Versioned security assessment

Report ID: SA-5C948AF0

10/4/2026, 2:41:09 PM

oil-ui security assessment v1

Skill Security Certification Report

Audit History
Scanner version 3.0.0 Audit model: codex Latest published report
Skill name
oil-ui
Version
v0.15.4
Maintainer
oil-oil
Coverage
24 Files scanned · 3,676 Lines analyzed
Policy version
skillstore-security-audit-policy-v1

Highest confirmed finding severity

High

2 confirmed security findings require attention.

Installation context

Check the current Skill page

This page summarizes report evidence only. The Skill page provides the canonical install advisory.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

Most alerts are benign JavaScript syntax, image data, Chinese documentation, and negative test fixtures. Confirmed risks include unpinned automatic updates, inherited secrets, and unsafe preview input handling. Release-note trust and selector interpolation add injection risks; no evidence of intentional malware was found.

Report position

Latest published report

Latest refers to the report sequence, not to artifact currentness.

Audit attestation

Active attestation

A public attestation is available for this exact report.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

24 Files scanned · 3,676 Lines analyzed

8 items shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Commit and path bound

  2. Artifact

    Content and tree hashes bound

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Observed in 2 evidence locations

Network access

May connect to external services.

Observed in 45 evidence locations

Filesystem access

May read or write local files.

Observed in 38 evidence locations

Env variables

May read values from the process environment.

Observed in 25 evidence locations

External commands

May invoke commands or programs outside the Skill.

Observed in 52 evidence locations

Capability review items (6)
High
Python subprocess.run
result = subprocess.run([npx, "-y", CLI, "update", name, "--path", str(ROOT), "--json"], env=env,
The updater runs npx -y against an unpinned GitHub CLI and replaces the installed skill without fresh consent. Compromised upstream code could execute locally.
High
Python environment access
env = {**os.environ, "CI": "1"}
The updater copies every environment variable into the unpinned downloaded CLI process. This exposes unrelated credentials to code outside the audited package.
High
Synchronous file operations
res.end(readFileSync(local));
The server reads files after a string-prefix containment check, which accepts sibling directories and follows escaping symlinks. Local requests can disclose files outside the preview root.
High
Ruby/shell backtick execution
版本检查:!`sh "${CLAUDE_SKILL_DIR}/scripts/check_update.sh" 2>/dev/null || true`
This is a real host command hook, not ordinary Markdown formatting. Loading the skill can trigger unpinned remote CLI execution through check_update.sh.
Medium
Synchronous file operations
writeFileSync(file, Buffer.from(data, "base64"));
Screenshot paths incorporate unchecked --states values at lines 358-359 and 366. Parent-directory segments can escape the output directory and overwrite writable PNG files.
Medium
Synchronous file operations
writeFileSync(tmp, html);
The generated sheet includes unescaped state labels from line 284, then opens the HTML at line 292. Crafted labels can execute scripts or load external resources.

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (2)

RISK-001 High
Untrusted Release Notes Enter Agent Instructions
Remote release notes are copied into updater notices after minimal trimming. SKILL.md tells agents to relay these notices, creating a prompt-injection channel.
The remote notes flow directly into output the agent consumes. No embedded attack was found, but the source-to-instruction trust boundary is explicit.
RISK-002 Medium
Selector Interpolation Allows Browser Code Injection
The type action inserts its selector directly into a quoted JavaScript error message. Crafted quotes can execute unintended code in the inspected page.
The querySelector argument is serialized, but the same selector is interpolated without escaping in the error string. An isolated expression check confirmed injection.

Remediation

Suggested fixes recorded by this audit. Applying them is the maintainer’s responsibility.

  1. FIX-001
    High
    Skill loading can execute an unpinned GitHub updater and replace audited files.
    Make updates opt-in, require confirmation, pin the CLI to a reviewed commit, and verify replacement artifacts before loading them.
  2. FIX-002
    High
    The downloaded updater inherits all environment variables.
    Pass a minimal environment allowlist and only explicitly authorized authentication values. Exclude unrelated project and service credentials.
  3. FIX-003
    High
    The local preview server uses string-prefix containment and follows symlinks.
    Resolve the root and target with realpath, enforce path-relative containment, and test encoded traversal, sibling prefixes, and escaping symlinks.
  4. FIX-004
    High
    Remote release notes are presented to agents without a clear trust boundary.
    Treat release notes as quoted untrusted data, remove control characters, and never execute or adopt instructions from updater output.
  5. FIX-005
    Medium
    Unchecked screenshot state names can escape the output directory.
    Generate safe artifact identifiers independently from state text, enforce output containment, and reject escaping paths before writing.
  6. FIX-006
    Medium
    Contact-sheet state labels are inserted into executable HTML.
    Render captions with textContent or HTML escaping. Apply a contact-sheet CSP that disables scripts and external resources.
  7. FIX-007
    Medium
    The type action embeds a raw selector in evaluated JavaScript.
    Serialize every dynamic string with JSON.stringify, including error messages. Add regression tests with quotes and code-like selectors.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
5c948af074e24413a5278072a82a5caa758753ba
Content hash
7e54a37acfc7601b6be919a53f5a3668db6beb7322f6e1fb8cc2e1ad8d328c30
Tree hash
74dfcc43cd92eb80de5c25761160452842152842998f71db5053d996e5d148f7
Skill path
skills/oil-oil/oil-ui
Audit payload hash
b55cb8c9d3c1bd4d5f8e963c51f69511

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: active