Back to skill

Security audit

支付宝开放平台密钥工具

Security checks for vulnerabilities and agentic risk

Overview

The skill supports a legitimate Alipay key workflow, but its default command prints newly generated private signing keys where logs or agent transcripts may capture them.

Review before installing. If used, run the generator only on a trusted local machine, prefer --no-print every time, avoid shared or world-writable output directories, and rotate any Alipay private key that has already appeared in terminal logs, CI logs, or agent transcripts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_alipay_rsa2_keys.sh:5
Finding

Private Signing Key Is Printed to Standard Output by Default

Content
View full analysis
Remediation
View remediation
&2 exit 1 fi ``` 5. Ensure Agent-facing documentation always invokes the script with `--no-print`. 6. Treat existing execution transcripts and logs as potentially compromised. Remove retained copies where feasible and rotate any private keys that may already have been logged. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_alipay_rsa2_keys.sh:93
Finding

Predictable and Non-Exclusive Output Directory Enables Symlink and Overwrite Attacks

Content
View full analysis
`. 3. Inside that directory, the attacker creates a symbolic link such as `app_private_key.pem` pointing to a file writable by the victim. 4. The victim runs the generation script during the predicted second. 5. `mkdir -p "$OUT"` accepts the attac ...[truncated 1125 chars]
Remediation
View remediation
&2 exit 1 fi ``` 3. Reject symbolic links and pre-existing output files before invoking OpenSSL. 4. Prefer creating temporary files exclusively inside the newly created private directory, then atomically rename them to their final names. 5. Document that key generation must not use shared, world-writable, or untrusted parent directories. 6. Add tests for: - Pre-existing output directories - Symbolic links at expected output paths - Concurrent script invocations - Paths containing spaces or leading hyphens ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/generate_alipay_rsa2_keys.sh:100
Finding

Private-Key Permissions Are Restricted Only After Key Creation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · scripts/test_generate_alipay_rsa2_keys.sh (reported line 27)May include surrounding context.

sh
}

cleanup() {
  [[ -n "${TMPDIR:-}" && -d "${TMPDIR:-}" ]] && rm -rf "$TMPDIR"
}
trap cleanup EXIT

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs use of shell scripts to generate and verify Alipay RSA2 keys, but it does not declare any explicit tool scope such as allowed shell usage. This creates a permission-boundary problem: an agent may execute shell commands involving sensitive key material without the skill clearly constraining or disclosing that capability, increasing the risk of unintended command execution or mishandling secrets.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · reference.md (reported line 5)May include surrounding context.

md
## 环境与工具

本目录为 Agent Skills 包(`SKILL.md` 入口);安装路径与 slash 调用见各产品文档:[agentskills.io](https://agentskills.io/)、[Cursor Skills](https://cursor.com/docs/skills)、[Claude Code Skills](https://code.claude.com/docs/en/skills)。用户级常见路径:`~/.cursor/skills/`、`~/.claude/skills/`;项目级:`.cursor/skills/`、`.claude/skills/`。

---

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/generate_alipay_rsa2_keys.sh (reported line 104)May include surrounding context.

sh
openssl genpkey -algorithm RSA -out "$PRIV" -pkeyopt rsa_keygen_bits:2048
openssl pkey -in "$PRIV" -pubout -out "$PUB"
chmod 600 "$PRIV"
chmod 644 "$PUB"

CSR=""

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/generate_alipay_rsa2_keys.sh (reported line 105)May include surrounding context.

sh
openssl genpkey -algorithm RSA -out "$PRIV" -pkeyopt rsa_keygen_bits:2048
openssl pkey -in "$PRIV" -pubout -out "$PUB"
chmod 600 "$PRIV"
chmod 644 "$PUB"

CSR=""
if [[ "$CERT_MODE" -eq 1 ]]; then

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/generate_alipay_rsa2_keys.sh (reported line 111)May include surrounding context.

sh
openssl genpkey -algorithm RSA -out "$PRIV" -pkeyopt rsa_keygen_bits:2048
openssl pkey -in "$PRIV" -pubout -out "$PUB"
chmod 600 "$PRIV"
chmod 644 "$PUB"

CSR=""
if [[ "$CERT_MODE" -eq 1 ]]; then

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script's description, usage output, and error/help messages are entirely in Chinese, which imposes a specific language on users without offering a language choice or documenting that the tool is intended only for a Chinese-language context. This matches the policy category for language/locale constraints expressed in natural language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.