Back to skill

Security audit

Ptengine Heatmap Analyze

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for Ptengine heatmap analysis, but it under-discloses API key handling and uses shell-style CLI command templates with user-provided inputs.

Review before installing. Configure ptengine-cli yourself in a trusted terminal instead of pasting API keys into chat, avoid using this skill on attacker-supplied URLs, and prefer a version that validates parameters and invokes ptengine-cli without shell interpolation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:179
Finding

Shell Command Injection Through Unsanitized User-Controlled Query Parameters

Content
View full analysis
" --start-date --end-date --output json # Block-level metrics (MUST specify device type) ptengine-cli heatmap query --query-type block_metrics \ --url "" --start-date --end-date \ --device-type --output json # Dimension-grouped insights (for ad/audience analysis) ptengine-cli heatmap query --query-type page_insight \ --url "" --fun-name \ --start-date --end-date --output json # Filtered data (for compare) ptengine-cli heatmap query --query-type block_metrics \ --url "" --start-date --end-date \ --device-type MOBILE --filter "visitType include newVisitor" --output json ``` ### Technical Analysis The workflow instructs the agent to collect a URL and other parameters from the user and interpolate them into shell command templates. It does not require validation, shell escaping, or execution through an argument-vector API. Placing the URL inside double quotes does not fully prevent shell injection. Shell constructs such as command substitution remain active inside double-quoted strings. For example, if a generated command includes a URL containing `$(malicious-command)`, a shell can execute that command before invoking `ptengine-cli`. The unquoted date, device, and function-name placeholders create additional injection opportunities if the implementation accepts values outside the documented enumeration. Similar risk applies to dynamically generated filter values in comparison workflows. This behavior exceeds the minimum privileges needed to query analytics. The task only requires passing inert strings to `ptengine-cli`; it does not re ...[truncated 1745 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:128
Finding

Ptengine API Key Is Collected in Conversation and Exposed Through Process Arguments

Content
View full analysis
--profile-id ` ``` The same command is repeated in `references/ptengine-cli.md`, lines 22-24 and 124-127: ```bash # Set credentials ptengine-cli config set --api-key --profile-id ``` ### Technical Analysis The workflow explicitly tells the agent to ask the user for an API key and then insert that secret into a command-line argument. This conflicts with the skill's earlier claim that it never reads or handles the key. Two separate exposure channels are created: 1. **Conversation exposure**: Asking for the API key places it in the agent conversation and potentially in model-provider logs, observability systems, transcripts, debugging records, or downstream tool-call records. 2. **Process argument exposure**: Supplying the key through `--api-key` may expose it through process inspection, command histories, shell tracing, audit systems, crash diagnostics, or process telemetry. The skill only needs to determine whether the external CLI is configured and invoke authenticated analytics queries. It does not need the agent to receive the credential. Credential entry should occur directly between the user and the trusted CLI through a non-logged secret input mechanism. If command construction is shell-based, a maliciously formed credential could also interact with the command-injection weakness described separately. Even when the credential is legitimate, placing it in conversation and process a ...[truncated 1480 chars]
Remediation
View remediation
# CLI securely prompts for the API key ``` 5. Alternatively, allow the CLI to read the key from standard input or a protected file descriptor, provided the secret is not recorded in shell history or tool logs. 6. Do not expose the key through command-line flags, shell history, generated reports, error messages, or debug output. 7. Verify configuration using `ptengine-cli config show` only if it reliably masks the key, or add a dedicated status command that reports whether credentials exist without returning them. 8. Avoid directly scanning the configuration file for `api_key:`. Delegate credential-status checks to the CLI so the skill does not require access to the secret-bearing file. 9. Update the capability disclosure to accurately state that credential handling is performed exclusively by the external CLI. 10. Advise users who previously pasted keys into a conversation or passed them on a command line to rotate those credentials and review relevant access logs. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (20)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest claims the skill does not read, write, or transmit the Ptengine API key itself, but the workflow directs the agent to collect the API key and pass it as a command-line argument to ptengine-cli config set. Handling secrets in agent-visible prompts and process arguments materially increases exposure risk through logs, telemetry, shell history, process inspection, and accidental model retention.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill makes strong assurances that it never reads or parses credential material, yet its workflow later requires checking the config file for an api_key: entry and instructs the agent to ask for the API key directly if not configured. This creates a trust-boundary mismatch: an operator may approve the skill believing it cannot handle secrets, while the instructions explicitly cause the agent to inspect credential-bearing storage and solicit sensitive input.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
| Ptengine Open API (`https://xbackend.ptengine.com`) | Source of heatmap metrics | Contacted by `ptengine-cli`, not by the skill directly |

**What this skill does NOT do:**
- Does not install `ptengine-cli` for the user (no bundled installer, no `curl | sh`)
- Does not read, parse, or transmit the contents of `config.yaml` or `PTENGINE_API_KEY`
- Does not access any URL other than the Ptengine API via the CLI
- Does not scrape the target webpage or use browser-automation tools (see Data Source Boundary)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/data-transform.md (reported line 165)May include surrounding context.

md
**Decimal strings** (e.g. `"4.24"`):
- Parse as float directly

#### Display rules (when writing the analysis report)

When presenting metrics in the human-readable report:
- **Durations**: Show in seconds with unit. Under 60s: "11秒" / "11s" / "11秒". Over 60s: "3分13秒" / "3m 13s"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Saying the skill only checks for existence and api_key: presence understates what it must do: detecting that entry requires reading credential-bearing file content. Even if it only scans for a key name and not the value, the skill is still accessing a secrets file, which broadens its effective data access beyond the plain-language disclosure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest says to trigger on phrases like "page behavior," "analyze this URL/page," "how are users behaving," and even "ptengine," plus "any request involving page analytics combined with behavioral insights." These activators are ambiguous and broad enough to match ordinary user requests that may not specifically intend this Ptengine heatmap skill, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file restricts language to CHINESE, ENGLISH, or JAPANESE, which is a locale policy constraint. The instructions do not present this as an explicit user choice at runtime beyond the fixed enum, and there is no justification that the skill is region-specific or otherwise requires this limitation.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · references/ab-test-task.md (reported line 46)May include surrounding context.

md
**For redirect** (campaign_type === "redirect"):
- Different URL per version — entire page differs; `abTest` records are absent by design
- ALL blocks from BOTH versions are comparison points (no filtering, no truncation)
- Derive `strategy` by comparing `contentSummary` across versions at equivalent positions
- MUST hedge with uncertainty language for every content assertion:
  - CN: 「据截图显示,该区块似乎…」

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction 'Write the entire report in the target language' imposes a language/locale behavior as a hard requirement. Although the file lists supported languages earlier, this line does not frame language choice as optional or user-consented, which matches the language-policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file states that language must be CHINESE, ENGLISH, or JAPANESE, defaulting to ENGLISH. This constrains the skill to specific languages and may force a locale choice on users who need a different language, without documenting an opt-in or justification for the restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The directive 'Write the entire report in the target language' enforces a language policy across all output. Because the file only permits a narrow set of languages and does not present this as a user-selected or justified regional constraint, it fits the locale-policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file specifies language: CHINESE | ENGLISH | JAPANESE (default ENGLISH), which imposes a limited language policy rather than allowing user choice more broadly. This is a natural-language policy concern because the skill forces a specific locale set without stating that the user can opt into other languages or that the restriction is required for a region-specific purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L171 instructs authors to "Always use the target-language metric label" and line L272/L311/L348 constrain language to CHINESE, ENGLISH, or JAPANESE. This imposes a language/locale behavior in natural-language instructions without any visible user opt-in or clear region-specific justification in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file instructs users to set an API key and query Ptengine's Open API, which implies transmitting analytics and potentially page-related data to an external service. The document explains configuration and usage but does not include any warning about external data transmission, handling of analytics data, or care around credential use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language policy requires output language to be controlled only by a language parameter limited to CHINESE, ENGLISH, or JAPANESE, and sets a default of ENGLISH. This is a locale/language constraint that may violate policy when applied without explicit user opt-in or justification for users outside those languages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file constrains the language input to CHINESE, ENGLISH, or JAPANESE, which is a natural-language locale restriction. The instructions do not present this as an optional policy choice or justify the limitation as region-specific, so it can violate language/locale flexibility expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file explicitly mandates that output be in the target language and that all headers, labels, and analysis text be replaced accordingly. This is a language-policy constraint, and the document does not frame it as user opt-in beyond selecting from a fixed set or explain why the restriction is necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The parameter table sets "Language" to a default of "ENGLISH" while only optionally allowing CHINESE or JAPANESE. This establishes a language preference without requiring the user to choose or opt in, which can violate language/locale choice expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file includes a section titled 'Phase Names by Page Type and Language' that prescribes specific language outputs across multiple tables. Because the file does not say the user can choose the language or that language selection is context-dependent, it may conflict with a policy requiring user language/locale choice rather than forcing a preset language set.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

These rules require the entire report, including headers and metric labels, to be in the target language only. While consistent with the template, this still represents a strict locale policy that is not explicitly justified in the document.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.