Back to skill

Security audit

Uos Packager

Security checks for vulnerabilities and agentic risk

Overview

This UOS/deepin packaging skill is mostly coherent, but it teaches under-scoped privileged system-file changes that users should review carefully before installing or following.

Review any generated maintainer scripts before installing packages with sudo. Do not follow the generic udev or privileged-file-write examples unless the destination and contents are fixed, necessary, and reviewed. Prefer package-managed system files, validate script inputs, and harden temporary directory handling before using these helpers in shared or privileged build environments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_deb.sh:23
Finding

Predictable Temporary Build Directory Permits Local Filesystem Manipulation

Content
View full analysis
"$PKG_DIR/DEBIAN/control" << EOF Package: ${APPID} Version: ${VERSION} Section: utils Priority: optional Architecture: ${ARCH} Maintainer: $(whoami) <$(whoami)@localhost> Description: UOS Application EOF ``` A local attacker who creates the predicted path first may populate it with attacker-controlled directories or symbolic links. Subsequent writes and copies can then target locations selected by the attacker, subject to the victim user's filesystem permissions. The attacker may also alter files in the build tree and thereby tamper with the generated package. ### Attack Path 1. A local attacker monitors process identifiers or repeatedly creates likely future paths such as `/tmp/uos_build_12345`. 2. Before the victim starts the build, the attacker creates the predicted directory and places crafted subdirectories or symbolic links within it. 3. The victim executes `scripts/build_deb.sh`. 4. `mkdir -p` accepts the pre-existing path instead of establishing a new, p ...[truncated 844 chars]
Remediation
View remediation
&2 exit 1 } chmod 700 "$BUILD_DIR" trap 'rm -rf -- "$BUILD_DIR"' EXIT HUP INT TERM ``` Additional hardening measures include: 1. Reject symbolic links in any sensitive destination path. 2. Verify that generated package directories remain beneath the canonical temporary directory. 3. Use `umask 077` before creating temporary files. 4. Avoid relying on process IDs, timestamps, or other predictable values for temporary names. 5. Keep the cleanup command quoted and include `--` before the path. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/introspect.sh:20
Finding

Predictable Inspection Directory Allows Local Tampering with Extracted Package Data

Content
View full analysis
/dev/null || true dpkg-deb -x "$DEB_FILE" "$WORK_DIR/rootfs" 2>/dev/null || true ``` The directory is later removed with: ```bash rm -rf "$WORK_DIR" ``` ### Technical Analysis The inspection directory is derived from a predictable process ID and is created under the globally writable `/tmp` directory. `mkdir -p` accepts an existing attacker-created directory and does not establish exclusive ownership or restrictive permissions. The script then extracts control and package data beneath that directory. An attacker who controls the directory before extraction may insert files, directories, or symbolic-link path components that influence the extraction environment or the data subsequently inspected. Because extraction failures are explicitly ignored with `|| true`, a collision or attacker-induced extraction error may not stop the audit. The script can consequently analyze stale or attacker-supplied files and report misleading results. The final recursive cleanup also operates on a path that was not securely created. Although normal `rm -rf` behavior does not follow a top-level symbolic link as a directory, attacker-controlled directory contents still create avoidable race and integrity risks. ### Attack Path 1. A local attacker predicts a future process identifier for the inspection script. 2. The attacker pre-creates `/tmp/uos_inspect_` and prepares controlled `DEBIAN` or `rootfs` content. 3. The victim runs `scripts/introspect.sh` against a Debian package. 4. The script accepts the existing directory. 5. Package extraction either interacts with the attacker-controlled structure or fails silently ...[truncated 866 chars]
Remediation
View remediation
&2 exit 1 } trap 'rm -rf -- "$WORK_DIR"' EXIT HUP INT TERM ``` Extraction errors should not be ignored. Replace the current commands with explicit failure handling: ```bash if ! dpkg-deb -e "$DEB_FILE" "$WORK_DIR/DEBIAN"; then echo "Failed to extract Debian control data" >&2 exit 1 fi if ! dpkg-deb -x "$DEB_FILE" "$WORK_DIR/rootfs"; then echo "Failed to extract Debian package data" >&2 exit 1 fi ``` The script should additionally verify that: 1. `WORK_DIR` is owned by the current effective user. 2. Its permissions are no broader than mode `0700`. 3. Extraction destinations are real directories rather than symbolic links. 4. All inspection paths resolve beneath the canonical `WORK_DIR`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_deb.sh:9
Finding

Unvalidated Package Parameters Are Used as Paths and Control Metadata

Content
View full analysis
"$PKG_DIR/DEBIAN/control" << EOF Package: ${APPID} Version: ${VERSION} Section: utils Priority: optional Architecture: ${ARCH} Maintainer: $(whoami) <$(whoami)@localhost> Description: UOS Application EOF ``` Finally, the same values determine the output filename: ```bash DEB_FILE="${APPID}_${VERSION}_${ARCH}.deb" dpkg-deb --build "$PKG_DIR" "$DEB_FILE" 2>/dev/null || \ fakeroot dpkg-deb --build "$PKG_DIR" "$DEB_FILE" ``` ### Technical Analysis The script only verifies that `APPID` and `VERSION` are non-empty. It does not enforce the documented appid syntax, a Debian-compatible version syntax, or an allowlist of supported architectures. Consequently, path separators and traversal components can affect `PKG_DIR`, source paths, and `DEB_FILE`. Newline characters or other invalid content can also alter or corrupt generated Debian control metadata. Quoting the variables prevents shell word splitting and command substitution, but it does not prevent path traversal or multiline metadata injection. The issue is therefore not conventional shell command injection; it is unsaf ...[truncated 2132 chars]
Remediation
View remediation
&2 exit 1 fi if [[ ! "$VERSION" =~ ^[0-9]+(\.[0-9]+){2,3}$ ]]; then echo "Invalid version" >&2 exit 1 fi if [[ ! "$ARCHS" =~ ^(amd64|arm64|loongarch64|mips64el|sw_64)(,(amd64|arm64|loongarch64|mips64el|sw_64))*$ ]]; then echo "Invalid architecture list" >&2 exit 1 fi ``` Apply the following additional controls: 1. Reject values containing `/`, `\`, newlines, carriage returns, or NUL-equivalent input. 2. Canonicalize generated paths with `realpath` or `readlink -f`. 3. Verify that every build path remains beneath the canonical temporary build directory. 4. Verify that the final package path remains beneath an explicitly selected output directory. 5. Use Debian-native validation where available, such as `dpkg-parsechangelog`-compatible version checks and supported architecture queries. 6. Keep supported architectures in a fixed allowlist rather than accepting arbitrary strings. 7. Do not run the builder with elevated privileges when processing untrusted arguments or project content. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (29)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill says system directories are read-only and should not be relied on, but later recommends directly writing to /lib/udev/rules.d/. This contradiction weakens operator trust boundaries and normalizes privileged filesystem writes despite earlier safety guidance, increasing the chance of unsafe package scripts being accepted without scrutiny.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

bash
# ✅ 正确(带引号)
rm -rf "$INSTALL_DIR/tmp"

# ❌ 错误(未引用变量,重定向不受 sudo 影响)
sudo echo xxx > /lib/udev/rules.d/xxx  # 重定向不在 sudo 作用域

Chaining Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

Piping content into sudo tee is a command-chaining pattern that facilitates privileged writes, and here it targets a concrete sensitive system path under /lib/udev/rules.d/. In combination with packaging scripts, this can be used to install persistent system-level configuration with broad effects outside the packaged app's own directory.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

❌ 错误(未引用变量,重定向不受 sudo 影响)

sudo echo xxx > /lib/udev/rules.d/xxx # 重定向不在 sudo 作用域

正确做法:

printf '%s\n' "content" | sudo tee /lib/udev/rules.d/xxx > /dev/null

text

#### 7.4 sudo 与重定向

Chaining Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

This chained printf | sudo tee pattern teaches a reusable way to send arbitrary content into privileged files. Although the destination is generic, in an agent context this is a dangerous primitive because it lowers the barrier to constructing root-level file modification chains.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

sudo echo "rule" > /path/file

正确

printf '%s\n' "rule" | sudo tee /path/file > /dev/null

text

#### 7.5 UOS 无 sudo 环境适配

Chaining Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

This command chain writes variable-controlled content through sudo tee into an arbitrary file path in the non-UOS branch, which is especially risky because both content and destination are abstracted. Such a pattern can easily be repurposed for unauthorized privileged configuration changes or persistence.

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
;;
        *)
            # 其他系统:使用 sudo
            printf '%s\n' "$CONTENT" | sudo tee /path/file > /dev/null
            ;;
    esac
fi

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

md
| 快捷方式不显示 | Exec 路径无效 / desktop 编码非 UTF-8 | 检查路径;保存为 UTF-8;确认 StartupNotify=true |
| 图标不显示 | Icon 路径错误 | 使用 `files/resources/logo.png` 或确认 entries 下图标路径 |
| DDE 未自动映射 entries | 缺少 info 文件 | 必须有 `opt/apps/${appid}/info` 文件 |
| udev 规则无效 | sudo echo 重定向不生效 | 使用 `tee` 而非 `echo + 重定向` |
| info 文件无效 | JSON 格式错误 | 严格 JSON 格式,注意字段名拼写 |
| 中文乱码 | desktop 文件非 UTF-8 编码 | 保存为 UTF-8 编码 |
| shellcheck 报错 | 脚本语法问题 | SC2024(sudo 重定向)、SC2129(多次重定向) |

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document presents all operational guidance in Chinese and does not provide an opt-in, alternative language, or explicit statement that the skill is limited to Chinese-speaking users. Under the policy criteria, forcing a specific language without user choice is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

rm -rf "$INSTALL_DIR/tmp"

❌ 错误(未引用变量,重定向不受 sudo 影响)

sudo echo xxx > /lib/udev/rules.d/xxx # 重定向不在 sudo 作用域

正确做法:

printf '%s\n' "content" | sudo tee /lib/udev/rules.d/xxx > /dev/null

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

rm -rf "$INSTALL_DIR/tmp"

❌ 错误(未引用变量,重定向不受 sudo 影响)

sudo echo xxx > /lib/udev/rules.d/xxx # 重定向不在 sudo 作用域

正确做法:

printf '%s\n' "content" | sudo tee /lib/udev/rules.d/xxx > /dev/null

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

rm -rf "$INSTALL_DIR/tmp"

❌ 错误(未引用变量,重定向不受 sudo 影响)

sudo echo xxx > /lib/udev/rules.d/xxx # 重定向不在 sudo 作用域

正确做法:

printf '%s\n' "content" | sudo tee /lib/udev/rules.d/xxx > /dev/null

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 194)May include surrounding context.

rm -rf "$INSTALL_DIR/tmp"

❌ 错误(未引用变量,重定向不受 sudo 影响)

sudo echo xxx > /lib/udev/rules.d/xxx # 重定向不在 sudo 作用域

正确做法:

printf '%s\n' "content" | sudo tee /lib/udev/rules.d/xxx > /dev/null

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 223)May include surrounding context.

rm -rf "$INSTALL_DIR/tmp"

❌ 错误(未引用变量,重定向不受 sudo 影响)

sudo echo xxx > /lib/udev/rules.d/xxx # 重定向不在 sudo 作用域

正确做法:

printf '%s\n' "content" | sudo tee /lib/udev/rules.d/xxx > /dev/null

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 299)May include surrounding context.

rm -rf "$INSTALL_DIR/tmp"

❌ 错误(未引用变量,重定向不受 sudo 影响)

sudo echo xxx > /lib/udev/rules.d/xxx # 重定向不在 sudo 作用域

正确做法:

printf '%s\n' "content" | sudo tee /lib/udev/rules.d/xxx > /dev/null

text

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

This line instructs piping content to sudo tee targeting /lib/udev/rules.d/xxx, which is an explicit privileged write into a system directory. Even though the shell pattern is technically correct, the dangerous part is that the skill normalizes and enables privileged host modification from packaging guidance without strict necessity or safeguards.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

❌ 错误(未引用变量,重定向不受 sudo 影响)

sudo echo xxx > /lib/udev/rules.d/xxx # 重定向不在 sudo 作用域

正确做法:

printf '%s\n' "content" | sudo tee /lib/udev/rules.d/xxx > /dev/null

text

#### 7.4 sudo 与重定向

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

This line promotes sudo tee /path/file as the correct pattern for privileged writes. Although generic, it teaches a reusable method for writing attacker-controlled content into arbitrary root-owned paths, which becomes more dangerous in an agent skill context because it can be repurposed across sensitive destinations.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

sudo echo "rule" > /path/file

正确

printf '%s\n' "rule" | sudo tee /path/file > /dev/null

text

#### 7.5 UOS 无 sudo 环境适配

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
97% confidence
Finding

The text claims that ordinary users on UOS can directly write to /lib/udev/rules.d/ and similar directories. This encourages unsafe assumptions about privileged filesystem access and normalizes direct modification of sensitive system locations during package operations, potentially bypassing expected admin review.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

printf '%s\n' "rule" | sudo tee /path/file > /dev/null

text

#### 7.5 UOS 无 sudo 环境适配

UOS/统信环境下,普通用户可以直接写入 `/lib/udev/rules.d/` 等目录。可以通过 `/etc/os-release` 检测:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly instructs writing udev rules into /lib/udev/rules.d/ from package maintenance scripts, granting system-level side effects unrelated to a generic packaging-specification document. Because udev rules execute in a privileged system context and can affect device handling globally, this creates a meaningful avenue for persistence, unsafe hardware-triggered behavior, or broad host modification.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
95% confidence
Finding

This line explicitly instructs using sudo to write content into an arbitrary file path, enabling privileged filesystem modification. In an agent skill, generic patterns for privileged writes can be transplanted into harmful contexts, especially when combined with package-maintainer execution paths.

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
printf '%s\n' "$CONTENT" > /path/file
            ;;
        *)
            # 其他系统:使用 sudo
            printf '%s\n' "$CONTENT" | sudo tee /path/file > /dev/null
            ;;
    esac

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's title, usage, examples, warnings, and status messages are presented in Chinese, and there is no indication that the skill is region-specific or that users can opt into another language. This can violate language/locale policy requirements when a skill is expected to be usable in the user's preferred language unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
echo "输出目录: $BUILD_DIR"
echo ""
echo "提示: 安装测试"
echo "  sudo dpkg -i ${APPID}_${VERSION}_${ARCH_ARRAY[0]}.deb"
echo "  # 或在 UOS 桌面上双击 deb 文件安装"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 209)May include surrounding context.

md
echo "输出目录: $BUILD_DIR"
echo ""
echo "提示: 安装测试"
echo "  sudo dpkg -i ${APPID}_${VERSION}_${ARCH_ARRAY[0]}.deb"
echo "  # 或在 UOS 桌面上双击 deb 文件安装"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 214)May include surrounding context.

md
echo "输出目录: $BUILD_DIR"
echo ""
echo "提示: 安装测试"
echo "  sudo dpkg -i ${APPID}_${VERSION}_${ARCH_ARRAY[0]}.deb"
echo "  # 或在 UOS 桌面上双击 deb 文件安装"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 326)May include surrounding context.

md
echo "输出目录: $BUILD_DIR"
echo ""
echo "提示: 安装测试"
echo "  sudo dpkg -i ${APPID}_${VERSION}_${ARCH_ARRAY[0]}.deb"
echo "  # 或在 UOS 桌面上双击 deb 文件安装"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 329)May include surrounding context.

md
echo "输出目录: $BUILD_DIR"
echo ""
echo "提示: 安装测试"
echo "  sudo dpkg -i ${APPID}_${VERSION}_${ARCH_ARRAY[0]}.deb"
echo "  # 或在 UOS 桌面上双击 deb 文件安装"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 330)May include surrounding context.

md
echo "输出目录: $BUILD_DIR"
echo ""
echo "提示: 安装测试"
echo "  sudo dpkg -i ${APPID}_${VERSION}_${ARCH_ARRAY[0]}.deb"
echo "  # 或在 UOS 桌面上双击 deb 文件安装"

Static analysis

No suspicious patterns detected.