Back to skill

Security audit

Huanzhi Fa Skill Pro V2.8.0

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real fundraising-advisor skill, but it overclaims security review, stores sensitive founder data with broad activation and reminder behavior, and includes under-scoped dependencies and network-facing preview content.

Review this carefully before installing. Do not upload confidential BP, cap table, TS, or founder profile data unless you accept local retention in data/users and any host-level memory/reminder behavior. Ask the publisher to remove the unverified ClawHub audit claim, narrow activation triggers, document consent and deletion controls, and pin or remove unused dependencies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:53
Finding

Mandatory Recurring Paid-Tier Promotion Alters Agent Responses

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/funding_diagnosis.py:393
Finding

Malformed or Type-Confused JSON Can Crash Scoring or Produce a Misleading Sample Report

Content
View full analysis
dict: """读取JSON输入文件,失败时返回示例数据""" if not os.path.exists(path): return { "traction": {"mao": 50000, "moq_growth": 0.15, "mrr": 5000}, "market": {"competitors": 5, "customers_interviewed": 30, "tam": 50000000000}, "team": {"has_cto": False, "founder_count": 2, "industry_exp_years": 8}, "product": {"has_mvp": True, "version": "v2.1", "active_users": 500}, "story": {"has_bp": True, "bp_score": 62}, "unit_econ": {"ltv_cac": 3.2, "gross_margin": 0.6}, "use_funds": {"has_plan": False, "breakdown": {}}, "timing": {"runway_months": 8, "market_window": ""}, } try: with open(path, "r", encoding="utf-8") as f: return json.load(f) except (json.JSONDecodeError, FileNotFoundError): sys.stderr.write(f"⚠️ 无法读取 {path},使用示例数据\n") return parse_input("") ``` An example of an unsafe type assumption later in the scoring path is: ```python breakdown = d.get("breakdown", {}) if breakdown: detail_pct = sum(breakdown.values()) ``` All scoring functions similarly assume that the root input and each dimension are dictionaries: ```python d = data.get("traction", {}) ``` ### Technical Analysis The parser verifies only that input is syntactically valid JSON. It does not verify that: - The root value is an object. - Each scoring dimension is an object. - Numeric fields contain finite numbers. - Allocation fields are numeric mappings. - Percentage and count values are within reasonable ranges. A valid JSON array as the root causes an `AttributeError` when `data.get(...)` is called. A stri ...[truncated 1441 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned and Unused Third-Party Dependencies Increase Supply-Chain Exposure

Content
View full analysis
=5.4.1 edge-tts>=6.0.0 ``` ### Technical Analysis Both requirements specify only minimum versions and allow the installer to select any future compatible release. Consequently, the code installed in a user's environment can differ from the dependency versions considered during this audit. The audited scoring script imports neither package. Their inclusion therefore expands the package installation and transitive dependency surface without supporting the reviewed executable path. In particular, `edge-tts` provides network-capable text-to-speech functionality, which conflicts with the project's broad claim that execution is local-only unless its behavior is separately disclosed and controlled. No evidence showed that these package names are typosquatted or currently malicious. The risk arises from unrestricted future versions, unnecessary installation, and the absence of integrity hashes. ### Attack Path 1. A user installs dependencies from `requirements.txt`. 2. The package resolver selects the newest versions satisfying the lower bounds. 3. Package or transitive-dependency code not represented by the audited project source is installed. 4. If a future release or dependency is compromised, its code can execute during installation, import, or use with the privileges of the installing user. ### Impact Assessment Potential impact is limited by the privileges used for package installation. In a user-level environment, compromised dependency code could access that user's files and network. If dependencies are installed with administrative privileges, the possible scope is correspondingly larger. The repository itself contains no demonstrated dependency exploit or malicious dependency payload. ]]>
Remediation
View remediation

other

Note
Location
preview-page.html:7
Finding

Bundled Preview Page Makes an Undeclared Request to Google Fonts

Content
View full analysis
``` ### Technical Analysis The preview page imports its stylesheet from Google Fonts. When the page is opened in a browser with network access, the browser contacts Google's infrastructure and may subsequently download font assets from additional Google-hosted endpoints. This behavior conflicts with the broad local-only and zero-external-call statements shown in `SKILL.md:30` and repeated inside the preview page. The Python scoring implementation itself does not make this request; the issue is confined to rendering the bundled HTML preview. ### Attack Path 1. A user opens `preview-page.html` in a browser. 2. The browser requests the Google Fonts stylesheet. 3. The stylesheet may cause additional requests for font files. 4. The remote provider receives connection metadata, including the user's IP address, browser user agent, and request timing. ### Impact Assessment The issue leaks ordinary browser connection metadata to a third party. It does not expose local BP files, user profiles, credentials, or system privileges based on the reviewed HTML. No script execution, tracking code, or credential collection was found in the preview page. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述涵盖三项核心能力:融资准备度诊断、TS条款陷阱解析、投资人谈判模拟。代码只支持其中第一项,而且是基于固定阈值与加分规则的8维度评分,不是更广义的融资顾问系统。它读取JSON文件,计算分数、等级、短板和建议,并输出JSON报告;没有处理条款文本、没有法律/融资条款检查、也没有任何对话式谈判模拟。因此描述明显高于代码实际能力,属于实质性能力不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The changelog adds the chinese tag, which suggests a language or locale targeting choice. In this file there is no accompanying statement that users can choose their language or that the locale restriction is explicitly justified, so this may conflict with the policy against forcing a specific language/locale without opt-in.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill claims local-only behavior and references reading user files (for BP analysis, knowledge-base references, and data/users storage), but it does not declare an explicit tool scope such as file read permissions. This creates an authorization/expectation gap: a host may grant broader filesystem access than users expect, or the skill may fail open/behave unpredictably when file access is implicitly available.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Broad top-level triggers like '融资/条款/焦虑' can activate the skill during ordinary conversation, causing unsolicited collection or processing of sensitive business and emotional information. In an assistant environment with multiple skills, ambiguous activation increases prompt-routing confusion and the chance that private content is handled by the wrong skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description explicitly states "中文" as part of the skill positioning, and the comparison table later emphasizes the product language as Chinese. The file does not indicate that users can choose another language or opt into this locale restriction, which can violate language/locale policy expectations for user choice.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Module-level trigger words such as '焦虑', '放弃', or '迷茫' are common everyday terms and may capture unrelated personal or mental-health discussions outside the intended fundraising scope. Because this skill also describes memory, profiling, and follow-up behavior, accidental activation could lead to unnecessary retention or inference about highly sensitive user state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document declares lang="zh-CN", which sets the page language and locale to Simplified Chinese for all users. The file does not present this as an optional user choice or document a justified region-specific requirement, which conflicts with the policy against forcing a specific language/locale without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation hint 触发:融资/条款/焦虑 includes broad terms such as financing, terms, and especially anxiety, which can overlap with common conversation and make it unclear when the skill should activate. The description does not define specific trigger phrases, scope constraints, or negative examples to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The page presents contradictory security assertions: the content says the skill was 'Audited by ClawHub' and 'Security scan passed ✓' while the sidebar shows the security audit is still pending. This can mislead users into trusting and installing the skill under false security assurances, which is especially concerning because explicit claims of being verified safe should increase suspicion rather than reduce it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all failure-handling instructions and user-facing prompt text exclusively in Chinese, but does not state that the skill is China/Chinese-specific or that the user can opt into this language. That can violate language/locale policy when users are not given a choice or documentation for the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file presents all headings, descriptions, examples, and constraints only in Chinese. Under the policy rule for language/locale, forcing a single language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger configuration uses very broad, common phrases such as '不知道', '怎么办', '担心', and '急', which can appear in many ordinary conversations unrelated to fundraising support. In an always-on or loosely scoped skill-routing system, this can cause unintended activation, leading the agent to inject financing advice, emotional coaching, or negotiation scripts into contexts where they were not requested.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire system prompt is written to enforce Chinese-only interaction patterns and output structure, but it does not offer users a choice of language or explain a justified locale restriction. This creates a natural-language policy concern because it implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The routing table uses broad natural-language trigger phrases like '融资', '条款', '焦虑' without clear precedence, disambiguation, or confirmation steps. This can cause the agent to enter the wrong workflow, collect unnecessary sensitive business information, or provide mismatched legal/financial guidance in a high-stakes fundraising context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language documentation for the skill is presented only in Chinese, including the usage note and warning. This can violate a language/locale policy when the skill forces a specific language without giving users an explicit choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's docstring, user instructions, and generated human-readable messages are in Chinese, which effectively forces a specific language for users. The file does not provide any opt-in, fallback, or explanation that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description advertises trigger terms including broad everyday words such as “融资/条款/焦虑”, and especially a generic emotional term like “焦虑” can cause accidental activation during normal conversation. In a skill with memory, scheduled tasks, knowledge-base access, and file writing, unintended invocation increases the chance of collecting sensitive business or emotional-state data and taking actions the user did not explicitly intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language description states "🇨🇳 中文" and presents the skill as Chinese-language focused, but does not indicate that users may choose another language or opt in to this constraint. This can violate language/locale policy when a specific language is imposed without explicit user choice or documented regional necessity.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The table identifies the skill language as "中文" while competitor tools are listed with other language options, but there is no accompanying note that users may request another language or that the restriction is justified by a region-specific requirement. This reads as a forced locale constraint in the natural-language documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file presents all user-facing content exclusively in Chinese, and there is no accompanying note that the skill is region-specific or that users can choose another language. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that users may choose another language or locale. Under the policy, language constraints should either be optional or clearly justified; no such opt-in or justification appears in this file.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

PyYAML is specified with a lower bound only, so builds can resolve to different future versions over time. This weakens supply-chain reproducibility and can unintentionally pull in a vulnerable or breaking release, especially relevant because PyYAML has a history of security advisories.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
PyYAML>=5.4.1
edge-tts>=6.0.0

Unverifiable Dependency: PyYAML has 8 known advisory(ies) (CVE-2019-20477 (Deserialization of Untrusted Data in PyYAML); CVE-2020-1747 (Improper Input Validation in PyYAML); CVE-2020-14343 (Improper Input Validation in PyYAML) +5 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The manifest includes PyYAML without pinning an exact version, while PyYAML has multiple known advisories affecting some releases. Because the resolved installed version is unknown, deployments may consume a vulnerable version, and if the application parses untrusted YAML this could lead to unsafe deserialization or input-validation issues.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
89% confidence
Finding

edge-tts is also unpinned, which makes installations non-reproducible and increases supply-chain risk if a future release introduces a vulnerability or malicious code. Even without a known current CVE in this finding, allowing arbitrary newer versions is a security hygiene issue.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
PyYAML>=5.4.1
edge-tts>=6.0.0

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This code opens and parses an arbitrary path provided on the command line, which is a file access operation covered by the missing-warning rule for code files. The script has no confirmation prompt and no explicit warning in comments or docstrings that it will read the specified local file; it only shows generic usage instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.