Back to skill

Security audit

业务图形生成

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed business-graphics renderer that sends user-provided chart data to a configured rendering service and writes the returned image locally.

Install only if you are comfortable sending the chart data you provide to the configured render service, especially for confidential business material. Review or set CHART_RENDER_BASE_URL and CHART_RENDER_API_KEY intentionally, and prefer non-sensitive test data until you trust the service endpoint.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (20)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs use of local Python scripts plus outbound HTTP calls and implicitly relies on environment variables, file reads/writes, network access, and shell execution, but it declares no explicit tool scope or permission boundaries. In an agent environment, this increases the chance of overbroad tool access, accidental data exposure through env vars or filesystem access, and unintended network actions beyond the minimum required for rendering graphics.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and the entire user-facing guidance are written in Chinese, and examples explicitly prefer Chinese labels such as 中文名称, without indicating that other languages are supported or that the user can choose a locale. This creates a natural-language locale constraint without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill metadata and default prompt authorize broad use of the skill for selecting graphics, querying online contracts, generating data, and rendering images without clear trigger boundaries or user-consent constraints. In an agent setting, this can cause over-invocation, unintended external lookups, and expansion of the skill’s authority beyond the user’s explicit request, increasing the chance of data leakage or unsafe tool use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The metadata and prompt are written to force Chinese-language behavior by default, regardless of the user’s language preference. While not directly enabling code execution, this can mislead users, reduce transparency of tool actions, and increase the risk that users approve rendered outputs or online queries they do not fully understand.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file imposes a specific language/locale for the skill instructions without indicating that users can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file is written only in Chinese and provides no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file presents all user-facing instructions and examples exclusively in Chinese, which imposes a specific language on users. Under the policy, language constraints should either be optional or clearly justified; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains all user-facing instructions in Chinese, and there is no indication that the skill is region-specific or that users may choose another language. That can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill file is written only in Chinese and presents the timeline specification exclusively in that language, with no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-language context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

标题及整篇说明均以中文编写,但未说明这是面向特定中文用户群体的区域性文档,也未提供其他语言选项。按照语言/locale 政策,若技能内容强制单一语言而没有用户选择或明确正当性,属于自然语言层面的策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

A language-specific skill description can violate locale-choice policy when it implicitly forces one language for all users. This file contains only Chinese instructions and does not provide an opt-in, alternative language, or justification that the skill is intended exclusively for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Dynamic import via __import__()

Medium
Category
Dangerous Code Execution
Confidence
75% confidence
Finding

Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.

Content

Scanner excerpt · scripts/_client.py (reported line 98)May include surrounding context.

python
def read_json_input(path: str) -> Any:
    raw = __import__("sys").stdin.read() if path == "-" else Path(path).read_text(encoding="utf-8")
    try:
        return json.loads(raw)
    except json.JSONDecodeError as error:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains natural-language documentation and command-line help text entirely in Chinese, starting with the module docstring. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The argparse description, help text, and emitted error output are presented only in Chinese. Because these are user-facing strings in a code file and no language selection or locale justification is provided, they violate the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructions, examples, and constraints solely in Chinese. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents all user-facing guidance exclusively in Chinese, and there is no indication that this language constraint is optional or limited to a justified region-specific use case. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire markdown file is written in Chinese and presents all instructions, examples, and constraints only in that language. This can constitute a language/locale policy issue when the skill does not document any user opt-in or alternative language support.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing instructions and labels in Chinese, and nowhere indicates that the language is optional or intentionally limited to a Chinese-only audience. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions and constraints exclusively in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing instructions only in Chinese, which can amount to forcing a specific language without user opt-in. The policy allows justified region-specific constraints, but this file does not state any locale limitation or provide alternatives.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.