Back to skill

Security audit

AI 项目评估助手

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its API configuration can send credentials and project details to an unintended or arbitrary LLM endpoint.

Review this skill before installing. Use it only with non-sensitive project descriptions unless you trust the configured LLM endpoint, and avoid running it in an environment containing unrelated OPENAI_API_KEY values. Prefer setting a provider-specific key intentionally and verify the destination before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/evaluate_project.py:6
Finding

API Credential Disclosure Through Unbound and Attacker-Controlled API Endpoint

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tainted flow: 'req' from os.environ.get (line 17, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The script reads both the API key and the API endpoint from environment variables, then sends the bearer token to whatever URL is in API_BASE. If an attacker can influence the environment, they can redirect requests to a malicious server and capture the credential, causing secret exfiltration and unauthorized API use. In this skill’s context, outbound LLM access is expected, but allowing an untrusted base URL makes the credential flow significantly more dangerous than a fixed vendor endpoint.

Content

Scanner excerpt · scripts/evaluate_project.py (reported line 19)May include surrounding context.

python
], "temperature": 0.7}).encode()
    req = urllib.request.Request(f"{API_BASE}/chat/completions", data=payload,
        headers={"Content-Type": "application/json", "Authorization": f"Bearer {API_KEY}"})
    with urllib.request.urlopen(req, timeout=90) as r:
        return json.loads(r.read())["choices"][0]["message"]["content"]

def build_prompt(idea, context=""):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill title and description are entirely in Chinese and present the interaction mode as fixed, with no indication that other languages are supported or that the user can choose their preferred language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises executable tool usage via a Python command that can write files and potentially access environment/networked resources, but it does not declare any explicit tool scope or permissions. This weakens containment and reviewability because the runtime capabilities are broader than what the manifest communicates, increasing the chance of unintended file writes, data exposure, or network misuse if the backing script is unsafe.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The display name, description, usage instructions, and output examples are all presented only in Chinese, which effectively imposes a language constraint through the skill's natural-language interface. The file does not indicate that users may choose another language or that the Chinese-only behavior is a documented, justified regional requirement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger language is very broad, inviting activation whenever a user merely describes a project idea. Overly generic invocation criteria can cause unintended skill routing, which may expose user input to tooling or scripted processing when the user only expected normal conversation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The example phrase '帮我评估这个项目' is generic and likely to overlap with normal conversational requests. That ambiguity can trigger the skill unexpectedly, reducing user control and potentially invoking script-backed behavior without clear consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes an idea-evaluation assistant that produces market/technical/business/risk analysis. While calling an LLM API is expected implementation detail, directly reading provider API keys and base URL from environment variables introduces credential access capability that is not stated or obviously inherent from the manifest text itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The system prompt explicitly instructs the model to '请用中文输出', which imposes a specific language regardless of user preference. Under the policy, forced language/locale behavior is a natural-language policy violation unless the user is given an opt-in choice or the restriction is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.