Back to skill

Security audit

长期计划推进

Security checks for vulnerabilities and agentic risk

Overview

This planning skill is mostly coherent, but it needs review because it combines persistent reminders, external fund lookups, and local file mutation with weak scoping.

Install only if you want a Chinese-language planning assistant that stores durable plan state, runs heartbeat-style checks, and may send fund codes to a third-party market-data service. Review or fix the filename validation and require confirmation before bulk task completion or automatic trigger setup.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fuzzy-match.mjs:144
Finding

Path Traversal Through Unvalidated Plan Filenames

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes behaviors that require network access and likely environment/runtime capabilities (cron registration, external fund API fetches, heartbeat processing) but does not declare any explicit tool scope or allowed-tools boundary. This creates a permission ambiguity where an agent may perform external calls or automation beyond what the user clearly authorized, increasing the chance of unintended data exposure or unsafe side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill advertises broad activation phrases like '今天计划任务' and '列出所有计划', which are common conversational expressions and could cause the skill to activate in situations where the user did not intend to invoke it. Accidental invocation is more dangerous here because the skill can read/write plan files and register reminders, so a trigger mismatch can lead to persistent state changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow states that creating a plan will automatically generate files, register triggers to cron, and update indexes, but the skill does not present a clear up-front warning that these persistent modifications and automations will occur. Users may believe they are only drafting a plan, while the skill actually enables background reminders and writes durable state, which undermines informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The asset-tracking logic performs external fund API calls to retrieve NAV data, but the skill does not provide a privacy notice or explain what identifiers may be transmitted externally. Even if only fund codes are sent, usage timing and tracked holdings can reveal sensitive financial interests and behavioral patterns, especially when combined with heartbeat automation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language completion feature allows commands like '所有/全部' to mark all pending tasks complete, which is an overly broad bulk action from ambiguous user text. In this skill's context, fuzzy matching plus batch completion can silently corrupt planning records, phase progress, and downstream review/automation logic based on task status.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script performs outbound network requests to a third-party fund data service during heartbeat-driven snapshot updates, but this behavior is not disclosed in the skill description. Undisclosed external fetching can expose sensitive portfolio metadata through request timing/content, create unexpected data egress, and introduce integrity/availability risks if the remote endpoint is manipulated or unavailable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments, examples, segmentation logic, trigger phrases, and CLI usage all assume Chinese text, and the matching behavior is built around Chinese-language phrases. This imposes a specific language/locale constraint without user opt-in or an explicit documented justification in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The function modifies plan files on disk based solely on a text match and performs no built-in confirmation, authorization, or dry-run step before persisting changes. In this skill’s context, fuzzy matching can misidentify a task and silently mark the wrong task complete, causing integrity loss in long-term plans and potentially triggering downstream workflow decisions based on incorrect state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains natural-language documentation and operational messages only in Chinese, including the module description and invocation instructions. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language content, including header comments, conflict reports, and CLI usage/output strings, is entirely in Chinese. This imposes a specific language on users without any opt-in, fallback, or documentation that the skill is intentionally region-specific, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file's user-facing CLI output and descriptive comments are entirely in Chinese, including usage and alert messages, with no indication that another language is supported or that the Chinese-only constraint is intentional and justified. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file defines and later uses a third-party market-data endpoint that is not evident from the stated long-term planning/reminder skill description. Hidden or undocumented network access expands the skill’s trust boundary, can leak user-linked financial interests such as fund codes, and introduces dependency on an external service without clear consent or disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs outbound requests to a third-party financial API during trigger evaluation, giving the skill an undeclared external communication capability. Even if only fund codes are sent, those identifiers can reveal user holdings or watchlists, and the external dependency could be abused for tracking, reliability issues, or future scope creep.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file contains natural-language comments and CLI strings entirely in Chinese, including the usage/help output shown to users. The skill does not provide any opt-in, alternative locale, or justification that it is intentionally region-specific, which conflicts with the language/locale policy for all file types.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage line defines broad natural-language triggers such as “开一个长期计划”, “今天计划任务”, and “列出所有计划”, which are generic phrases likely to overlap with ordinary user requests outside this specific skill. This can cause unintended invocation, leading the agent to expose or manipulate long-term-plan data when the user may have intended a normal planning conversation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill description and command phrases are presented only in Chinese, with no indication that the user can choose another language or locale. Under the stated policy, language constraints should be opt-in or clearly justified, and no such choice or justification is provided here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code includes natural-language comments and CLI output entirely in Chinese, such as the module description and completion/status messages. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The request URL embeds a user-provided fund code and sends it to an external service without any disclosure in this file. While the data volume is small, fund codes may still expose sensitive investment preferences or holdings context, making this a privacy issue rather than a direct code-execution flaw.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing instructions and templates in the file are presented in Chinese, and there is no natural-language statement offering alternative languages or confirming that Chinese is required for a region-specific purpose. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.