Back to skill

Security audit

data-grade-checker

Security checks for vulnerabilities and agentic risk

Overview

This is a small, disclosed data-classification decision-support CLI with no hidden persistence, credential access, network execution, or destructive behavior.

Install only if you are comfortable using a simplified, AI-assisted decision-support checker for GB/T 43697-2024. Treat its output as a starting point, not a compliance proof or legal opinion, and verify classifications against official current rules and qualified advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
The natural-language content of the skill forces a single language/locale for all user-facing instructions and warnings. Under the policy, language restrictions should either be optional for the user or clearly documented as a justified region-specific constraint, which is not present here.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The module docstring, CLI description, argument help text, and output/disclaimer strings are all presented only in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless a justified locale constraint is clearly documented, which is not present here.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Content
out_list.append({"tool": META["slug"], "input": d, "errors": [str(e)], "rc": 2, "aigc_mark": AIGC})
        print(json.dumps(out_list, ensure_ascii=False, indent=2))
        sys.exit(0 if allok else 2)
    args = {k: getattr(ns, k) for k in argnames}
    try:
        res, rc = _run(args)
    except GateError as e:
Confidence
50% confidence
Finding
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Static analysis

No suspicious patterns detected.