T09 · Insecure Skill Coding Practices
- Location
scripts/skill_doctor.py:90- Finding
Security Audit Bypass Through Incomplete Script and Instruction Analysis
- Content
View full analysis
"): continue if not clean or re.search(r"\b(do not|never|avoid|refuse)\b", clean, re.I): continue if any(re.search(pattern, clean, re.I) for pattern in patterns): out.append(clean) return out[:5] ``` ### Technical Analysis The auditor detects whether a package contains files under `scripts/`, but it does not read or analyze those files. It only checks whether the `SKILL.md` body contains wording that mentions scripts, Python, Node, or a bundled script. Consequently, a malicious script can satisfy this check merely by being mentioned in otherwise benign documentation. The unsafe-instruction scanner also excludes several security-relevant Markdown contexts: - Fenced code blocks are skipped entirely. - Indented code blocks are skipped. - Block quotations are skipped. - Lines containin ...[truncated 2678 chars]- Remediation
View remediation
