Back to skill

Security audit

smartlink-ip-workbench

Security checks for vulnerabilities and agentic risk

Overview

The skill appears intended for a local SmartLink/Patsnap HTML workbench, but it asks the agent to run unreviewed local code, serve an entire Downloads folder, and create hard-coded backup copies.

Install only if you trust the specific local machine layout and the external Patsnap proxy file it runs. Before use, restrict the preview server to a dedicated folder, verify or bundle the proxy script, make backup locations configurable, and require confirmation before overwriting files or restarting services.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:76
Finding

Local HTTP Server Exposes the Entire Downloads Directory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 76
Vulnerability Type: Excessively broad local file exposure
Risk Level: Medium

Vulnerable Code:

bash
screen -dmS smartlink_http_8767 bash -lc 'cd "/Users/tangmingying/Downloads" && python3 -m http.server 8767 --bind 127.0.0.1 > /tmp/smartlink_http_8767.log 2>&1'

Technical Analysis

The command starts a Python HTTP server with the user's entire Downloads directory as its document root. Although the service is bound to the loopback interface, any process running in the same host or network namespace can request files from that directory.

The intended operation only requires access to the SmartLink workbench and its assets. Serving the complete Downloads directory violates least privilege and may expose unrelated documents, exported credentials, archives, reports, or other sensitive files. Python's basic HTTP server does not provide authentication or per-file authorization.

Attack Path

  1. A sensitive or unrelated file exists under /Users/tangmingying/Downloads.
  2. The Agent follows the Skill instructions and starts the HTTP server.
  3. A malicious or compromised local process enumerates http://127.0.0.1:8767/ or requests a known filename.
  4. The server returns the file without authentication.
  5. The local process reads or further distributes the exposed content.

Impact Assessment

Exploitation can disclose any file readable by the service account and located beneath the Downloads directory. It does not directly grant privileges beyond the account running the server, but it bypasses the intended file-level access boundary by making unrelated files available over an unauthenticated local endpoint. The scope is limited to files served from the selected document root and the lifetime of the HTTP server.

Remediation
View remediation

Remediation Suggestions

  • Create a dedicated directory containing only the workbench HTML and required static assets.

  • Start the HTTP server with that dedicated directory as its document root, for example:

    bash
    python3 -m http.server 8767 --bind 127.0.0.1 --directory "/path/to/smartlink-preview"
    
  • Apply restrictive permissions to the preview directory and its contents.

  • Avoid copying confidential or unrelated files into the served directory.

  • Shut down the server when previewing is complete.

  • If untrusted local processes are within the threat model, use a server that supports authentication and explicit path allowlisting.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/save_latest.sh:5
Finding

Unvalidated Backup Label Allows Destination Path Traversal

Content
View full analysis

Vulnerability Details

File Location: scripts/save_latest.sh, lines 5–12
Vulnerability Type: Path traversal and arbitrary file write
Risk Level: Medium

Vulnerable Code:

bash
SRC="$1"
LABEL="${2:-SmartLink}"
DATE=$(date +%Y%m%d)
DEST_DIR="$(dirname "$SRC")"
DEST="${DEST_DIR}/${LABEL}_最新版_${DATE}.html"
cp "$SRC" "$DEST"
BACKUP_DIR="/Users/tangmingying/Downloads/智慧芽HTML自动备份"
mkdir -p "$BACKUP_DIR"
cp "$SRC" "${BACKUP_DIR}/${LABEL}_${DATE}_$(date +%H%M%S).html"

Technical Analysis

The caller-controlled LABEL value is interpolated directly into two filesystem paths without validating that it is a simple filename component. Shell quoting prevents command injection, but it does not prevent path traversal. A label containing path separators and parent-directory components can cause the normalized destination to escape the intended output or backup directory.

If a traversed destination already exists, cp can overwrite it using the contents of the selected source HTML file. Successful exploitation depends on the constructed parent directories existing and the executing user having write permission at the resulting destination.

Attack Path

  1. An attacker influences the second argument passed to save_latest.sh.
  2. The attacker supplies a traversal-bearing label such as ../../some/existing/path/output.
  3. The script concatenates the value into DEST or the backup destination.
  4. Filesystem path resolution processes the .. components and escapes the intended directory.
  5. cp creates or overwrites the resulting file with the source HTML content under the privileges of the user running the script.

Impact Assessment

The flaw can create or overwrite files at attacker-selected, path-derived locations writable by the invoking user. It does not inherently elevate privileges beyond that user, and the generated date and .html suffix constrain the exact destination name. Ne ...[truncated 186 chars]

Remediation
View remediation

Remediation Suggestions

  • Restrict LABEL to an explicit allowlist, such as ASCII letters, digits, underscores, and hyphens:

    bash
    if [[ ! "$LABEL" =~ ^[A-Za-z0-9_-]+$ ]]; then
      printf 'Invalid label\n' >&2
      exit 1
    fi
    
  • Explicitly reject /, \, .., control characters, and empty labels.

  • Canonicalize each destination and verify that it remains beneath the expected directory before writing.

  • Use cp -- "$SRC" "$DEST" so option-like path values cannot be interpreted as command options.

  • Consider refusing to overwrite existing files by using cp -n or atomic exclusive creation where appropriate.

  • Validate that the source is a regular file before copying it.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:73
Finding

Predictable Temporary Log Paths Permit Symlink-Based File Clobbering

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 73–76
Vulnerability Type: Unsafe temporary-file handling
Risk Level: Medium

Vulnerable Code:

bash
screen -S zhihuiya_mcp_proxy -X quit >/dev/null 2>&1 || true
screen -dmS zhihuiya_mcp_proxy bash -lc 'cd "/Users/tangmingying/Downloads/AI项目文件库" && node zhihuiya_mcp_proxy.js > /tmp/zhihuiya_mcp_proxy.log 2>&1'

screen -S smartlink_http_8767 -X quit >/dev/null 2>&1 || true
screen -dmS smartlink_http_8767 bash -lc 'cd "/Users/tangmingying/Downloads" && python3 -m http.server 8767 --bind 127.0.0.1 > /tmp/smartlink_http_8767.log 2>&1'

Technical Analysis

Both services redirect output to fixed filenames in the shared /tmp directory. Shell redirection opens these paths with truncation and normally follows symbolic links. On systems where another local user can create entries in /tmp, an attacker can pre-create either predictable path as a symbolic link to another file.

When the Agent starts the service, the redirection can follow that symbolic link and truncate or populate the target file. The attacker cannot use this flaw to write beyond the permissions of the Agent user, but the operation crosses the temporary-directory trust boundary.

Attack Path

  1. A local attacker predicts one of the fixed log paths.
  2. Before the service starts, the attacker creates a symbolic link at that path pointing to a file writable by the Agent user.
  3. The Agent executes the documented startup command.
  4. Shell redirection follows the symbolic link and opens the target with truncation.
  5. The target is truncated and subsequently receives service log output.

Impact Assessment

Exploitation can corrupt or truncate files writable by the account running the Skill. It may cause denial of service, configuration loss, or unintended insertion of log data into another file. The flaw does not independe ...[truncated 162 chars]

Remediation
View remediation

Remediation Suggestions

  • Create a private runtime or log directory owned by the Agent user with mode 0700.
  • Generate unpredictable files with mktemp rather than using fixed names in /tmp.
  • Refuse to use an existing path if it is a symbolic link or not a regular file.
  • Prefer an application-specific log directory with restrictive permissions.
  • Use operating-system service management and protected logging facilities where available.
  • Configure log rotation and ensure newly created log files use restrictive modes such as 0600.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:11
Finding

Skill Executes an External Proxy Script Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 11 and 73
Vulnerability Type: Execution of an unaudited mutable local component
Risk Level: Medium

Vulnerable Code:

markdown
- MCP 代理:`/Users/tangmingying/Downloads/AI项目文件库/zhihuiya_mcp_proxy.js`
bash
screen -dmS zhihuiya_mcp_proxy bash -lc 'cd "/Users/tangmingying/Downloads/AI项目文件库" && node zhihuiya_mcp_proxy.js > /tmp/zhihuiya_mcp_proxy.log 2>&1'

Technical Analysis

The Skill instructs the Agent to execute a JavaScript proxy stored outside the reviewed project package in a Downloads subdirectory. The external script was not included in the audited directory, and the startup procedure does not verify its digest, ownership, permissions, file type, or provenance.

This creates a mutable trust boundary: the behavior reviewed in the Skill can differ from the code ultimately executed. Any party or process able to replace or modify the external script can cause arbitrary JavaScript to run when the documented service startup workflow is invoked.

Attack Path

  1. An attacker or compromised local process obtains write access to the external proxy file or its containing directory.
  2. The attacker replaces or modifies zhihuiya_mcp_proxy.js with malicious JavaScript.
  3. The user asks the Agent to start or restart the local proxy.
  4. The Agent follows SKILL.md and invokes Node.js on the modified file.
  5. The substituted code executes with the filesystem, network, and process privileges of the Agent user.

Impact Assessment

Successful exploitation permits arbitrary code execution with the privileges of the user running the Skill. This may expose files and environment variables accessible to that user, enable outbound network connections, alter user-owned data, or launch additional processes. The flaw does not itself grant elevated operating-system privileges; exploitation first requires the attacker to modify ...[truncated 53 chars]

Remediation
View remediation

Remediation Suggestions

  • Include the proxy implementation inside the reviewed Skill package so it is versioned and audited with the rest of the project.
  • Pin and verify a cryptographic digest before every execution.
  • Verify that the proxy is a regular file, is owned by the expected user, and is not writable by untrusted users or groups.
  • Store executable project components outside general-purpose download directories.
  • Resolve and validate the canonical path before execution.
  • Abort startup if ownership, permissions, path, or digest verification fails.
  • Run the proxy with the minimum necessary permissions and, where practical, inside a sandbox with restricted filesystem and network access.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向特定业务领域的综合 HTML 工作台构建与验证能力,包含专利/IP 解决方案、MCP 工作流、合规分析、OCR 流程、检索和数据接入等场景。而提供的代码只是一个非常狭窄的辅助校验脚本:读取本地 HTML,抽取非 src 的 script 标签内容,并检查其 JavaScript 语法是否可被解析。它既不构建或更新工作台,也不运行页面、不提供业务逻辑、不访问任何专利或智慧芽/Patsnap 数据源。虽然“验证 HTML 工作台”中的“验证”一词与该脚本存在弱相关,但该代码仅覆盖了极小一部分技术性语法检查,无法支撑声明中的主要用途,因此属于明显的描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s operational guidance and required self-check instructions are written entirely in Chinese, which effectively imposes a language requirement on users. Under the policy, locale or language constraints should either be optional for the user or clearly justified as region-specific; neither is stated here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

文档要求每次有意义更新后直接写回工作文件、备份目录和最新版副本,但未要求先获得用户对文件修改和落盘位置的明确确认。这会导致代理在本地文件系统上进行持久化修改,可能覆盖用户数据、泄露敏感内容到备份副本,或在错误路径下造成不可逆变更。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

技能文档明确指导终止并重启本地后台服务、切换目录并执行 Node/Python 命令,这超出了单纯编辑 HTML 的最小权限需求。若代理或操作者盲目遵循,这会引入不必要的本地进程控制能力,可能导致服务中断、误操作,且在受信环境中放大为执行任意本地命令的先例。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

这里不仅执行 shell 命令,还先无条件终止名为特定 screen 会话的本地服务,再重启新实例,且没有要求提醒用户服务中断风险。若在共享开发环境或已有任务运行中执行,可能中断其他工作流、丢失未保存状态,甚至掩盖对本地服务状态的非预期更改。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently creates an अतिरिक्त backup copy in a fixed Downloads subdirectory that is not implied by its stated 'save latest' purpose. This can expose potentially sensitive HTML content to a broader, user-accessible location, create unintended data retention, and surprise operators who expected only an in-place timestamped copy.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script writes to a hard-coded absolute path under a specific user's Downloads folder, which is broader than necessary and bypasses least-privilege design. In shared, synced, or production-like environments, this can leak proprietary content, fail unpredictably on other hosts, or cause data to be written to an unintended location outside the working directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction '用中文回答' forces a specific response language for all uses of the skill. This is a natural-language policy concern because it does not provide an opt-in or fallback based on the user's preferred language.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/verify_html_js.js:15