Back to skill

Security audit

外卖评价智能监控

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its review-monitoring purpose, but it stores optional platform API keys in plaintext and can generate unsafe HTML reports from customer review text.

Install only if you are comfortable handling review exports and generated reports as sensitive local files. Avoid enabling API mode or entering real platform API keys until secret storage is improved, and do not open generated HTML reports from untrusted review data without fixing HTML escaping or using an isolated browser context.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/reporter.py:214
Finding

Stored Cross-Site Scripting Through Unescaped Review Content

Content
View full analysis
{"".join(f'''
{r["content"]}
评分:{r.get("rating","-")} 情感:{r.get("score","-")} {r.get("time","-")}
''' for r in negative_reviews[:15]) if negative_reviews else '
暂无差评 🎉
'} ``` The affected content originates from imported review data and is added to the report data in `scripts/analyzer.py`: ```python result["negative_reviews"].append({ "content": str(row['content'])[:200], "score": round(row.get('sentiment_score', 0), 2), "time": str(row.get('review_time', '')), "rating": row.get('rating', None), }) ``` ### Technical Analysis Review content is attacker-controlled data imported from CSV, Excel, or JSON files. The reporter inserts `r["content"]` directly into an HTML element through an f-string without HTML escaping or sanitization. Truncating the review to 200 characters does not prevent HTML or JavaScript injection. A short payload containing a script-capable element or an event-handler attribute can remain valid within that limit. Because imported reviews are also merged into `history.csv`, the injected content can persist and be included in later reports generated through history or check operations. The vulnerability is therefore a stored injection issue rather than only a one-time reflected issue. The report also lacks a restrictive Content Security Policy that could mitigate inline script and event-handler execution. ### Attack Path 1. An attacker submits a malicious review to a supported platform, or supplies a crafted CSV, Excel, or JSON review file. 2. The review includes ...[truncated 1348 chars]
Remediation
View remediation
``` 5. Avoid inline JavaScript and inline event handlers so that a strict CSP can be enforced. 6. Add security tests using reviews containing closing tags, event-handler attributes, script tags, encoded markup, and malformed HTML. 7. Sanitize previously stored review content when regenerating reports; do not assume existing `history.csv` data is trusted. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/monitor.py:60
Finding

API Credentials Are Entered Visibly and Stored in Plaintext

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:8
Finding

Unpinned Python Dependencies and Unverified Remote JavaScript

Content
View full analysis
``` ### Technical Analysis The Python dependencies have no exact version constraints or cryptographic hashes. The installed artifacts can therefore change between installations even though the audited Skill source remains unchanged. The configured package mirror also becomes part of the trusted supply chain. The ECharts reference specifies a version but retrieves executable JavaScript at report-viewing time from jsDelivr. No `integrity` attribute is provided, so the browser cannot verify that the received file matches a reviewed artifact. This means effective executable code can be supplied by external package repositories, mirrors, CDNs, or their upstream release infrastructure after the Skill itself has been audited. ### Attack Path #### Python dependency path 1. A user installs or activates the Skill dependencies. 2. The package installer resolves the latest versions matching the unpinned package names through the configured mirror. 3. A compromised upstream package, mirror, maintainer account, or dependency release supplies malicious code. 4. The malicious pac ...[truncated 1086 chars]
Remediation
View remediation
``` 8. Add a Content Security Policy that permits scripts only from approved local or integrity-protected sources. 9. Ensure reports can function offline so opening a report does not silently retrieve executable code from the network. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown states that the skill automatically monitors and analyzes customer review data from multiple delivery platforms, but it does not mention any privacy, data-handling, or retention warning. Because review exports may contain customer-generated content and related business data, the description should disclose that users are processing potentially sensitive data locally and should verify compliance with applicable privacy requirements.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares behavior that reads user-provided files, writes reports, and creates local configuration/history files, but it does not define an explicit tool scope such as permissions or allowed-tools. This creates a mismatch between documented capabilities and declared restrictions, increasing the chance of unintended file access or writes if the runtime grants broader defaults than users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases include very generic terms such as '评价分析' and 'review monitor', which can overlap with ordinary conversation and cause accidental invocation. Unintended activation is risky here because the skill can process local files and create persistent artifacts on disk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation examples are broad everyday requests like '检查外卖评价' and '生成评价报告', which do not clearly distinguish this skill from normal assistant behavior. In context, ambiguous triggering could lead to unintended analysis runs, local data processing, or scheduled automation without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The API mode mentions collecting and using platform credentials but does not clearly explain how secrets are stored, protected, rotated, or deleted. Poor credential-handling disclosure is dangerous because API tokens for merchant platforms may expose customer review data or operational business information if stored insecurely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module description and surrounding natural-language strings are written entirely in Chinese, and the skill provides no indication that language choice is optional or region-specific by design. Under the policy for natural-language issues, forcing a specific language without user opt-in is a locale policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup flow collects platform API keys via stdin and save_config persists the entire config object as plaintext JSON under ~/.food_review_monitor/config.json. API credentials stored unencrypted in a predictable path can be exposed to other local users, backups, malware, shell history/desktop indexing side channels, or accidental sharing, leading to unauthorized access to external platform accounts or data APIs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module description and all user-facing output are written exclusively in Chinese, indicating the skill is designed to operate in a fixed locale without offering any language or locale choice. The policy explicitly flags language or locale constraints when they are forced without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

All user-facing documentation in this file is Chinese, and there is no indication that the skill supports other languages or that Chinese-only usage is a deliberate, documented regional limitation. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language instructions, examples, and operational guidance are presented only in Chinese, which effectively imposes a language constraint on users. The file does not offer an alternate language option or explicitly state that the skill is intentionally limited to a Chinese-speaking or China-region audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill does disclose local storage later in the document, but the description and activation-facing sections do not prominently warn users that configuration and historical review data will be created and retained on disk. This weak disclosure can undermine informed consent and surprise users with persistent local data retention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level docstring describes the skill entirely in Chinese, and the implementation also hard-codes Chinese-language labels and outputs. For a general-purpose skill file, this imposes a specific language/locale without any visible opt-in, configurability, or justification that the tool is limited to a Chinese-only deployment context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This manifest-style JSON file contains user-facing notes and labels exclusively in Chinese, such as the shop name and explanatory note fields. Because the file provides no language choice or opt-in and does not document a justified region-specific restriction, it appears to force a specific language/locale in a way that conflicts with the stated policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.