T09 · Insecure Skill Coding Practices
- Location
scripts/inline_images.py:27- Finding
Path Traversal Allows Arbitrary Local File Embedding
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent as a WeChat article preview formatter, but its helper scripts can expose local files or run unsafe preview content when given untrusted HTML or image paths.
Review before installing if you will process HTML or image paths from other people. Use it only with trusted article drafts and trusted local assets, avoid absolute or parent-directory image paths, avoid custom theme/style JSON from untrusted sources, and inspect generated previews before copying or publishing. The behavior does not look intentionally malicious, but the helper scripts need tighter input validation and sanitization.
scripts/inline_images.py:27Path Traversal Allows Arbitrary Local File Embedding
scripts/generate_preview.py:120Unsanitized Template Substitution Enables Script Execution in Generated Previews
The declared purpose centers on HTML article creation and formatting for WeChat, including normalization, theming, preview generation, and preparing article body content. The actual code does none of those things. Instead, it implements a local image-to-base64 converter for cover or other images. While such a utility could conceivably support article preparation, that capability is not disclosed in the description, and the code chunk’s primary purpose is materially different from the declared article-processing functionality. Therefore this is a clear description-behavior mismatch.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</div>
<main class="preview-stage">
<!--
重要提示:
LLM 在生成内容时,请将生成的包含 data-role 属性的 HTML 标签放入此 article 容器内。
无需再生成外层的 html/head/body 结构,也无需重新定义样式。
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
</div>
<main class="preview-stage">
<!--
重要提示:
LLM 在生成内容时,请将生成的包含 data-role 属性的 HTML 标签放入此 article 容器内。
无需再生成外层的 html/head/body 结构,也无需重新定义样式。
The skill instructs the agent to read and write local files and to invoke scripts that may open previews, but it declares no explicit tool scope or permission boundaries. Without an allowlist, downstream runtimes may grant broader filesystem or network access than users expect, increasing the chance of unauthorized file access or side effects.
The instruction '保留来源语种。中文来源的标题、标签和正文都应保持中文' imposes a language constraint for Chinese-source content. Because the skill does not present this as a user-selectable option or clearly justify it as a region-specific compliance requirement, it can violate language/locale policy expectations.
Line L07 requires headings to use 'natural Chinese phrasing,' which is a language-specific constraint expressed in natural language. Because the file does not offer a user language choice or explain that the skill is limited to a Chinese-language context, this appears to force a specific language without opt-in.
The HTML declares lang="zh-CN" and the visible interface labels are written in Chinese throughout the toolbar. This enforces a specific language/locale in the skill output without any opt-in or documented region-specific justification, which matches the language/locale policy violation criteria.
This JavaScript includes hard-coded Chinese error text and UI strings, beginning here and continuing throughout the file, which imposes a specific language on users without any opt-in or locale selection mechanism. That matches the policy-violation category for language or locale constraints in natural-language content.
The skill is presented as an HTML-first article formatter and preview tool for local copy into WeChat. This code performs arbitrary URL fetches for image sources during copy preparation, introducing network access that is not mentioned in the manifest and is not an obvious requirement of a local formatter.
The manifest describes generating, normalizing, theming, previewing, and preparing WeChat-friendly article HTML. This code implements a full edit mode with mutable content state and local persistence, plus later annotation workflows, which are materially broader capabilities than formatting and preview alone.
Line L201 uses the specific Chinese trigger phrase “换个配色” as the only example for the fallback behavior, which embeds a language-specific assumption into the skill guidance. The file does not offer an alternative language choice or explain that the skill is intentionally limited to Chinese-speaking or WeChat-specific users.
Line L23 says headings should be kept natural in Chinese and provides only Chinese examples, which imposes a language preference in the skill's instructions. The file does not indicate that Chinese output is optional, user-selected, or required by a clearly documented region-specific use case.
The script displays its confirmation prompt and status/error messages in Chinese only, which imposes a specific language on users without opt-in. This matches the policy concern for locale/language restrictions because the file contains no indication that the skill is intended only for Chinese-speaking users or that alternative language handling is available.
The skill defaults to creating files under dist/ and may generate preview artifacts as part of normal operation, but it does not require clear prior user consent for filesystem modification. Unexpected writes are a safety issue because they can alter the workspace, overwrite files if paths are changed, or surprise users in automated contexts.
The document requires output to be copied into the WeChat Official Account backend, which is a locale/platform-specific constraint expressed in natural language. It does not indicate user opt-in, alternatives, or that this restriction is justified as a region-specific tool, so it may violate the language/locale policy requirement.
This code presents the browser-open prompt and several CLI defaults/messages in Chinese, including the interactive confirmation at L135 and the default title/help text around L148-L149, without any opt-in or locale selection. That is a natural-language locale policy concern because the skill fixes one language for user interaction rather than offering a choice or documenting a justified locale restriction.
No suspicious patterns detected.