Back to skill

Security audit

create-technology-intelligence-briefing-ip

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated research-reporting purpose, but its HTML renderer executes a Python “data” file, which is a high-impact under-disclosed code-execution risk.

Install only if you are comfortable running a local Python renderer and can ensure v2_data.py is created by a trusted workflow, reviewed as code, and not supplied by an untrusted source. Prefer a version that uses JSON or another non-executable data format before generating reports from third-party or externally influenced evidence.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/build_report_v2.py:75
Finding

Arbitrary Code Execution Through Executable Report Data Module

Content
View full analysis

Vulnerability Details

File Location: scripts/build_report_v2.py, lines 75–86
Vulnerability Type: Unsafe dynamic import of an untrusted data file
Risk Level: High

Vulnerable Code

python
def load_data(path: Path | None = None) -> Any:
    """Load v2_data.py from the working directory or an explicit path."""
    source = path or (Path.cwd() / "v2_data.py")
    if not source.is_file():
        raise FileNotFoundError(f"Data module not found: {source}")
    spec = importlib.util.spec_from_file_location("briefing_v2_data", source)
    if spec is None or spec.loader is None:
        raise RuntimeError(f"Cannot load data module: {source}")
    module = importlib.util.module_from_spec(spec)
    spec.loader.exec_module(module)
    return module

Technical Analysis

The report renderer treats v2_data.py as a structured report-data source, but loads it through Python's import system. The call to spec.loader.exec_module(module) executes every top-level statement in the selected file.

The renderer accepts an explicit data path through its second command-line argument; otherwise, it loads v2_data.py from the current working directory. Therefore, anyone able to supply or modify that file can place arbitrary Python statements in it.

The subsequent validate() operation does not mitigate this issue because module execution occurs first. HTML escaping and HTTP(S)-only link validation also protect only the generated document and do not restrict Python behavior during data loading.

For example, a malicious data file could contain top-level code equivalent to:

python
import os
os.system("attacker-controlled command")

The malicious statement would execute as soon as load_data() imports the file, before the report data is validated or rendered.

Attack Path

  1. An attacker creates or modifies a v2_data.py file in the report-generation working directory, or convinces the operator to provide an attacker-controlled file as the ...[truncated 1462 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace executable Python data with a non-executable format.
    Use JSON as the primary data contract and load it with json.load() rather than importing a Python module.

  2. Apply strict schema validation before rendering.
    Define allowed top-level fields, nested structures, scalar types, required fields, permitted status values, and date formats. Reject unknown or incorrectly typed fields rather than silently accepting them.

  3. Enforce resource limits.
    Set reasonable limits for file size, nesting depth, list length, and string length to reduce denial-of-service risks from oversized input.

  4. Retain existing output protections.
    Continue escaping all rendered text and limiting links to absolute HTTP(S) URLs. These controls remain necessary even after the code-execution flaw is removed.

  5. If legacy Python files must be supported, never import them.
    Parse the source with Python's ast module and permit only simple assignments whose values pass ast.literal_eval(). Reject imports, calls, attribute access, comprehensions, and all other executable syntax. This should be a temporary compatibility mechanism rather than the preferred design.

  6. Restrict input provenance and filesystem behavior.
    Require an explicitly approved data path, avoid implicitly trusting the current working directory, and document that report inputs must come from a trusted workflow.

A safer loading pattern would be:

python
import json
from pathlib import Path
from typing import Any

def load_data(path: Path) -> dict[str, Any]:
    if not path.is_file():
        raise FileNotFoundError(f"Data file not found: {path}")
    if path.stat().st_size > 10 * 1024 * 1024:
        raise ValueError("Data file exceeds the permitted size")
    with path.open("r", encoding="utf-8") as handle:
        data = json.load(handle)
    if not isinstance(data, dict):
        raise ValueError("Report data must be a JSON object")
 
...[truncated 44 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (538)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a high-level skill for producing full technology-intelligence briefings backed by patents, literature, and news. The supplied code chunk instead implements a narrow utility: reading local JSON news records, validating fields, normalizing text and dates, filtering unsafe URLs, deduplicating by URL, and writing normalized JSON. This is materially different in primary purpose and scope. While such normalization could support a larger briefing pipeline, this chunk by itself does not perform the declared briefing, evidence gathering, synthesis, comparison, or HTML generation.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
- `references/company_aliases.json` for optional assignee candidates;

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
- `references/company_aliases.json` for optional assignee candidates;

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The docstring asserts the script is 'safe' and relies on a 'reviewed' v2_data.py, but the implementation later imports that file as a Python module and executes its top-level code. This creates a misleading trust boundary: anyone who can influence v2_data.py can run arbitrary code when the report is built, while the safety claims may cause reviewers or users to underestimate that risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

load_data() uses importlib to load and execute a local Python file as 'data', which means arbitrary code in v2_data.py runs with the privileges of the user executing the script. For a report-building skill whose stated purpose is to transform evidence into static HTML, executable input is unnecessary and substantially increases attack surface, enabling local code execution, data exfiltration, file tampering, or persistence.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill requests file read, file write, and network-capable behavior in its instructions, but it does not declare an explicit tool/permission scope. That creates an authorization ambiguity where an agent may over-grant capabilities or users may not understand the operational reach of the skill, increasing the chance of unintended data access, outbound requests, or filesystem writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that one deliverable must be "an English" HTML briefing, which imposes a specific language requirement. The file does not indicate that users may choose another language or opt into English, and no region-specific justification is provided.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 20)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 21)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 26)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 74)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 75)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 76)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 97)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 228)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 229)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 234)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 277)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 278)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 442)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 500)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 501)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 502)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 503)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/company_aliases.json (reported line 541)May include surrounding context.

json
"entity_scope":  "candidate_names_require_verification"
                                                 },
                               "Contemporary Amperex Technology Co., Limited":  {
                                                                                    "source_label":  "\u5b81\u5fb7\u65f6\u4ee3",
                                                                                    "aliases":  [
                                                                                                    "\u5b81\u5fb7\u65f6\u4ee3\u65b0\u80fd\u6e90\u79d1\u6280\u80a1\u4efd\u6709\u9650\u516c\u53f8",
                                                                                                    "Contemporary Amperex Technology Co., Limited",

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/build_report_v2.py:85