Back to skill

Security audit

Ptengine Heatmap Analyze

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for Ptengine heatmap analysis, but it needs review because it can install external CLI software and one reference recommends an unsafe remote installer command.

Review before installing. Use the local install.sh wrapper rather than the curl | sh command in the reference file, approve installation explicitly, and provide Ptengine credentials only through a secure secret-handling path. Expect the skill to query Ptengine analytics for the URLs and date ranges you provide.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/ptengine-cli.md:5
Finding

Unverified Remote Installer Is Piped Directly to a Shell

Content
View full analysis

Vulnerability Details

File Location: references/ptengine-cli.md, lines 5–12
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
## Installation

```bash
# Via official install script (recommended)
curl -sSL https://raw.githubusercontent.com/Kocoro-lab/ptengine-cli/v0.1.0/scripts/install.sh | sh

# Or use the project's wrapper
sh install.sh
text

### Technical Analysis

The documentation recommends downloading a shell script from a third-party GitHub namespace and piping the response directly into `sh`. The command references the mutable `v0.1.0` tag and performs no checksum or cryptographic signature verification before execution.

Consequently, the code ultimately executed is not fixed by the audited Skill package. It may change if the upstream repository owner moves the tag, the GitHub account or repository is compromised, or an upstream maintainer publishes malicious content. Piping the response directly to a shell also prevents meaningful inspection before execution.

This unsafe path bypasses the protections present in the local `install.sh` wrapper, which pins an immutable commit and validates the downloaded installer against a SHA-256 checksum. Calling the verified wrapper is sufficient for the declared functionality; therefore, the unverified pipe-to-shell alternative exceeds the minimum risk necessary to install the CLI.

### Attack Path

1. An attacker gains control of the upstream repository, maintainer account, or referenced mutable tag.
2. The attacker replaces the remote installer with a script containing arbitrary shell commands.
3. A user or Agent follows the documentation’s recommended installation command.
4. `curl` retrieves the attacker-controlled response.
5. The response is immediately passed to `sh` without checksum or signature validation.
6. The malicious commands execute with the privileges of the account running the Skill.

### Impact Assessment

Successful expl
...[truncated 538 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh command from the documentation.
  2. Direct users exclusively to the hardened local wrapper:
    bash
    sh install.sh
    
  3. Preserve the wrapper’s immutable commit pin and SHA-256 verification.
  4. Prefer a cryptographic signature tied to a documented maintainer key when upstream support is available.
  5. Vendor the reviewed installer or binary into a controlled release process where practical.
  6. Review the complete upstream installer and any binaries it subsequently downloads; verifying only the first-stage script does not automatically establish the integrity of later-stage artifacts.
  7. Run installation without elevated privileges and install only within a user-controlled directory.
  8. Document the expected files, network destinations, and credential locations so users can verify installation behavior.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an end-to-end analytics skill focused on analyzing Ptengine heatmap data and producing behavioral/CRO insights. The supplied code does none of that. It is strictly an installation/status utility for ptengine-cli: it checks for the binary, checks for a config file with an API key, shows configuration, optionally downloads a pinned installer script from GitHub, verifies its checksum, and runs it. This is a materially different primary purpose and adds an undeclared capability (software installation/bootstrap). While installing ptengine-cli could support a later analysis workflow, this code chunk itself does not implement the described analysis behavior, making the description inaccurate for the provided code.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/data-transform.md (reported line 165)May include surrounding context.

md
**Decimal strings** (e.g. `"4.24"`):
- Parse as float directly

#### Display rules (when writing the analysis report)

When presenting metrics in the human-readable report:
- **Durations**: Show in seconds with unit. Under 60s: "11秒" / "11s" / "11秒". Over 60s: "3分13秒" / "3m 13s"

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The | sh construct is particularly dangerous because it removes any opportunity for inspection and directly chains network-fetched content into code execution. In this skill context, that is more dangerous than a passive reference because the documentation is operational and likely to be copied and run by users handling production analytics environments.

Content

Scanner excerpt · references/ptengine-cli.md (reported line 9)May include surrounding context.

bash
# Via official install script (recommended)
curl -sSL https://raw.githubusercontent.com/Kocoro-lab/ptengine-cli/v0.1.0/scripts/install.sh | sh

# Or use the project's wrapper
sh install.sh

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes shell-based installation and command execution (sh install.sh, ptengine-cli ...) but does not declare an explicit tool scope or allowed-tools boundary. In an agent environment, undeclared execution capability increases the chance of overbroad tool access, unexpected command execution, or policy bypass because reviewers and orchestrators cannot reliably constrain what the skill may run.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match many generic analytics or page-review requests, which can cause the wrong skill to activate and request sensitive analytics operations or credentials unexpectedly. Over-triggering increases the risk of data exposure, unnecessary command execution, and user confusion in multi-skill environments where routing precision matters.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to ask for and set an API key and profile ID without any safeguard language for sensitive credential handling. In practice, this can normalize users pasting secrets into chat, increase accidental logging or retention of credentials, and enable misuse if the agent stores, echoes, or exposes those values through shell history or transcripts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L013 limits language to CHINESE, ENGLISH, or JAPANESE with a default of ENGLISH. This is a natural-language locale restriction, and the document does not present it as an opt-in user choice or justify the limitation as region-specific policy.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
94% confidence
Finding

The instruction to include ALL blocks from BOTH versions with no filtering or truncation can cause unbounded processing and output growth when analyzing large redirect experiments. This creates denial-of-service risk through excessive token consumption, slow execution, or model/context exhaustion, especially if an attacker supplies unusually large page/block datasets.

Content

Scanner excerpt · references/ab-test-task.md (reported line 46)May include surrounding context.

md
**For redirect** (campaign_type === "redirect"):
- Different URL per version — entire page differs; `abTest` records are absent by design
- ALL blocks from BOTH versions are comparison points (no filtering, no truncation)
- Derive `strategy` by comparing `contentSummary` across versions at equivalent positions
- MUST hedge with uncertainty language for every content assertion:
  - CN: 「据截图显示,该区块似乎…」

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Line L010 limits the language input to CHINESE, ENGLISH, or JAPANESE, which is a natural-language locale restriction. The file does not explain why only these languages are permitted or provide an opt-in mechanism for other user-preferred languages, so this may violate language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill constrains output to a fixed language enum with ENGLISH as default and instructs the report to be written entirely in that target language, without indicating that the user's own language preference must take precedence. This can cause responses in an unintended locale, creating accessibility, usability, and policy-compliance issues, especially when the user did not request Chinese/Japanese or when raw segment labels are forcibly transformed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The target format hard-codes language to CHINESE|ENGLISH|JAPANESE, which is a natural-language locale constraint. The document does not state that this is optional, user-selected, or justified by a region-specific requirement, so it appears to impose a language policy without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This schema again limits language to CHINESE|ENGLISH|JAPANESE and provides no indication that the user can choose the locale. Under the policy, forcing a specific language set without opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The compare-task data structure repeats the same fixed language enumeration and does not mention user preference or opt-in. Repeated locale constraints across the document suggest an enforced language policy rather than a configurable option.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The recommended installation method downloads a remote script and immediately executes it with the shell, giving the remote content full code execution on the user's machine. If the source repository, network path, or referenced script is compromised, users can be silently infected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly shows passing an API key on the command line, which can expose the secret via shell history, process listings, logs, and CI output. In a skill that guides users to run analytics commands with real credentials, this increases the chance of credential leakage and unauthorized API access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file states "Default: ENGLISH," which imposes a specific output language unless the user or caller explicitly sets a different language. Under the policy criteria, forcing a language without user opt-in is a natural-language policy violation unless the constraint is justified as region-specific or optional.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions require the output to be entirely in the selected target language, and the allowed values are limited to Chinese, English, or Japanese. This is a natural-language locale constraint that may override the user's preferred language unless they explicitly opt in at runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The parameter table sets Language to a default of ENGLISH while supporting multiple languages. This imposes a specific language choice unless the user overrides it, which is a locale/language policy concern when no opt-in is obtained.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction 'Write the entire report in the target language' enforces a language choice determined by the skill input rather than by explicit user preference at runtime. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless clearly justified as region-specific or optional.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
96% confidence
Finding

This line fetches executable content from an external source at runtime, which creates a supply-chain risk and makes trust dependent on the integrity of GitHub-hosted content and transport security. Because this is documentation for a self-contained skill, users may follow it verbatim, turning the reference into an execution vector.

Content

Scanner excerpt · references/ptengine-cli.md (reported line 9)May include surrounding context.

bash
# Via official install script (recommended)
curl -sSL https://raw.githubusercontent.com/Kocoro-lab/ptengine-cli/v0.1.0/scripts/install.sh | sh

# Or use the project's wrapper
sh install.sh

Static analysis

No suspicious patterns detected.