Back to skill

Security audit

投放素材效果诊断

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently analyzes user-provided advertising CSV reports locally, but users should treat generated Markdown as untrusted data before asking an AI to expand or share it.

Install only if you are comfortable giving the skill access to the specific ad report files you select. Review generated reports before sharing them through Feishu, email, or another channel, and ensure the consuming AI treats campaign names and other CSV values as untrusted report data rather than instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyzer_generic.py:188
Finding

Untrusted CSV Content Is Embedded Verbatim into an AI-Consumed Markdown Report

Content
View full analysis
Remediation
View remediation
", ">") return text[:500] ``` Use the function at every report interpolation point: ```python safe_name = escape_markdown_cell(row["name"]) report.append( f"| {i + 1} | {safe_name} | {row['roi']:.2f} | " f"{row['ctr']:.2%} | {row['cvr']:.2%} | " f"{row['spend']:.2f} | {row['revenue']:.2f} |" ) ``` 2. **Preserve the trust boundary for downstream AI processing** Pass report data to the AI in a structured data field rather than combining it with instructions. Explicitly identify CSV-derived values as untrusted data that must never be treated as commands. 3. **Prefer structured serialization** Generate JSON containing separately typed fields, and let a trusted rendering layer create Markdown. This prevents data fields from changing the report's structure. 4. **Validate text fields** Reject or normalize control characters, excessive lengths, embedded NUL bytes, bidirectional-control characters, and unexpected multiline values. 5. **Disable active Markdown constructs where possible** If the report is rendered as HTML, use a sanitizer that blocks remote images, unsafe links, raw HTML, and active URI schemes. 6. **Add adversarial tests** Test names containing table delimiters, headings, links, images, HTML, multiline instructions, and Unicode control characters. Verify that each value remains confined to one inert table cell. 7. **Apply protections consistently** The direct i ...[truncated 214 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · input/内容报表_20260314_092445_utf8.csv (reported line 1)May include surrounding context.

text
日期,主体ID,主体类型,主体名称,展现量,点击量,花费,点击率,平均点击花费,总成交金额,总成交笔数,点击转化率,总购物车数,收藏宝贝数,收藏店铺数,总收藏数,宝贝收藏成本
2026-03-13,555519041535,短视频,可爱家居,115,3,5.75,0.02609,1.92,0.00,0,0,1,0,0,0,
2026-03-13,555458610849,短视频,奶油风的家,161,3,5.16,0.01863,1.72,0.00,0,0,0,0,0,0,
2026-03-13,555458290062,短视频,沙发垫的正确打开方式,194,8,8.31,0.04124,1.04,0.00,0,0,0,0,0,0,

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes reading user-supplied local CSV files and invoking a Python script, but it does not declare any tool scope, permissions, or allowed-tools boundary. This creates an authorization ambiguity: an agent or runtime may permit broader file access than the user expects, increasing the chance of unintended local data exposure beyond the intended report input.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written entirely in Chinese and presents the skill as generally applicable, but it does not indicate that Chinese is optional or that the skill is limited to a Chinese-speaking or China-specific operational context. Under the policy rule, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that enriched recommendations may be sent through Feishu or email, but it does not warn that the generated report may contain sensitive business performance data, campaign identifiers, or creative names. If users or downstream agents follow this workflow automatically, sensitive commercial data could be transmitted to external channels without adequate consent, minimization, or sanitization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language strings such as the module docstring and argparse help text exclusively in Chinese, which effectively forces a specific language for users. The policy allows fixed locale only when the tool offers opt-in or clearly documents a justified region-specific constraint, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON manifest/config uses Chinese-only natural-language labels for all visible field names, which can impose a specific language/locale on users without any opt-in or explanation. The stated policy requires flagging language or locale constraints when they are forced rather than optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file content, including headers and titles, is entirely in Chinese and provides no indication that alternative languages or locale choices are supported. Under the stated policy, a skill artifact that effectively constrains interaction to a single language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/analyzer_generic.py (reported line 48)May include surrounding context.

python
mapping = json.load(f)
    # 命令行参数覆盖
    for key in ['id', 'name', 'impressions', 'clicks', 'spend', 'revenue', 'orders', 'cart', 'favorite', 'date']:
        arg_val = getattr(args, f"{key}_col", None)
        if arg_val:
            mapping[key] = arg_val
    return mapping

Static analysis

No suspicious patterns detected.