Back to skill

Security audit

auto-workflow

Security checks for vulnerabilities and agentic risk

Overview

This workflow skill is broadly useful in concept, but it gives custom workflows unrestricted command, file, network, and environment-variable access without adequate safeguards.

Install only if you intend to run trusted, locally reviewed workflows and are comfortable treating workflow JSON as executable code. Do not run workflows from untrusted sources, especially on machines with API keys or tokens in the environment, and avoid using this engine for destructive cleanup until shell execution, environment interpolation, path restrictions, and dry-run behavior are fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/workflow-engine.py:399
Finding

Environment Secrets Can Be Substituted into Arbitrary Outbound Requests

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/workflow-engine.py:339
Finding

Untrusted Workflow Definitions Provide Unrestricted Shell Command Execution

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/workflow-engine.py:221
Finding

Arbitrary Downloads Can Be Chained with Shell Execution to Run Remote Payloads

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/workflow-engine.py:190
Finding

Recursive File Deletion Is Not Restricted to an Authorized Workspace

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/workflow-engine.py:497
Finding

Advertised Dry-Run Option Is Ignored and Does Not Prevent Side Effects

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/workflow-engine.py:57
Finding

Workflow-Controlled Log Name Permits Path Traversal and Unsafe Temporary-Directory Writes

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (24)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents backup and other automation flows that can overwrite, move, or delete data, but provides no warning about irreversible actions or scheduling risks. In an auto-executing workflow context, users may enable tasks that continue running and cause repeated data loss without realizing the consequences.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The engine implements a generic shell.exec action using subprocess.run(..., shell=True), which enables arbitrary command execution far beyond the documented workflow purposes. Because the skill also supports custom workflows, any user-supplied or attacker-influenced workflow can execute OS commands, read/write sensitive files, or launch follow-on attacks.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Using subprocess.run with shell=True on workflow-supplied command text allows shell metacharacter interpretation and direct OS command execution. In this skill's context, that means a crafted workflow can chain file access, secret expansion, and network operations into full command-injection and system-compromise scenarios.

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
print(f"    💻 执行:{cmd}")
        
        try:
            result = subprocess.run(
                cmd, shell=True, capture_output=True, text=True, timeout=60
            )
            print(f"    ✅ 完成")

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
99% confidence
Finding

The code enumerates all environment variables and makes them available for substitution into workflow-controlled strings. This is a classic secret-harvesting primitive because credentials from the runtime environment can be injected into files, network requests, or shell commands without any per-secret approval.

Content

Scanner excerpt · SKILL.md (reported line 387)May include surrounding context.

md
text = text.replace('{day}', now.strftime('%d'))
        
        # 替换环境变量
        for key, value in os.environ.items():
            text = text.replace(f'{{{key}}}', value)
        
        # 替换上下文变量

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The engine explicitly exposes a shell.exec workflow action, which extends the skill from automation into arbitrary code execution. Because the skill is designed for automatic workflow execution, this capability materially increases risk: a crafted workflow can run system commands, pivot to network actions, or modify local files far beyond a narrow automation purpose.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The subprocess invocation is directly parameterized by workflow input and executed with shell=True, so the workflow file acts as code. In an automation skill that can be triggered on behalf of users, this is a tool-parameter abuse path that can execute arbitrary commands, bypass intended workflow semantics, and compromise the execution environment.

Content

Scanner excerpt · scripts/workflow-engine.py (reported line 336)May include surrounding context.

python
timeout = params.get('timeout', CONFIG['timeout'])
        try:
            log(f"    执行:{cmd}", 'info', 2)
            result = subprocess.run(
                cmd, shell=True, capture_output=True, text=True, timeout=timeout
            )
            if result.returncode == 0:

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
95% confidence
Finding

Enumerating os.environ.items() and applying substitutions into workflow-controlled text creates a broad secret-harvesting surface. In this engine, the expanded values can be routed into HTTP requests, shell commands, saved files, or logs, making credential exfiltration straightforward for any untrusted workflow.

Content

Scanner excerpt · scripts/workflow-engine.py (reported line 393)May include surrounding context.

python
text = text.replace('{minute}', now.strftime('%M'))
        
        # 环境变量
        for key, value in os.environ.items():
            text = text.replace(f'{{{key}}}', value)
        
        # 上下文变量

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes capabilities for filesystem access, network access, environment-variable access, and shell execution, but declares no explicit tool scope or permissions boundaries. In an automation skill that can run custom workflows, this lack of scoping increases the chance of over-privileged execution and makes dangerous behavior harder to audit or restrict.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Broad trigger phrases like '自动化', '工作流', and 'automate' are likely to match many ordinary requests, causing the skill to activate in contexts where users did not intend privileged automation. Because this skill can perform destructive file operations, network access, and custom workflow execution, accidental invocation materially increases risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation and implemented behavior are inconsistent: documented actions include image/upload/cleanup capabilities that are not implemented, while the code includes undocumented shell execution. This mismatch can mislead reviewers and users about the true attack surface, causing unsafe trust decisions and insufficient approval controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill supports HTTP/API workflows but does not warn that workflow data may be sent to external services. Combined with environment-variable expansion and custom workflows, this can lead to unintentional exfiltration of local files, workflow outputs, or secrets to remote endpoints.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The variable expansion logic iterates over the full process environment and substitutes any matching token into workflow parameters. This gives workflows access to unrelated secrets and runtime context such as API keys or tokens, enabling accidental disclosure through files, HTTP requests, or shell commands.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The description "备份指定目录到压缩包" describes a general backup action but does not define specific invocation phrases, scope limits, or exclusion conditions, which could allow unintended activation for broad backup-related requests.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The workflow is described as backing up a specified directory to an archive, which is already covered by the dedicated archive step. Using shell.exec to run mkdir introduces command-execution capability that is not clearly justified by the stated backup purpose, since directory creation could be handled by safer built-in file operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest context emphasizes file processing and workflow automation, and this specific workflow claims only to back up a directory into an archive. Running ls -lh via shell.exec adds a general shell capability unrelated to the core archive creation behavior and broadens what the workflow can do beyond the narrowly described task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The workflow supports deleting arbitrary files or directories, including recursive directory removal, with no confirmation, path restriction, or safety interlock. In an auto-executing workflow system, a malicious or mistaken workflow can irreversibly destroy data, especially when combined with variable expansion or user-provided paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill allows arbitrary shell execution without meaningful safety boundaries or prominent warnings, which is especially dangerous for an automation engine that may process externally authored workflows. This enables workflows to chain file, network, and command actions into full remote-control behavior on the host.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The workflow engine executes a workflow-supplied command via subprocess.run(..., shell=True), which permits arbitrary shell execution. In an agent skill context where workflow files or parameters may be influenced by users or other automated systems, this becomes a direct command-execution primitive and can lead to full host compromise, data theft, or destructive actions.

Content

Scanner excerpt · scripts/workflow-engine.py (reported line 336)May include surrounding context.

python
timeout = params.get('timeout', CONFIG['timeout'])
        try:
            log(f"    执行:{cmd}", 'info', 2)
            result = subprocess.run(
                cmd, shell=True, capture_output=True, text=True, timeout=timeout
            )
            if result.returncode == 0:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The parameter-expansion logic iterates over all environment variables and substitutes them into workflow-controlled strings. This allows any workflow author to reference secrets such as API keys, tokens, credentials, or internal endpoints and then exfiltrate them through logs, HTTP requests, file writes, or shell commands.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI advertises a --dry-run mode, but no such control is implemented. Users may reasonably rely on this documented safety feature and accidentally trigger real file deletion, network access, downloads, archive extraction, or shell execution while believing they are only simulating a workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Most of the skill’s natural-language instructions and examples are presented only in Chinese, despite including English trigger terms like “workflow” and “automate.” This creates an implicit language constraint without opt-in, language selection, or documentation that the skill is intended solely for a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 530)May include surrounding context.

md
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest uses Chinese-only natural-language metadata for the skill name and description, with no indication that language selection is optional or that the workflow is intentionally region-specific. This can violate a language/locale policy when users are not offered a choice or informed of the locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings in the module header, help text, logs, and status messages are presented in Chinese only, with no indication that users may choose another language. This creates a locale policy concern because the skill effectively enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.