Back to skill

Security audit

Daily Market Report

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese futures market report generator with optional PDF export, but users should only convert trusted report files to PDF.

Install only if you need Chinese futures market reports. Treat the PDF export as a convenience for trusted reports: do not run it on markdown from unknown sources, and avoid using it in environments with sensitive local files or unrestricted network access unless the renderer is sandboxed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/report_generator.py:151
Finding

Unescaped Report Content Is Embedded into Active HTML During PDF Conversion

Content
View full analysis

Vulnerability Details

File Location: scripts/report_generator.py, lines 151–153
Vulnerability Type: HTML injection and unrestricted resource loading during document conversion
Risk Level: Medium

Vulnerable Code

python
with open(markdown_path, "r", encoding="utf-8") as f:
    html = f"<html><body><pre>{f.read()}</pre></body></html>"
HTML(string=html).write_pdf(str(pdf_path))

Technical Analysis

The WeasyPrint fallback reads the Markdown report and interpolates it directly into an HTML document without HTML escaping. The <pre> element does not provide a security boundary: input containing </pre> can terminate it and introduce arbitrary HTML and CSS that WeasyPrint will process.

For example, attacker-controlled report content could contain:

html
</pre><img src="https://attacker.example/track">

Resource-bearing HTML or CSS may cause the PDF renderer to request remote URLs. Depending on the renderer's supported URL schemes and runtime permissions, references to accessible local resources may also be rendered or incorporated into the resulting PDF.

The primary Pandoc/wkhtmltopdf conversion path is also not configured here with an explicit resource allowlist, network isolation, or local-file restrictions. The confirmed unsafe interpolation, however, is specifically present in the WeasyPrint fallback shown above.

Attack Path

  1. An attacker gains control over, or can influence, the Markdown file supplied as markdown_path to export_pdf().
  2. The attacker inserts a closing </pre> tag followed by resource-bearing HTML or CSS.
  3. Pandoc conversion is unavailable or fails, causing execution to continue to the WeasyPrint fallback.
  4. The report is concatenated into active HTML without escaping.
  5. WeasyPrint parses the injected markup while generating the PDF.
  6. The renderer requests an attacker-controlled URL or attempts to load another resource reachable from its execution environment.
  7. The attacker may observ ...[truncated 808 chars]
Remediation
View remediation

Remediation Suggestions

  1. Escape report text before placing it inside an HTML <pre> element:
python
import html

with open(markdown_path, "r", encoding="utf-8") as f:
    escaped_report = html.escape(f.read())

document = f"<html><body><pre>{escaped_report}</pre></body></html>"
HTML(string=document).write_pdf(str(pdf_path))
  1. If Markdown rendering is required, use a maintained Markdown parser configured to disable raw HTML rather than concatenating untrusted text into an HTML document.

  2. Configure a custom WeasyPrint URL fetcher that rejects all resource schemes and destinations except an explicit allowlist. In particular, deny remote HTTP/HTTPS URLs and local file: URLs unless they are necessary.

  3. Run PDF conversion in an isolated process or container with:

    • No unnecessary network access.
    • A read-only filesystem.
    • Access only to the input and output files.
    • A dedicated unprivileged account.
    • CPU, memory, file-size, and execution-time limits.
  4. Apply equivalent resource restrictions to the Pandoc/wkhtmltopdf path. Do not rely on renderer defaults for local-file or network isolation.

  5. Validate that markdown_path refers to an expected regular file in an approved report directory before processing it.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes shell-capable behavior via documented curl, pandoc, and Python command usage, but it does not declare any explicit tool scope such as allowed tools or permissions. That makes operational boundaries unclear and can enable broader-than-expected command execution or file access when the skill is invoked in an agent environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill is framed entirely around Chinese futures markets and Chinese-language trigger phrases, but the description does not explicitly state that the locale/language constraint is intentional nor offer user opt-in for language preferences. Under the stated policy, forcing a specific language or locale without opt-in can be a natural-language policy violation unless clearly justified and documented.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/report_generator.py (reported line 52)May include surrounding context.

python
# Use subprocess to call curl
    try:
        result = subprocess.run(
            ["curl", "-s", "-e", "https://finance.sina.com.cn", url],
            capture_output=True, text=True, timeout=10
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
87% confidence
Finding

The code converts attacker-controlled or untrusted markdown into PDF via external rendering engines (pandoc/wkhtmltopdf or weasyprint) without sanitization. Document conversion pipelines can fetch remote resources or process active content, creating risk of SSRF, local file disclosure, or exploitation of parser/rendering bugs if untrusted input is converted.

Content

Scanner excerpt · scripts/report_generator.py (reported line 140)May include surrounding context.

python
# Try pandoc
    try:
        subprocess.run(["pandoc", str(markdown_path), "-o", str(pdf_path), "--pdf-engine=wkhtmltopdf"], 
                      check=True, capture_output=True)
        print(f"[OK] PDF generated: {pdf_path}")
        return True

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown explicitly instructs users to save report.md and generate report.pdf, which are file-write operations. The section presents these actions as routine export steps but does not include any warning or disclosure that running them will create or overwrite local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This code performs file creation by writing a PDF to disk, but the function only prints success after the write completes and does not include any prior warning, confirmation, or cautionary comment/docstring about modifying the filesystem. Under the code-file criteria, file writes should have some visible disclosure unless clearly covered as part of the skill's stated purpose; here the write behavior is present but not explicitly warned about to the user before execution.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.