Back to skill

Security audit

oled-intelligence-portal

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it should be reviewed carefully because it writes generated HTML from external data without adequate sanitization or output-path containment.

Install only if you are comfortable with the skill using configured Zhihuiya/Patsnap MCP services and writing a local multi-page HTML report. Run it in a dedicated workspace, review the resolved output directory before generation, avoid untrusted portal JSON, and treat the generated HTML as untrusted until escaping, URL validation, slug validation, and output-directory containment are added.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_portal.py:69
Finding

Stored HTML and JavaScript Injection in Generated Portal Pages

Content
View full analysis
str: if not news_list: return '

暂无相关新闻

' cards = [] for n in news_list[:8]: url = n.get("url") or "#" title = n.get("title", "(无标题)") date = n.get("date", "") source = n.get("source", "") summary = n.get("summary", n.get("content", ""))[:200] cards.append(f"""
{date} {source}
{title}

{summary}

""") ``` The same direct interpolation pattern is used for patent records, company data, technology tags, events, the portal keyword, and the date range. ### Technical Analysis The generator inserts values obtained from portal JSON, user input, and external search results directly into HTML f-strings. It applies neither HTML escaping nor URL-scheme validation. Text values can terminate their intended element and inject arbitrary markup. For example, a malicious title or summary containing: ```html

``` would be writte ...[truncated 1722 chars]

Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_portal.py:315
Finding

Path Traversal and Arbitrary File Overwrite Through Unvalidated Slugs

Content
View full analysis
/../../target.html ``` After filesystem path resolution, that destination is outside the intended portal directory. The technology filename has a `tech-` prefix, but this does not provide containment. A value with enough traversal components can still escape from the output directory. ### Attack Path 1. An attacker influences a generated company or technology object and sets its `slug` to a traversal value such as `../../target`. 2. The object is included in the portal JSON. 3. The relevant page-generation function reads the slug without validation. 4. The script joins the malicious filename to `out_dir`. 5. ...[truncated 861 chars]
Remediation
View remediation
Path: root = out_dir.resolve() destination = (root / filename).resolve() if destination.parent != root: raise ValueError("Output path escapes the portal directory") return destination ``` 3. Generate slugs internally from trusted names rather than accepting arbitrary path components from portal data. 4. Reject empty slugs, duplicate slugs, path separators, dot components, control characters, and platform-specific reserved filenames. 5. Avoid silently overwriting existing files. Use exclusive creation where practical or require explicit overwrite authorization. 6. Apply the same validation to both company and technology page filenames and add tests for `../`, absolute paths, backslashes, encoded separators, and duplicate names. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_portal.py:448
Finding

Unrestricted Output Directory Allows Writes Outside the Intended Workspace

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/generate_portal.py:191
Finding

Generated Pages Execute Mutable Remote JavaScript from an Unpinned CDN

Content
View full analysis
``` This tag is embedded in every generated portal page. ### Technical Analysis Opening a generated page causes the browser to download and execute JavaScript from `cdn.tailwindcss.com`. The URL is not tied to an immutable version, and no Subresource Integrity hash is supplied. Consequently, the effective JavaScript payload is not fully contained in the audited project and can change after the audit. A CDN compromise, upstream account compromise, malicious upstream release, or unexpected service change could introduce arbitrary browser-side behavior into every generated portal. The Google Fonts stylesheet is also fetched remotely, but the Tailwind resource is more significant because it executes JavaScript. ### Attack Path 1. The generator creates a portal page containing the remote script tag. 2. The user opens the generated page while connected to the network. 3. The browser retrieves the current JavaScript response from the CDN. 4. If the CDN content or delivery account has been compromised or changed maliciously, the browser executes the modified payload. 5. The remote payload can read and modify the generated page and initiate browser network requests. ### Impact Assessment A successful supply-chain compromise would affect every generated page opened while the malicious remote response is active. The payload could alter report content, capture interactions, read intelligence displayed in the page, or communicate with external services. Execution occurs in the browser context rather than directly as an operating-system process. Access to unrelated local files remains subject to bro ...[truncated 46 chars]
Remediation
View remediation
``` 4. Deploy a restrictive Content Security Policy that allows scripts only from explicitly approved sources and avoids unsafe inline execution. 5. Consider bundling fonts locally to reduce external network requests and improve offline operation. 6. Test generated portals with network access disabled to verify that all essential functionality remains available without remote executable dependencies. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents an end-to-end portal generator that, given a domain keyword, automatically discovers entities/branches and retrieves news and patents from external data sources. The supplied code only handles the final presentation layer: it loads already-prepared JSON data, selects a visual theme based on the keyword, and writes static HTML pages. There are no network calls, database queries, AI/model calls, retrieval logic, keyword expansion, or automatic monitoring logic. So while the HTML portal generation part matches, the primary declared automation and data-gathering capabilities are absent from this code chunk, making the description materially broader than the actual behavior shown.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes behaviors that require reading environment/configuration, generating files, and likely invoking external capabilities, but it declares no explicit tool scope or allowed-tools boundary. In an agent environment, this can lead to overbroad ambient authority, where the runtime may permit file or environment access beyond what is necessary, increasing the chance of unintended data exposure or unsafe writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad trigger phrases can cause the skill to activate unintentionally during ordinary conversation, leading to unexpected external searches, file generation, or use of paid/internal tools without clear user intent. In this skill's context, accidental invocation is more concerning because the workflow includes multi-step retrieval and HTML file creation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

L024 将新闻检索语言固定为 lang="CN",且 L143 明确要求“所有 UI 文字使用中文”,形成默认且强制的语言/locale 约束。文档中未提供用户选择其他语言的机制,也未说明该限制仅适用于特定区域合规场景。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states it will generate and write a multi-page HTML site but does not specify user-facing consent, output location controls, or warnings about writing files. This can result in unexpected persistence of generated content, overwriting files, or creating locally opened HTML that may contain untrusted content from retrieved data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains multiple hard-coded Chinese UI labels for navigation and user-facing sections, indicating the template is designed to present content in a specific language by default. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The embedded JavaScript uses Chinese-only prompt and alert messages for date editing and validation. Because the file does not offer a language selection mechanism or explain that it is intentionally limited to a Chinese locale, this conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains natural-language and markup that hard-code the generated HTML document language to zh-CN. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in, and no alternate language selection or justification is provided anywhere in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The company, tech, and patents page templates all set the HTML language to zh-CN, so the locale restriction is applied uniformly across all generated artifacts. Because the file provides no opt-in, fallback, or justification for non-Chinese users, this is a repeated natural-language policy issue rather than an isolated template choice.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes news retrieval from Zhihuiya news vector search and patent retrieval from the Zhihuiya patent database after keyword expansion. The footer template instead states the report uses '用户提供JSON文件 + 公开网络搜索 + 专利数据Excel', which expands the apparent data sources to user-supplied JSON, public web search, and Excel-based patent inputs not mentioned in the manifest.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The inline documentation in this reference template says the data sources are '用户提供JSON文件 + 公开网络搜索 + 专利数据Excel'. That actively conflicts with the manifest description, which says monitored companies/branches are AI-retrieved, news comes from Zhihuiya vector retrieval, and patents are directly searched in the Zhihuiya patent database.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes a skill that generates an intelligence portal from a domain keyword, which naturally justifies HTML generation and handling provided data. Reading arbitrary environment variables such as EUREKA_PORTAL_DATA_JSON is an additional capability outside that stated purpose, because it depends on process environment state rather than direct user/task input.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script lets an external environment variable fully control the filesystem write destination, then creates that directory and writes multiple HTML files into it without restriction. In a shared or higher-privilege execution context, an attacker who can influence that environment variable could redirect output into unintended locations, causing unauthorized file creation or overwriting application artifacts.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.