Back to skill

Security audit

Customer Visit Prep

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent customer-visit preparation assistant, but it automatically reads and writes persistent customer memory that may contain sensitive business information without clear user confirmation or retention controls.

Review this skill before installing in environments with confidential sales, customer, or account data. It should require confirmation before reading or writing customer memory, show a preview of saved content, constrain customer-name paths, and confirm recipients before sending generated documents through enterprise messaging.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:75
Finding

Unconfirmed Automatic Access and Modification of Persistent Customer Memory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 75–78
Vulnerability Type: Automatic persistent-memory access without explicit user approval
Risk Level: Medium

Complete Relevant Skill Instructions:

markdown
## Memory Integration

- Before preparing for a visit, retrieve historical interactions from `memory/customers/{customer_name}.md`.
- After the visit, remind the user to conduct a visit review using the Sales Review Manager's `review-visit` scenario.
- Automatically append the current visit-preparation content to the customer memory file.

The excerpt above is an English rendering of the complete source segment at the specified lines.

Technical Analysis

The Skill directs the agent to retrieve historical customer interactions and automatically append generated visit-preparation content to persistent customer memory. It does not require explicit user approval before either operation and does not specify validation or normalization of the customer name used to select the memory file.

This creates two security concerns:

  1. Historical customer information may be retrieved and incorporated into a response without confirming that the current user is authorized to access it.
  2. User-controlled or model-generated content may be written into persistent records without review, allowing inaccurate, sensitive, or adversarial content to influence later sessions.

If the implementation directly substitutes a supplied customer name into the documented path, insufficient path validation could also allow unintended file selection. The reviewed package contains no implementation code proving that path traversal is possible, so this aspect remains a conditional risk rather than a confirmed exploit.

Attack Path

  1. A user supplies a customer name and visit context containing inaccurate, misleading, or adversarial information.
  2. The Skill uses the customer name to identify a persistent file unde ...[truncated 1209 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require explicit user confirmation before reading customer history and again before writing generated content to persistent memory.
  2. Display the target customer record and a preview of the proposed changes before committing them.
  3. Validate customer identifiers against a strict allowlist of expected characters and lengths.
  4. Resolve and normalize the target path, then verify that it remains within the designated memory/customers/ directory.
  5. Use an authorization check to ensure that the current user may access the selected customer record.
  6. Store structured, provenance-tagged entries rather than appending unrestricted text. Record the source, timestamp, author, and confidence level.
  7. Exclude unnecessary personal, confidential, and credential-like information from persistent storage.
  8. Treat stored customer content as untrusted data when it is retrieved, and never interpret stored text as agent instructions.
  9. Maintain an audit log and provide rollback or deletion controls for erroneous entries.
  10. Add tests covering unauthorized record access, malicious customer identifiers, path traversal attempts, instruction-like memory content, and rejected or cancelled writes.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1)May include surrounding context.

md
---
name: customer-visit-prep
description: >
  客户拜访一站式准备。输入客户名+背景+拜访目的,自动输出客户调研报告+拜访策略+话术+注意事项。

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to automatically append visit-preparation content to a customer memory file introduces a persistent write without user warning or approval. Because the content may include sensitive customer names, deal context, and strategy, unauthorized retention can expose confidential business information and create compliance issues.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest description and trigger wording are entirely Chinese and present the skill as operating in Chinese without documenting any user language option or justified locale restriction. This can violate language or locale policy where skills should not force a specific language absent opt-in or clear regional scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger wording is broad enough that ordinary conversation about visiting customers could activate the skill unintentionally. Accidental activation matters here because the skill may perform searches, generate sharable artifacts, and interact with persistent memory, causing actions the user did not clearly request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger examples are illustrative but do not define firm boundaries for when the skill should run versus when the assistant should simply answer normally. In a sales-assistant context, this ambiguity increases the chance of unrequested search, data retrieval, and downstream persistence of customer-related information.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill declares conversational output and optional document generation, but also instructs the agent to automatically append preparation content into a persistent customer memory file. This creates a hidden side effect that can store sensitive business context beyond the current task without clear disclosure or consent, increasing privacy and data-governance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Generating files and transmitting them via enterprise messaging can move sensitive customer strategy or sales material outside the immediate chat context. Without a privacy warning, destination confirmation, or transmission safeguards, users may unknowingly disclose confidential information to unintended recipients or channels.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Persisting and reusing customer interaction history across sessions expands the data exposure surface beyond the immediate task. In this context, the stored information could include customer identities, internal strategy, procurement signals, and meeting objectives, which may be commercially sensitive and unnecessary to retain without explicit governance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language description is written entirely in Chinese and does not indicate any user language choice or opt-in. Under the policy, locale or language constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.