Back to skill

Security audit

digital-solution-designer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Chinese-language digital solution planning aid with a local Graphviz diagram script, and the observed risks are disclosed operational caveats rather than malicious behavior.

Install only if you are comfortable with a Chinese-language planning workflow that may ask for project, budget, system, and organizational context. Run Graphviz setup in a virtual environment or container, approve any apt/pip installation yourself, and require the agent to ask before web searching or using sensitive client details in external queries.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Graphviz Dependencies Create a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:5-7, SKILL.md:413, SKILL.md:491, README.md:310, README.md:379
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

SKILL.md:5-7:

yaml
dependency:
  python:
    - graphviz>=0.20.1

SKILL.md:413 and SKILL.md:491:

shell
pip install graphviz
apt-get install graphviz

README.md:310 and README.md:379:

shell
pip install graphviz

Technical Analysis

The project declares graphviz>=0.20.1 and instructs users or agents to install graphviz without an exact version, package hash, lockfile, or explicit trusted package repository. The lower-bound constraint permits any future package version, while pip install graphviz normally resolves the latest compatible release available from the configured package index.

Consequently, the dependency installed during one execution may differ from the dependency reviewed during the audit. If the configured repository, package publisher account, package artifact, dependency resolution process, or local package-index configuration is compromised, attacker-controlled code could be introduced through the installation workflow.

The apt-get install graphviz instruction also modifies the host environment and may be executed with elevated privileges depending on the operating environment. No malicious dependency or compromised repository was identified during this audit; the vulnerability is the unsafe and non-reproducible dependency acquisition process.

Attack Path

  1. An attacker compromises a relevant package release, publisher account, configured package repository, mirror, or dependency-resolution environment.
  2. A user or agent activates the Skill and follows its prerequisite installation instructions.
  3. pip install graphviz or the non-exact graphviz>=0.20.1 constraint resolves an artifact that was n ...[truncated 1178 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the lower-bound dependency with an exact, reviewed version:

    yaml
    dependency:
      python:
        - graphviz==0.20.3
    

    The exact version should be selected after compatibility and security review.

  2. Maintain a lockfile or requirements file containing cryptographic hashes:

    text
    graphviz==0.20.3 --hash=sha256:<verified-package-hash>
    
  3. Install dependencies with hash enforcement:

    shell
    python -m pip install --require-hashes -r requirements.txt
    
  4. Explicitly use an approved package repository or internally controlled mirror, and ensure package-index configuration cannot silently redirect resolution to an untrusted source.

  5. Pin the operating-system Graphviz package to an approved repository version where operationally practical. Verify repository signatures and metadata before installation.

  6. Do not automatically perform privileged package installation. Request explicit user approval before changing the host environment, and prefer an isolated virtual environment or container with minimal privileges.

  7. Add automated dependency scanning and scheduled review of pinned versions so security updates can be adopted deliberately without allowing unreviewed versions to be installed automatically.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

描述声称的是一个覆盖数字化解决方案设计全流程的综合能力,而代码仅实现了“架构图生成”这一很窄的子功能。代码没有任何与政策分析、需求分析、实施计划、风险评估、投资估算、文档生成或方案分类相关的逻辑;也没有处理政府/企业数字化转型场景知识的能力。它主要做的是接收 DOT 或模板并调用 Graphviz 渲染图片文件。虽然描述中提到架构设计(业务、功能、数据、技术四维度),代码确实提供了若干对应模板,但这只能部分支撑“架构图可视化生成”,不足以匹配所宣称的全流程方案设计能力,因此构成明显不符。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README presents all instructions, prompts, examples, and required interaction text exclusively in Chinese, including mandatory user-facing wording. Under the language/locale policy, forcing a single language without user opt-in can be a natural-language policy issue unless the constraint is explicitly justified or alternatives are offered.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation scope mixes very specific government-digitalization terms with broad generic keywords, but does not define boundaries for when the skill should not run. That ambiguity can cause accidental invocation in unrelated requests, leading the agent to over-collect information, impose mandatory workflow steps, or follow unsuitable design patterns outside the intended scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The activation scope mixes very specific government-digitalization terms with broad generic keywords, but does not define boundaries for when the skill should not run. That ambiguity can cause accidental invocation in unrelated requests, leading the agent to over-collect information, impose mandatory workflow steps, or follow unsuitable design patterns outside the intended scope.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill references multiple local files under references/ and scripts/, which implies file-read capability, but the manifest does not declare any explicit tool scope such as allowed-tools or permissions. This creates an authorization ambiguity: an agent may read more of the workspace than users expect, increasing the risk of unintended data exposure if similarly named sensitive files are present or if tool mediation is weak.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

该技能的名称说明、任务目标、触发条件和全部操作指引均以中文固定表述,面向交互的询问语也只提供中文版本,未说明可根据用户偏好切换语言。按规则,若技能在自然语言层面强制特定语言而没有用户选择或明确限定理由,属于语言/locale 策略风险。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad phrases such as '规划方案', '政务系统', and '工作汇报', which are likely to overlap with ordinary conversation and invoke the skill outside the user's intent. Over-broad activation can cause unintended collection of business context, generation of authoritative-seeming planning content, or unnecessary file/script references in conversations that did not request this specialized workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill file is written in Chinese and does not indicate that the language is optional, user-selected, or limited to a region-specific use case. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill content is written in Chinese and provides no indication that users may choose another language or that Chinese is required for a region-specific purpose. This creates a natural-language policy concern because it effectively imposes a locale/language choice without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains natural-language documentation entirely in Chinese, and later user-facing help and error strings are also Chinese-only. Under the stated policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified or alternatives are offered.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly permits the agent to obtain missing client-current-state information by searching the internet for similar customers' common conditions. In a solution-design context, this expands the agent's authority into external research without clear source restrictions, consent boundaries, or verification requirements, which can introduce data leakage, hallucinated assumptions, and untrusted external content into deliverables.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill instructs the agent to obtain current-state information 'from internet search' when user information is incomplete, but it does not require user consent, source validation, or boundaries on what may be searched. In enterprise or government contexts, this can lead to unapproved external data gathering, inaccurate assumptions being presented as fact, or inadvertent disclosure of sensitive project intent through queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

文件标题及全文内容均以中文呈现,但没有说明这是面向中文用户的区域性文档,也没有提供其他语言选项或用户选择机制。根据规则,强制特定语言且缺乏明确的适用范围或用户 opt-in,属于自然语言层面的语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing natural language content exclusively in Chinese, starting with the title and continuing throughout the document. Under the policy, forcing a specific language without user opt-in can be a locale-policy violation when no alternative language option or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all guidance in a single fixed language and does not mention any language preference, alternatives, or opt-in. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

该文件全文以中文撰写,未见任何关于语言可选项、受众范围或地区限定的说明。根据语言/locale 政策,若技能内容强制单一语言而无用户选择或明确正当化,可能构成自然语言层面的策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file uses Chinese throughout, including the title and all operational guidance, but does not indicate that the user can choose another language or that Chinese is required for a specific region-only use case. Under the policy, forcing a specific language without user opt-in is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains natural-language guidance exclusively in Chinese, including headings, descriptions, and selection guidance, but does not indicate that Chinese is optional or required for a specific regional context. Under the language/locale policy rule, forcing a single language without user opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructions and checklist content exclusively in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy for natural-language constraints, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is a markdown document, so natural-language policy checks apply. Its content exclusively uses Chinese for headings and instructions, and nowhere indicates that the skill is China-specific or that users may choose another language, which can violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.