Back to skill

Security audit

伐谋 - 实验管理

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Famou experiment-management purpose, but it needs Review because it installs mutable packages, stores API keys insecurely, and can delete or resubmit experiments without clear confirmation.

Review before installing. Use this only in a controlled environment, prefer a pinned and verified famou-sdk install, avoid entering API keys through command-line arguments, check permissions on ~/.famou-ctl/settings.json, and require explicit confirmation before canceling, deleting, modifying, or resubmitting experiments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned SDK Installation from Mutable Package Repositories

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:45
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis
``` ### Technical Analysis The documented workflow passes the API key as a positional command-line argument. Command-line arguments can be exposed through shell history, terminal logging, agent execution logs, process monitoring, audit systems, and process-listing utilities such as `ps`. Although operating-system restrictions vary, another local process or administrative monitoring service may be able to capture the credential while the command is running. The secret may also remain in persistent shell or agent logs after the process exits. Masking the key in the script's JSON output does not protect the original command-line argument. ### Attack Path 1. A user provides a valid Famou API key to the agent. 2. The agent executes the documented command with the key embedded in its argument list. 3. A local attacker, monitoring service, command logger, or retained shell history records the command. 4. The attacker extracts the plaintext API key. 5. The attacker authenticates to the Famou service using the stolen credential and performs any operations authorized for that key. ### Impact Assessment The scope of compromise is bounded by the permissions assigned to the stolen API key. Potential effects include unauthorized access to experiment metadata, logs, results, experiment submission, cancellation, or deletion. Persistent command logs may extend the exposure beyond the duration of the skill invocation. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/config.py:48
Finding

API Credential File Created Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向 famou 实验任务生命周期管理的技能,触发场景集中在‘提交实验’、‘查看实验状态’、‘删除实验’、‘获取实验结果’等操作。但给出的代码只是在本地用户目录下读写配置文件 ~/.famou-ctl/settings.json,并输出 api_url、掩码后的 api_key,以及缺失字段检查结果。write 命令还会写入默认 api_url 和 user_id。整个代码没有任何与实验任务相关的网络请求、任务 ID 处理、状态查询、结果下载、删除操作或 config.yaml 上传逻辑。因此其实际主要用途与声明的核心用途明显不一致,属于实质性描述-行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs actions that can modify local state, including installing packages and writing API configuration via scripts/config.py write, but it does not declare any tool restrictions or explicit permissions. In an agent environment, missing scope boundaries increases the chance the skill is invoked with broader-than-necessary file write capability, enabling unintended local changes or secret persistence.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases are overly broad, including generic terms like “提交” or “跑实验” whenever context mentions the platform, which can cause unintended invocation of a skill that performs installation, configuration, and potentially destructive experiment actions. Overbroad triggering increases the risk of the wrong workflow being activated and sensitive or state-changing commands being suggested or executed inappropriately.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the user to provide an API key and then passes it directly on the command line to a local script. Command-line arguments can be exposed through shell history, process listings, logs, or telemetry, making credential leakage more likely in shared or monitored environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes experiment deletion as a supported operation without requiring an explicit warning, confirmation, or verification step. In a workflow management context, deletion is destructive and may irreversibly remove experiment records, logs, or results if executed from mistaken context or against the wrong experiment ID.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file includes natural-language docstrings, CLI help text, and status/error messages only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This skill includes credential configuration management even though the manifest describes experiment workflow management. Expanding scope to read and write local API credentials increases the trust and attack surface of the skill: a workflow-triggered skill can become a persistence point for secrets and may be invoked in broader contexts than users expect.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code persistently stores the API key in ~/.famou-ctl/settings.json without any permission hardening, encryption, or use of the OS credential store. If the local machine is multi-user, backed up, synced, or otherwise accessible to other processes, the plaintext credential can be recovered and used to access the remote Famou service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language instructions and user-facing behavior are entirely specified in Chinese, with no indication that the user may choose another language or locale. Under the language/locale policy, forcing a specific language without user opt-in is a policy concern unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.