switching between only 'zh' and 'en'. This can violate language/locale policy when a skill imposes a specific language pair without clearly offering user choice or documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.