Back to skill

Security audit

法律合同风险审查系统

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward contract-risk checker that analyzes user-provided contract text without evidence of hidden access, persistence, or data exfiltration.

Before installing, users should understand that contract text can contain confidential business or personal information, so they should redact unnecessary sensitive details and should not treat the output as formal legal advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly invites users to submit full contract text, which commonly contains highly sensitive business terms, personal information, signatures, contact details, and dispute history, but it provides no privacy, retention, redaction, storage, or access-control guidance. In a legal-review context this omission materially increases the chance that users disclose confidential or regulated data without understanding how it will be handled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and all user-facing instructions are written entirely in Chinese, with no indication that users may choose another language or that the skill is intended only for a Chinese-speaking or China-specific context. The policy requires either user opt-in for language/locale restrictions or a clearly documented justification for the constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's natural-language descriptions, labels, messages, and recommendations are entirely hard-coded in Chinese, with no visible option for the user to choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly requests the full contract text, which commonly contains highly sensitive commercial, personal, and legal information, but provides no privacy notice, data-handling disclosure, retention policy, or minimization guidance. In a legal-review context, users are especially likely to submit confidential documents, so the absence of clear handling warnings materially increases the risk of unintended data exposure or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

All user-facing instructions and examples in the file are in Chinese, which effectively forces a specific language for use of the skill. The README does not indicate that the tool is region-specific or provide any user opt-in or alternative language option.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.