Back to skill

Security audit

聚水潭 ERP

Security checks for vulnerabilities and agentic risk

Overview

This ERP skill is mostly purpose-aligned, but it stores and uses sensitive ERP credentials through a broad API caller without enforcing its own consent and endpoint limits in code.

Install only if you are comfortable storing Jushuitan ERP credentials locally and letting the skill make authenticated API calls. Use least-privileged, read-only ERP tokens where possible, avoid passing secrets in shell commands, review profiles.json handling, and prefer a version that enforces consent and an endpoint allowlist in code.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/jst_erp.mjs:120
Finding

ERP API calls do not enforce recorded user consent

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/jst_erp.mjs:52
Finding

Caller-controlled API paths allow access beyond the documented read-only scope

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/jst_erp.mjs:94
Finding

Secrets are accepted through exposed command-line arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
- 保存方式:使用文件写入工具(如 `create_file` 或 `file_replace`),在当前 skill 根目录下创建或更新 `profiles.json` 文件。文件路径为 `<skill_root>/profiles.json`,skill 根目录即本 `SKILL.md` 所在的目录。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
- agent 可以直接运行 `scripts/jst_erp.mjs public-ip` 获取并告诉用户。

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/jst_erp.mjs (reported line 107)May include surrounding context.

js
app_secret: args["app-secret"],
      access_token: args["access-token"],
      refresh_token: args["refresh-token"] || profiles[name]?.refresh_token || "",
      env: args.env || profiles[name]?.env || "prod",
      updated_at: new Date().toISOString(),
    };
    saveProfiles(profiles);

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to perform network-relevant actions such as retrieving the public IP and accessing external ERP services, but it declares no explicit tool scope or allowed-tools boundary. This creates a least-privilege violation: an agent runtime may permit broader tool or network use than users expect, increasing the chance of unintended outbound access, data exfiltration, or unsafe execution paths involving sensitive ERP credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation without any stated trigger constraints, exclusions, or user-confirmation boundaries. Because this skill handles ERP connectivity and merchant operational analysis, automatic invocation could expose or act on sensitive business data in contexts where the user did not clearly intend to use this integration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file’s instructions, examples, and expected outputs are entirely Chinese-language, which effectively forces a specific language/locale for skill operation. The policy allows this only when the skill offers user choice or clearly documents a justified regional constraint, neither of which appears here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The callApi function sends access_token, app_key, signature material, and biz data to remote Jushuitan API endpoints via HTTP POST. The code performs this transmission without a user-facing warning, confirmation, or inline disclosure near the call path, so users may not realize potentially sensitive business data is being sent off-host.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The public-ip command performs an external request to api.ipify.org that is unrelated to the stated ERP data connection and analysis purpose. Unrelated network-capable features expand the attack surface, disclose environmental metadata, and can be repurposed for reconnaissance in environments where users expect only ERP operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script stores app_key, app_secret, access_token, and potentially refresh_token in a local profiles.json file without any explicit disclosure or consent flow warning users that long-lived credentials will persist on disk. Even with restrictive file permissions, local persistence raises exposure risk from backups, shared environments, compromised accounts, or accidental inclusion in the skill directory.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The generic call command accepts arbitrary --path values and forwards authenticated requests using stored JuShuiTan credentials, enabling access well beyond the narrowly described analysis scenarios. In skill context, this effectively turns the tool into a broad API proxy, increasing the chance of unauthorized or overly broad data access, state changes, or misuse of merchant credentials.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/jst_erp.mjs:62