Back to skill

Security audit

Perspective Transform Visualizer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local visualization tool, but its page silently loads an unrelated remote visitor-counter script that can run third-party code.

Review before installing. The visualization behavior itself is understandable, but remove or disable the busuanzi visitor-counter script before using the page, especially through a local web server or the hosted version. Be aware that the skill may edit its bundled index.html to set initial parameters and may open an external GitHub Pages URL for remote-device scenarios.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
index.html:597
Finding

Unpinned Third-Party JavaScript Is Retrieved and Executed at Runtime

Content
View full analysis
👁️ 访问: -
``` ### Technical Analysis The page loads and executes JavaScript from `busuanzi.ibruce.info` whenever it is served over HTTP or HTTPS. The protocol-relative URL inherits the page's scheme. The downloaded payload is not bundled, cryptographically pinned, or protected by a Subresource Integrity hash, so its effective behavior can change after the project has been reviewed. A third-party script included this way executes in the security context of the embedding page rather than in an isolated third-party context. It can therefore read or modify the page DOM, observe transformation parameters entered by the user, falsify visualization results, register event handlers, and initiate additional network requests within normal browser restrictions. The script implements visitor counting, which is not required for the perspective-transformation functionality. Its presence is not disclosed by `SKILL.md` or `README.md`. It also conflicts with the project's claim that it supports offline operation using a localized Three.js dependency. The connection necessarily exposes network metadata, including the requesting IP address and ordinary HTTP request headers, to the third-party service. ### Attack Path 1. The Agent follows the project instructions and opens the application through its GitHub Pages deployment or an HTTP server such as the one recommended in `README.md`. 2. The browser parses the external `script` element in `index.html`. 3. The browser connects ...[truncated 1529 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill should accept transformation parameters, modify an initial webpage configuration, and open a browser to visualize the result. However, the supplied code chunk contains only the license/header of three.min.js and no visible code implementing those behaviors. Based on the provided chunk, the actual content is a generic library file rather than the described tool logic. This is a material description-behavior mismatch for the supplied code.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
→ 直接用浏览器打开 ./index.html

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 1)May include surrounding context.

html
<!-- 配置(修改这里来调整初始值) -->
<script>
const configData = {
    "matrix": { "m00": 1, "m01": 0, "m02": 0, "m10": 0, "m11": 1, "m12": 0, "m20": 0, "m21": 0, "m22": 2 },

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · index.html (reported line 1)May include surrounding context.

html
<!-- 配置(修改这里来调整初始值) -->
<script>
const configData = {
    "matrix": { "m00": 1, "m01": 0, "m02": 0, "m10": 0, "m11": 1, "m12": 0, "m20": 0, "m21": 0, "m22": 2 },

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill instructs behavior that can access an external website but does not declare any explicit tool scope or permissions boundary for network use. In an agent setting, undeclared network capability weakens reviewability and can lead to unexpected outbound access, especially when the skill decides between local and remote resources at runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language instructions and examples are entirely in Chinese, which effectively imposes a language constraint on users and maintainers. The file does not provide an opt-in language choice or explain that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is presented as modifying and opening a local visualization, but it also instructs the agent to open an externally hosted version for remote-device scenarios. That changes the trust boundary from local, offline content to a mutable remote site, creating risks of tracking, content drift, or malicious updates not covered by the local project review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document directs the agent to inspect runtime channel/surface metadata and use that to decide whether to visit an external site. This introduces unnecessary environment awareness and outbound navigation beyond the core educational visualization purpose, expanding the attack surface and privacy exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The page includes a third-party visitor counter script that causes users' browsers to contact an external domain and disclose visit metadata. For a local teaching/debug visualization tool, this introduces unnecessary network exposure and third-party code execution beyond the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Loading remote JavaScript grants a third party the ability to execute arbitrary code in the page origin and observe access behavior. Because this capability is unrelated to the visualization function, it increases attack surface without functional necessity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The external visitor-counter script is fetched without any user-facing notice or consent, creating undisclosed network activity and privacy leakage. It also creates a supply-chain risk because the page trusts executable code from a third-party host.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The README content is entirely in Chinese, including the title, warnings, feature descriptions, and usage instructions, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells the agent to edit index.html in place without warning that it modifies a project file. Silent local file mutation can cause accidental corruption, overwrite user changes, or create confusing state changes, especially if the file is under version control or shared with other workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This stylesheet hard-codes 'Microsoft YaHei' in the font stack, which introduces a locale-specific presentation choice in natural-language-facing UI behavior. The file provides no indication that this Chinese-oriented font preference is optional, user-selected, or justified by a region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The page declares lang="zh-CN" and all visible UI text is in Chinese, effectively enforcing a specific language/locale. There is no indication that the user can select another language or that the locale restriction is intentionally limited to a justified region-specific use case.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.