Back to skill

Security audit

sales-winner-assistant(赢单助手)

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent sales assistant, but it needs review because it can turn broad requests into web research, customer-record updates, task creation, reminders, and colleague notifications without clear approval controls.

Install only for an authorized sales context. Keep it read-only unless you explicitly approve each CRM/customer-profile update, opportunity-stage change, task, reminder, or notification. Review web-sourced facts before using them, and avoid entering confidential customer notes or personal contact details unless your organization permits that use.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The document says the skill will automatically update customer profiles, opportunity status, tasks, and notify colleagues after merely analyzing a visit record. Those are state-changing side effects beyond a read-only parsing request, and they can modify CRM data or trigger workflow actions based on unverified or mis-transcribed input.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The skill text promises automatic updates while also stating that key information must be confirmed by the user before updating. This contradiction creates an unsafe ambiguity: implementers or users may assume confirmation is optional, leading to unauthorized or premature changes to customer and sales records.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill’s activation guidance is broad enough to trigger on common requests like generic company analysis or follow-up advice, which can cause the agent to invoke this skill outside the user’s intended scope. In this skill, that matters because invocation leads to opinionated sales guidance, automatic strategy generation, and external company/personnel data collection, increasing the risk of unexpected data processing and manipulative sales outputs.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The trigger phrases include very generic language such as requests equivalent to 'check this', 'latest status', 'what to do next', or 'give me suggestions', which overlaps heavily with ordinary conversation. Because the skill also contains auto-triggered follow-on behavior and strong vendor-biased recommendations, an accidental match could steer unrelated interactions into targeted sales playbooks or real-time external lookups without clear user intent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The description does not clearly warn users that the skill performs real-time web searches and collects external information about companies, executives, IT systems, and decision-makers. In context, this omission is significant because the workflow explicitly prioritizes external sourcing and personnel-related intelligence, so users may unknowingly trigger broad data collection and profiling behavior.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The file instructs the agent to automatically launch broad web searches whenever a user asks to analyze any company, with no narrowing based on user authorization, business necessity, target type, or sensitive-context exclusions. In a sales-intelligence skill, this can cause unnecessary collection of third-party data at scale and expand the scope from user assistance into generalized profiling, increasing privacy, compliance, and misuse risk.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill explicitly directs collection of decision-maker information, including CIO, CFO, CEO, management team changes, and contact-related clues from bidding records, but provides no privacy warning, lawful-basis check, or handling restrictions. In context, this is more dangerous because the skill is designed to help sales staff identify and exploit buying windows and key individuals, making it easy to convert broad web scraping into targeted profiling of identifiable persons.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The file instructs the system to 'automatically call this module after customer analysis' without defining strict activation boundaries, user consent requirements, or context validation. In a sales assistant that handles broad enterprise-analysis requests, this can cause unintended invocation and generation of persuasive strategy outputs in situations where the user did not explicitly request them, increasing the risk of overreach, privacy misuse, and workflow manipulation.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The '按客户特征自动触发' logic uses broad customer attributes to automatically activate sales messaging and recommendation paths, but it does not specify scope limits, confidence thresholds, or approval steps. Because this skill is designed for enterprise sales operations and can influence competitive positioning, such loose triggering increases the chance of misfiring on partial or inferred customer data and producing inappropriate or manipulative guidance.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger examples for bid/opportunity discovery are broad enough that ordinary user requests like asking about recent tenders or ERP projects could invoke the skill without a clear intent to use this specific capability. In an enterprise agent, over-broad routing can cause unintended collection, analysis, and prioritization of external business data, producing misleading sales actions or exposing sensitive workflow context.

Vague Triggers

Medium
Confidence
95% confidence
Finding
Phrases like "关注一下XX行业的动态" and especially "XX地区有什么好消息" are ambiguous and can match many non-sales requests. Because this skill performs business-opportunity monitoring and downstream planning, ambiguous activation increases the chance of unintended surveillance-style analysis and automatic follow-on actions based on weak user intent.

Vague Triggers

Medium
Confidence
97% confidence
Finding
The keyword list includes generic phrases such as "有新的线索吗", "行业动态", and "帮我找找客户" without constraints, making accidental invocation likely in normal conversation. In this skill's context, unintended triggering is more dangerous because it chains into strategy generation, customer prioritization, and work-plan creation, amplifying the effect of a mistaken route.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger phrases include very generic expressions such as '制定计划', '今天做什么', '帮我安排一下', and '待办事项', which can match ordinary conversation unrelated to this sales workflow. In an agent skill that can drive downstream CRM updates and reminders, overly broad triggering increases the chance of unintended activation, causing the assistant to enter a sales-planning flow when the user did not explicitly request it.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The document states that after generating a work plan, the system can trigger 'CRM数据更新', '提醒设置', and '拜访记录分析' with automatic parsing and updates, but it does not specify user consent, confirmation, scope limits, or safeguards. In a sales assistant context handling customer and opportunity records, this creates a real risk of unauthorized or mistaken data modification, reminder spam, or corruption of customer records from incorrect parsing.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The trigger phrases include very broad language like '这个客户什么情况' and even direct sending of voice or text records, which can overlap with ordinary conversation. In a skill that can lead to downstream updates, broad triggers increase the chance of accidental invocation, unintended parsing of sensitive content, and initiation of impactful follow-on actions without clear user intent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill advertises automatic updates to profiles, opportunities, tasks, and notifications without a clear warning that these are impactful side effects. Users may reasonably believe they are only requesting analysis, while the system may change CRM state or alert colleagues, creating integrity, privacy, and workflow risks.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrases are generic requests like '给我一些建议' and '看看需要什么行动', which can match many ordinary conversations unrelated to sales workflow. This can cause the skill to activate unexpectedly, hijack user intent, and steer the assistant into producing sales-specific guidance or handling business data in contexts where the user did not actually request this skill.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file is entirely written as Chinese sales scripts and templates, with no indication that the agent should adapt language to the user's preference. In a general-purpose assistant context, this can cause the skill to respond in a language the user did not request, reducing usability and potentially causing misunderstanding in sales, procurement, or compliance-sensitive conversations.

Static analysis

No suspicious patterns detected.