Back to skill

Security audit

Software Copyright Cn

Security checks for vulnerabilities and agentic risk

Overview

This skill appears purpose-built for Chinese software copyright paperwork, but it can copy broad source content into shareable PDFs and store personal contact details without enough safeguards.

Install only if you are comfortable with the agent reading the selected source tree and generating PDFs that may be submitted externally. Use it on trusted repositories, inspect the included files and final PDFs before sharing, keep software_info.json out of version control, and avoid entering or storing personal contact details unless required for your filing. Treat generated security, API, login, backup, and admin-function sections as draft text that must be verified or removed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/generate_source_pdf.py:188
Finding

Source Directory Boundary Bypass Through Symbolic Links

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_doc_pdf.py:1270
Finding

Unescaped ReportLab Paragraph Markup in Imported Documents

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

代码内容明确是 generate_doc_pdf.py,其核心行为是生成“文档鉴别材料PDF(用户手册)”或把已有文本转换为PDF。虽然这与声明中的一个子能力相符,但声明将技能描述为“软著申请所需的全部材料生成器”,并特别列出软件基本信息表单和程序鉴别材料PDF(源代码高亮)两项能力,而在本代码片段中均未体现。因此,若将该代码块视为对技能实际行为的代表,则其实际能力明显窄于声明的整体用途,构成描述与行为不一致。未发现与此目的无关的可疑外部访问或越权行为;不匹配主要在于功能范围被夸大。

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to explore a user's code repository and read source files, but it does not declare any explicit tool scope or allowed-tools constraints. In practice, this creates an authorization-boundary problem: the skill can induce file access behavior without a machine-readable limitation on which files or directories may be read, increasing the chance of overbroad repository inspection or accidental access to unrelated local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill collects detailed personal contact information including real name, address, postal code, and phone number, then instructs saving it to software_info.json, but provides no privacy notice, retention limits, masking guidance, or handling constraints. This creates unnecessary exposure of personally identifiable information in plaintext files that may be retained, shared, committed to repositories, or processed by other tools without the user's informed consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file contains user-facing instructions only in Chinese, which can constitute a language/locale policy violation when no opt-in or alternative language is provided. The policy specifically calls for flagging cases where a skill forces a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generator emits detailed claims about authentication, RBAC, encryption, audit logging, backup, API security, and other concrete product capabilities without verifying that the target software actually implements them. In this skill’s context, the output is intended for software copyright registration materials, so inaccurate security and capability assertions can become authoritative-looking compliance evidence and mislead reviewers, customers, or internal stakeholders.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README title and description present the skill entirely in Chinese and position it specifically as a China software copyright application material generator, with no indication that users may choose another language or locale. Under the policy criteria, forcing a specific language without user opt-in is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring describes the tool as a Chinese document generator with automatic Chinese font discovery, which imposes a specific language/locale behavior. The file does not indicate that users can opt into another language or that the Chinese-only constraint is required by a clearly documented regional compliance scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains natural-language strings that assume Chinese as the required user language, including the module docstring and CLI help/messages. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs a file write by creating the output PDF at the chosen path, but there is no check for an existing file and no confirmation prompt before replacement. Although the script logs the target path, it does not disclose overwrite behavior or protect existing user data at that location.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.