Back to skill

Security audit

变更方案自动审核助手

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real deployment-plan reviewer, but it persistently stores original operational documents and report evidence, including possible credentials, without enough user control or retention limits.

Review this skill before installing in any environment that handles production deployment plans, inventories, IP lists, hostnames, or credentials. Use it only with a clear local storage policy, redaction of credential evidence, restricted file permissions, and a cleanup process for data/raw, output reports, and the master tracking workbook.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_review_report.py:988
Finding

Unconditional Persistent Archival of Sensitive Operational Documents

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_review_report.py:581
Finding

Detected Plaintext Credentials Are Reproduced in Persistent Reports

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_review_report.py:900
Finding

Excel Formula Injection Through an Attacker-Controlled Plan Filename

Content
View full analysis
5 else ("条件通过" if p1 else "通过")], ] for row_data in summary_data: ws2.append(row_data) wb.save(output_path) ``` It is also written directly into the persistent master tracking workbook: ```python wb = openpyxl.load_workbook(str(TRACK_XLSX)) ws = wb.active for f in findings: ws.append([ts, plan_name, f["id"], f["level"], f["location"], f["description"], f["evidence"][:200], f["suggestion"], "待修改"]) wb.save(str(TRACK_XLSX)) ``` ### Technical Analysis Spreadsheet applications can interpret text beginning with `=`, `+`, `-`, or `@` as a formula. The plan name is derived from a user-controlled DOCX basename and passed directly to `openpyxl`. For example, a filename with a basename resembling the following can become a formula cell: ```text =HYPERLINK("https://attacker.example/collect","Open report").docx ``` Exact formula capabilities depend on the spreadsheet client, version, operating system, and security configuration. At minimum, formula injection can create deceptive links or external data references. In permissive or legacy environments, spreadsheet formulas may enable more significant external interactions. Although several other finding fields are generated from document content, the confirmed direct injection route is the attacker-controlled plan filename s ...[truncated 1377 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented behavior and the actual/prescribed behavior diverge in several security-relevant ways, including undeclared data retention and output generation. When a skill silently archives user files or produces additional artifacts beyond its stated purpose, users and reviewers cannot accurately assess privacy, storage, and operational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The instructions require copying all user-supplied files into a raw archive before any processing, yet no explicit consent or warning is required. This is especially risky because change plans and deployment spreadsheets commonly contain confidential system architecture, network topology, and potentially operational secrets, so compulsory archival materially increases breach impact.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill embeds file-writing and persistence behavior but does not declare any explicit tool scope or permissions boundary. That increases the chance the runtime grants broader filesystem access than users expect, making unintended data storage or modification harder to govern and audit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description is written to prescribe default output behavior in Chinese context and the rest of the skill consistently assumes Chinese-language interaction, but nowhere offers language selection or states that the skill is intentionally restricted to a Chinese-only audience. This can violate language/locale policy when users have not opted into that language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill states that it will save generated reports and, in the broader instructions, user documents, but does not present a clear user-facing privacy or retention warning. Because the inputs are enterprise change plans and spreadsheets, silent storage can expose sensitive infrastructure details, internal IPs, hostnames, or credentials to later unauthorized access.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed keywords include broad phrases such as “帮我审核方案”, “帮我检查方案”, and “帮我审一遍”, which are generic requests that could match many unrelated review tasks rather than this specific deployment-plan skill. The trigger section does not provide negative examples or tighter constraints to prevent unintended invocation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly mandates retaining raw copies of all uploaded files in a history directory. Persistent storage of original documents increases the attack surface and the blast radius of any local compromise, because sensitive source materials remain available long after the review task completes.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill requires keeping all process artifacts, including original uploads and generated reports, in a persistent skill directory. Centralized long-term retention of both inputs and derived outputs creates an attractive repository of sensitive operational data and makes later unauthorized discovery easier.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest claims the review is grounded on templates under /home/deploy_template and that template discovery should prioritize plan filename keywords. This file only uses local skill data/output directories and hardcoded chapter heuristics; it performs no access to /home/deploy_template and no filename-based template resolution.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a conditional requirement: the deployment table is required by default unless the user clearly says they do not want it. The validator and CLI enforce --deploy as mandatory in all cases, with no branch supporting an explicit opt-out.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code persistently copies raw input plan and spreadsheet files into a local archive directory, even though these documents can contain infrastructure details, host/IP inventories, and explicit credential material the tool already detects. This creates unnecessary long-term retention of sensitive data and increases blast radius if the skill workspace, backups, or neighboring processes are accessed by unauthorized parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill writes user-supplied documents to disk without clear disclosure, which is especially risky because the reviewed content may include passwords, topology data, and operational procedures. Undisclosed persistence violates data minimization expectations and can surprise users who assume analysis is transient.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest explicitly promises a default concise Markdown response while also saving a Word report. In the implementation, the audit flow generates a Word report, an Excel tracking sheet, and appends to a master Excel workbook, but nowhere constructs or returns Markdown content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Appending findings into a cumulative master workbook creates cross-run persistence of issue evidence, locations, and potentially sensitive excerpts from customer documents. Over time this centralizes data from multiple reviews into one file, increasing exposure and enabling unintended data mixing between users, projects, or tenants.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Persistently aggregating findings and evidence into a master workbook without clear disclosure creates an undisclosed audit trail containing sensitive operational details. In a shared or multi-user skill context, this is more dangerous because it can expose prior users' review artifacts beyond the immediate task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all instructions, examples, and guidance exclusively in Chinese. Under the policy rule for natural-language violations, forcing a specific language without user opt-in or a documented justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's natural-language description and user-facing strings are entirely in Chinese, indicating the skill is designed to operate in a single language by default. There is no visible opt-in, locale selection, or documentation that this is a region-specific tool, which can violate language/locale choice policy.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.