Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 97% confidence
- Finding
该脚本的实际功能是一个电影数据采集器:调用猫眼的上映列表、即将上映列表和详情接口,整理字段并输出 JSON。代码注释也明确写着“纯数据采集,不做过滤”。声明中的核心能力——个性化推荐、基于用户偏好档案智能排序、飞书周报推送——在代码中完全没有体现,也没有任何用户数据读取、排序打分、消息发送或调度逻辑。因此描述与实际行为存在明显且实质性的不匹配。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Chinese movie recommendation workflow that fetches Maoyan movie data, uses a user-created preference file, and can send scheduled reports to Feishu.
Before installing, expect the skill to fetch current movie data from Maoyan, read your local movie preference profile, and send generated recommendations to Feishu if you configure that delivery. Keep sensitive personal notes out of profile.json, review any profile updates before allowing them, and be aware that the referenced profile-template.json was not present in the inspected package.
该脚本的实际功能是一个电影数据采集器:调用猫眼的上映列表、即将上映列表和详情接口,整理字段并输出 JSON。代码注释也明确写着“纯数据采集,不做过滤”。声明中的核心能力——个性化推荐、基于用户偏好档案智能排序、飞书周报推送——在代码中完全没有体现,也没有任何用户数据读取、排序打分、消息发送或调度逻辑。因此描述与实际行为存在明显且实质性的不匹配。
The script performs outbound HTTP requests to Maoyan APIs via urllib.request, so it has network capability that should be explicitly declared and reviewed. Undeclared network access weakens permission transparency and can enable unexpected data exfiltration or policy bypass if the skill is executed in a broader agent environment.
The README explicitly instructs users to send personalized movie reports to Feishu while the ranking logic depends on a local preference profile containing detailed taste data and potentially identifiable behavioral information. There is no warning, consent step, data-minimization guidance, or description of what profile-derived content may be transmitted off-device, so users may unintentionally disclose personal preference data to an external platform.
The skill handles a personal preference profile and instructs delivery of recommendation reports to Feishu, but the top-level description does not prominently warn users that personalized viewing preferences and derived recommendations may be transmitted to an external service. This can cause unintentional disclosure of sensitive preference data, especially if users assume processing remains local or within the agent environment.
The skill states that the AI will update profile.json in response to conversational requests, but it does not clearly warn users that a persistent local preference file may be modified. This creates risk of silent or unintended changes to user data, which can affect future recommendations and potentially overwrite sensitive notes users did not intend to store.
The module docstring explicitly states it is '纯数据采集,不做过滤' and the code only fetches Maoyan now-showing/coming-soon listings plus per-movie details, then prints structured JSON to stdout. Nothing in the file builds user preference profiles, performs intelligent ranking, or pushes a Feishu report, which are central behaviors promised by the manifest description.
The module docstring is entirely in Chinese and provides the usage description only in that language. This imposes a specific language on users without any opt-in or alternative, which matches the language/locale policy violation category.
The natural-language instructions throughout the file are entirely in Chinese, and the README does not indicate that the skill is intentionally limited to Chinese-speaking users or offer any language/locale choice. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy issue.
The natural-language instructions, examples, and interaction model are entirely in Chinese, and the manual trigger phrases are presented only in Chinese. Under the stated policy, forcing a specific language without giving the user a choice can be a locale/language policy violation unless clearly justified as region-specific with documented constraint.
No suspicious patterns detected.