Back to skill

Security audit

skill-to-cn

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-localization tool, but its helper script can delete any existing output directory the user or agent points it at.

Review this before installing or running it. Use only on skill directories you trust, avoid custom --output paths unless they point to a new empty directory, and do not let untrusted skill text choose paths. The main risk is accidental or attacker-influenced deletion of local directories writable by the current user.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/translate_skill.py:98
Finding

Arbitrary Recursive Directory Deletion via Unrestricted Output Path

Content
View full analysis

Vulnerability Details

File Location: scripts/translate_skill.py, lines 98-99 and 440-444
Vulnerability Type: Unrestricted user-controlled path used for recursive deletion
Risk Level: High

Vulnerable Code

python
if output_override:
    target_path = Path(output_override).expanduser().resolve()
python
# Create the target directory
if target_path.exists():
    print("Target directory already exists and will be overwritten")
    shutil.rmtree(target_path)

target_path.mkdir(parents=True)

The translated English message above corresponds to the original Chinese status message; executable behavior is unchanged.

Technical Analysis

The command-line --output argument is converted into an absolute path but is not constrained to an approved output directory. The script does not reject critical paths, verify that the destination was previously generated by this tool, ensure that the source and target differ, or require confirmation before deletion.

Calling Path.resolve() only normalizes the supplied path; it does not establish that the path is safe. Any existing writable directory selected through --output is passed directly to shutil.rmtree(), which recursively removes its contents.

The option is part of the documented interface in SKILL.md, which demonstrates invocation with --output /custom/output. Consequently, an accidental argument or an attacker-influenced instruction can direct the script to remove unrelated data.

Attack Path

  1. An attacker, untrusted Skill instruction, or mistaken user command supplies an existing writable directory through --output.
  2. get_skill_paths() resolves and accepts that directory without containment or protected-path validation.
  3. translate_skill() detects that the destination exists.
  4. The script invokes shutil.rmtree(target_path).
  5. The selected directory and all descendants are recursively deleted before the re ...[truncated 848 chars]
Remediation
View remediation

Remediation Suggestions

  1. Restrict output destinations to an explicitly approved base directory, such as the configured Claude Skills directory, and validate containment using resolved paths.
  2. Reject filesystem roots, home directories, the source directory, ancestors of the source directory, and other protected locations.
  3. Explicitly verify that source_path != target_path and that neither path contains the other where deletion could affect source data.
  4. Do not recursively delete an existing destination by default. Abort with an error unless the user supplies an explicit --force option.
  5. When running interactively, display the resolved destination and require affirmative confirmation before destructive replacement.
  6. Create generated output in a new staging directory, validate it, and use a controlled rename or replacement operation only after successful processing.
  7. Before replacing an existing directory, require a tool-specific marker file proving that the directory was generated by this script.
  8. Add automated tests covering root paths, home paths, source/output equality, parent-child path relationships, symlink-resolved paths, and unrelated existing directories.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states the skill translates skills into Chinese and is triggered when users ask to '汉化技能' or '翻译技能' into Chinese, but it does not offer any language or locale choice. Under the policy rules, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to read source skill files and write translated files, but it does not declare any explicit tool scope or path restrictions. That creates an over-broad capability surface where an agent may access or modify unintended files if given a malicious path or if the source skill content is adversarial.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file states that translated skills should explicitly specify Chinese as the output language by default, unless the original text requires otherwise. This imposes a locale/language policy on downstream skill behavior without indicating that the end user can choose or opt in to a different language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template under '实施方法' tells authors to add instructions saying output content defaults to Chinese unless the user explicitly asks for another language. That is a natural-language locale policy that forces a specific language by default rather than offering a neutral preference-preserving behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s natural-language description and all user-facing behavior are explicitly tied to converting skills into Chinese, and the runtime messages/help text throughout the script are also fixed in Chinese. Under the policy, forcing a specific language without offering a user choice or opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.