Back to skill

Security audit

一人公司记账管家

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malware, but it needs review because it handles sensitive bookkeeping while also allowing account-key API access and external forum posting without clear consent controls.

Install only if you are comfortable with a finance assistant that may contact soloteam.com.cn for tax cards, may use a user-provided Bearer Key for team reconciliation, and includes an optional external posting workflow. Before use, require explicit approval for any API call that uses a key or posts content, and keep bank records, invoice numbers, customer names, amounts, and tax filings local unless you deliberately approve a narrow disclosure.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description lists generic trigger terms such as “记账”, “对账”, “月结”, and “报税”, and the argument hint also uses broad phrases like “帮我记账/月结/列申报清单”. These are common user utterances that could match many ordinary conversations, and the file does not provide narrowing conditions, explicit exclusions, or negative examples to bound when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs external retrieval of tax-card data and later API use involving a Bearer Key, but the up-front interface does not clearly warn that network access and potentially sensitive business context may be transmitted. In a bookkeeping skill, hidden or under-disclosed network behavior is especially sensitive because financial records, tax context, and credentials are high-value data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The alliance/team revenue-sharing API access extends the skill from bookkeeping into account-linked external data retrieval using a Bearer Key. This broadens privilege and data access beyond the core manifest purpose, increasing the risk of credential misuse, overcollection of third-party business data, and user surprise about networked account access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill claims bookkeeping data stays local, but it also instructs posting to an external forum endpoint. Even though it says to post only desensitized policy discrepancies, this expands behavior beyond local processing and creates a path for unintended business-data disclosure or operator confusion about what may be transmitted.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Community posting is not necessary for routine bookkeeping output and introduces an unrelated external action surface. In a finance context, even optional outbound posting is risky because users may not expect the agent to transmit any derived information to third-party services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.