Back to skill

Security audit

html-text-editor-lite

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does what it says, but needs Review because its text-only editing workflow can save and apply raw HTML that may become executable code in the edited page.

Install only if you are comfortable reviewing the exported JSON and the resulting HTML before deployment. Use dry runs and backups, avoid sending confidential report content to an external AI, and do not apply JSON diffs from untrusted sources unless the new content has been checked for markup or scripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/apply_edits.py:39
Finding

Unsanitized HTML Editing and Backfill Enables Stored Cross-Site Scripting

Content
View full analysis
Remediation
View remediation
`, and `&` is safely encoded in the resulting document. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill clearly instructs use of scripts that read and modify local files, but the manifest does not declare any tool scope or allowed-tools restrictions. That creates a permission-boundary ambiguity: an agent may invoke file read/write capabilities more broadly than a reviewer or orchestrator expects, increasing the chance of unintended file modification or misuse if the skill is activated in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description contains many broad natural-language trigger phrases like 'make this HTML editable' and 'edit the text myself,' which can cause the skill to auto-match in loosely related situations. Over-broad activation is risky here because the skill performs file transformation and write-back operations, so accidental selection could lead to unnecessary modification of source HTML or confusion about which editing workflow should be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The injected editor UI labels and status text are primarily presented in Chinese, and the exported file name and instructions also assume Chinese-language use. This creates a locale/language constraint without user opt-in or a documented region-specific justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The exported workflow explicitly tells users to send a JSON bundle containing both original and modified HTML fragments to an AI. Those fragments can include sensitive business content, embedded identifiers, internal links, or other confidential text from the source page, creating a data exfiltration/privacy risk when shared with external AI systems. In this skill context, the feature is designed specifically to capture page content and hand it to an AI, which makes the exposure pathway more realistic rather than incidental.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.