Back to skill

Security audit

Sop Extractor

Security checks for vulnerabilities and agentic risk

Overview

This SOP-to-skill generator is coherent in purpose, but it would create persistent automations that may install software, read local agent configuration, and store credentials with too little scoping and consent.

Review before installing. Do not let generated skills automatically install packages, write secrets into shell profiles or plaintext .env files, or read local agent configuration without explicit approval. Use a secret manager or scoped app tokens, redact sensitive documents and screenshots, and require human confirmation before saving generated skills or running workflows that affect finance, HR, approvals, or business systems.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/credential-setup-guide.md:44
Finding

Unsafe Plaintext Credential Persistence and Shell Command Injection

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/skill-template.md:29
Finding

Automatic Installation of Unpinned Third-Party Dependencies

Content
View full analysis
Tools do not need to be installed in advance. The Agent automatically checks and installs them when reaching the relevant step. ``` ```markdown - **Dependency check at execution time**: `python3 -c "import xxx"` or `which xxx` - **If missing**: `pip install xxx` or fall back to manual mode ``` ```markdown | Tool not installed | Automatically attempt installation (`pip install` / `apt install`); fall back to manual mode on failure | ``` ### Technical Analysis The generated-Skill template instructs Agents to install packages automatically at runtime. It provides no requirements for: - Package-name validation or an approved allowlist - Version pinning - Cryptographic hash verification - Registry or repository restrictions - Publisher and provenance verification - Isolation in a virtual environment or container - User review and explicit approval - Prevention of elevated package-manager execution Python packages can run arbitrary code during installation or import. A misspelled, dependency-confused, compromised, or attacker-selected package can therefore execute code under the Agent's account. Permitting `apt install` also introduces the possibility of privilege escalation requests and system-wide modification. The extractor's legitimate function only requires documenting dependencies. Automatically installing arbitrary dependencies is not necessary during extraction and exceeds least privilege. ### Attack Path 1. An attacker supplies an SOP or conversational input that names a plausible but malicious tool or pa ...[truncated 930 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/tool-discovery-guide.md:71
Finding

Unnecessary Inspection of Local Agent Configuration and Skill Inventory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
**语言**:对用户说"工作流程文档",不说"SKILL.md";说"8 步里 5 步 AI 可以帮你做",不说"自动化率 62%"。

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file instructs modifying shell profiles and .env files to persist secrets, including replacement commands that write credential values directly into user-controlled config files. Persisting secrets in plaintext across broadly loaded environment files increases exposure to local compromise, accidental disclosure, process inheritance, backups, and version-control mistakes; this is especially unjustified for a skill whose stated purpose is SOP extraction.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template explicitly tells the agent to trigger even on a vague scenario, which encourages over-broad activation and increases the chance the skill runs outside its intended context. In an agent system, this can cause unintended workflow execution, incorrect tool use, or accidental handling of sensitive data when the user did not clearly request this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description claims the skill applies to 'any岗位' and 'any可标准化的重复性工作' across sensitive business domains, but it does not define clear activation boundaries, exclusions, or required user confirmation before processing potentially sensitive workflows. This can lead to overbroad use in high-risk contexts such as HR or finance, where the skill may solicit or normalize disclosure of confidential process details without adequate guardrails.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The description presents the skill entirely in Chinese and does not indicate that language choice is configurable or based on user preference. While not directly enabling code execution or privilege abuse, this can cause user misunderstanding about prompts, consent, or handling of extracted procedures, especially in multilingual environments where clarity of workflow instructions matters.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written as a Chinese-only interaction description and frames the skill in Chinese without indicating that users may choose another language. Under the policy rule, language constraints should either be optional or explicitly justified; neither appears here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The listed trigger phrase "帮我把工作变成Skill" is natural conversational language that could plausibly appear in ordinary discussion, making activation scope too broad. The file does not provide exclusion conditions or narrower context limits to reduce unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide explicitly instructs the skill to request external service credentials, accept user-provided secrets, store them, and verify them. For an SOP-extraction skill, this materially expands capability beyond extracting workflow knowledge and creates a path for unnecessary secret collection and handling, increasing the chance of credential exposure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide tells the user to provide credentials and then write them into persistent environment variables, but it does not clearly warn that this is plaintext storage with associated risks. Users may be led to expose SMTP passwords, webhook URLs, or database credentials without understanding the confidentiality and persistence implications.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger examples include very generic natural-language phrases such as asking the agent to help with reimbursement, which can overlap with ordinary conversation and unintentionally activate or route into this skill. In a skill that saves reusable workflows and may later automate business actions, ambiguous invocation increases the risk of accidental execution, misrouting, or unauthorized use in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The placeholder trigger format '[触发词]' does not constrain what final trigger will be registered, leaving room for unsafe, overly broad, or conflicting phrases to be chosen later. Because this skill is intended to create reusable automations from dialogue, unspecified trigger scope can propagate insecure defaults into generated skills and cause collisions with unrelated user requests.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to match common, ambiguous user phrases such as asking how to handle an invoice or requesting help with reimbursement. This can cause the skill to activate when the user only wants general advice, leading to unintended workflow execution, confusion, or premature handling of sensitive finance processes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all guidance, examples, and instructions exclusively in Chinese, which can amount to a language/locale policy violation when no user opt-in or justification is provided. The file does not indicate that the skill is region-specific or that users may select another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template normalizes automatic dependency checks and package installation during execution without requiring user notice or approval. This is dangerous because installing tools at runtime can introduce supply-chain risk, alter the execution environment unexpectedly, and execute package-install scripts without the operator making an informed decision.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The credential setup flow instructs the agent to write user-provided secrets into environment variables and continue, but it omits warnings about persistence, shell history, process exposure, logs, and least-privilege handling. In a skill generator context, this omission is risky because generated skills may replicate insecure secret-handling patterns across many downstream workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide explicitly instructs the agent to access Feishu/DingTalk document links via API or browser, but gives no requirement to verify authorization, obtain user consent, or warn that linked documents may expose private or internal data. In a document-extraction skill, this can normalize broad retrieval of enterprise content and increase the risk of over-collection or accidental access to sensitive information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

整份技能参考文档仅以中文编写,并以指令式语气规定操作流程,但没有提供用户语言选择,也未说明该技能仅面向中文团队或特定区域。根据语言/locale 政策,若技能强制单一语言而无用户 opt-in 或合理限定,属于自然语言层面的合规问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

All dialogue templates and user-facing instructions in this file are presented solely in Chinese, with no indication that the user may choose another language or that the skill is intentionally limited to a Chinese-language context. This can violate language/locale policy when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The guide tells the agent to process images/screenshots with vision capabilities without warning that screenshots often contain sensitive information such as personal data, credentials, internal dashboards, or confidential business context. Even without malicious intent, this omission can cause users to submit more data than necessary and lead to unnecessary exposure during analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and nowhere indicates that the skill is intended only for Chinese-speaking users or a China-specific environment. Under the language/locale policy rule, forcing a specific language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.