Back to skill

Security audit

Cnsdoce Publish V5

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a construction-costing purpose, but it needs Review because it can send sensitive project text and API credentials to configurable third-party endpoints and can mutate local pricing/history databases without strong guardrails.

Install only if you are comfortable with third-party LLM processing of construction/project descriptions. Before use, restrict HUNYUAN_URL to trusted HTTPS provider hosts, avoid putting confidential bid or supplier data into LLM-backed flows unless approved, back up any local quota/history databases, and review dependencies or pin them in your own environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/llm_semantic_match.py:39
Finding

Unrestricted LLM Endpoint Override Exposes API Credentials and User Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ai_quota_engine.py:617
Finding

AI Quota Parser Sends API Key and Bill-Item Data to an Unvalidated Endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/requirements.txt:2
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Future Releases

Content
View full analysis
=1.5.0 openpyxl>=3.0.0 sentence-transformers>=2.2.0 chromadb>=0.4.0 faiss-cpu>=1.7.0 volcengine-python-sdk>=0.1.0 requests>=2.28.0 ``` ### Technical Analysis Every dependency is specified with only a minimum version. There are no: - Exact version pins - Upper version bounds - Package hashes - Lock files - Documented trusted package-index restrictions As a result, two users installing the same Skill at different times may receive materially different dependency versions. Future releases have not been covered by this audit and may introduce vulnerabilities, incompatible behavior, unexpected network access, or compromised package code. This is not evidence that any currently named package is malicious. The risk arises from allowing package resolution to select arbitrary future releases. The project does not automatically invoke a package installer, which reduces immediacy but does not remove the risk when a user installs the requirements. ### Attack Path 1. A user or deployment process runs `pip install -r scripts/requirements.txt`. 2. The resolver queries its configured package index and selects the newest versions satisfying the lower bounds. 3. A future compromised, vulnerable, or incompatible release satisfies those constraints. 4. The package is installed into the Skill's Python environment. 5. Package code executes during installation, import, model initialization, or normal Skill use. 6. The package obtains the permissions of the Python process. A related organizational attack path exists if an attacker can influence the configured package index or mirror. Without hashes or index restrictions, the resolver may accept an unexpected distribution that satisfies the package name and version constraint. ### Impact Assessment ...[truncated 642 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (51)

Direct flow: os.environ.get (credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The code sends user-provided list descriptions to an external endpoint and includes a bearer token from an environment variable in the request headers. Although the API key itself is not exfiltrated to the model payload, this still creates a real data egress path for potentially sensitive project or procurement data and trusts a runtime-configurable URL, which could redirect requests to an unintended host.

Content

Scanner excerpt · scripts/ai_quota_engine.py (reported line 631)May include surrounding context.

python
"特征": "碳钢、法兰连接"
}}
清单描述:{text}"""
            resp = requests.post(
                os.environ.get("HUNYUAN_URL", "https://tokenhub.tencentmaas.com/v1/chat/completions"),
                headers={"Authorization": f"Bearer {api_key}", "Content-Type": "application/json"},
                json={"model": os.environ.get("HUNYUAN_MODEL", "hy3-preview"),

Tainted flow: 'payload' from os.getenv (line 146, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/llm_semantic_match.py (reported line 158)May include surrounding context.

python
"Content-Type": "application/json",
            "Authorization": f"Bearer {api_key}"
        }
        response = requests.post(url, headers=headers, json=payload, timeout=30)
        result = response.json()

        if "choices" in result and len(result["choices"]) > 0:

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

代码的主功能是一个 LLM 辅助的定额语义匹配脚本,而不是完整的工程造价技能实现。它通过外部 API 将用户的“工作内容”发送给腾讯混元或豆包,要求模型判断所属安装分册、提取搜索关键词、设备类型和参数;随后用本地搜索器搜索/验证真实定额结果。这与声明中的一小部分“定额子目查询”相关,但与更核心、更宽泛的宣称能力存在明显落差:声明覆盖安装/建筑/市政/园林多专业、组价计算、取费计算、报价表生成、山东/济南价目表查询、唯一来源模式等,而本代码均未体现。尤其是代码的专业知识硬编码仅为“安装工程13分册”,与声明的多专业范围不符;并且实际资源访问包括外部 LLM 服务,声明虽提到“默认模式:大模型推理数据”,但该代码是明确的网络 API 依赖实现,而非本地数据库/费率标准主导。综合来看,描述与该代码块的实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The description presents a full-featured engineering costing skill with multiple engineering domains, fee standards, quotation generation, and configurable data-source modes. The supplied code chunk, however, is a narrower search component: a local JSON-backed matcher for installation-engineering quota items. It does accurately align with part of the declared purpose—installation quota lookup for the 2025 13-volume standard and Jinan-derived data—but it does not implement many of the prominent declared capabilities. The code's primary behavior is retrieval/matching, not full costing, fee computation, or document generation. It also uses different concrete resources than advertised and exposes extra behavior (BIM matching helper, CLI interaction) not mentioned in the description. Therefore the description materially overstates and partly misstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk does not implement the core end-user capabilities promised in the description, such as定额查询交互逻辑, 组价计算, 取费计算, Excel报价表生成, or enforcement of the claimed '唯一来源模式' and unit-checking workflow. Instead, it is an internal maintenance/build script whose primary purpose is to migrate two local JSON files into a SQLite database, create indexes/full-text search structures, and benchmark query speed. While this could support the broader skill, the chunk itself is materially different in primary purpose and includes undeclared capabilities around database creation, schema management, and performance testing. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

从代码看,主用途是“定额/材料检索”,而不是完整的“工程造价组价与报价生成”技能。其实现包括:定额名称/章节 LIKE 搜索、多关键词搜索、编号精确查找、分册筛选、材料价格查询、DN 映射口径查询、以及多后端降级(SQLite、FAISS、Chroma、文本倒排)。这些与声明中的“定额查询、山东/济南价目表查询”部分一致,但声明列出的多项核心能力在该代码块中没有体现,尤其是组价、取费、Excel 报价表生成、单位校验、价格自检、指标引擎等。因此,描述相对代码行为明显夸大且主能力范围更广,构成描述与实际行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares environment-variable use, local file/database access, and external LLM/network behavior, but it does not define an explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity where the runtime may permit broader access than users expect, especially given the documented use of API keys, local databases, and Excel file generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs network-based LLM use and Excel file generation without clearly disclosing that user inputs may be transmitted to third-party providers or that files will be written locally. This creates a material consent and data-handling risk, especially in a cost-estimation context where project names, quantities, and commercial pricing data may be sensitive.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Elsewhere the file repeatedly states Step 0 must run before Step 1, but L490 says unit comparison is executed '在 Step 1 定额查询之后、Step 2 组价计算之前'. This is an active contradiction in the operational instructions, not merely an omission, and it can change how the skill is implemented or used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad enough to activate the skill for common requests, increasing the chance of unintended invocation. In a skill that may read files, use environment-backed API keys, perform network calls, and generate local output, overbroad activation can cause unnecessary data exposure or undesired side effects from ordinary conversation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, and there is no natural-language indication that the user may choose another language or that Chinese is optional. Under the policy, forcing a specific language without user opt-in is a locale/language policy concern unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file instructs the LLM to answer user queries by following a fixed reply logic written entirely in Chinese for a general query about how to calculate '其他项目费'. There is no indication that the user can choose another language, nor a clear justification that the skill is restricted to Chinese-only interactions as a locale-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file is entirely written as a Chinese-language reference and does not provide any indication that users may request another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script transmits raw user input to a third-party LLM service without any explicit user-facing notice or consent mechanism at the point of use. In this skill's context, inputs may contain confidential bill-of-quantities, supplier, pricing, or project details, so silent transmission increases privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code opens the SQLite database in write mode and inserts project-derived indicator records, permanently modifying local data. Although there is a success print after the write, there is no prior warning, confirmation, or explicit disclosure in the command flow that running this path will store data into project_history.db.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The dynamic_adjust path performs an UPDATE against the indicators table, changing the stored info_price for an existing record. The function returns data after the fact, but there is no advance warning or confirmation that the adjust command mutates persistent state rather than only calculating a temporary adjusted value.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This code performs external transmission of prompt contents to remote APIs. In a cost-estimation and quotation skill, that data can include commercially sensitive project details, so the network call is security-relevant even if functionally intended.

Content

Scanner excerpt · scripts/llm_semantic_match.py (reported line 158)May include surrounding context.

python
"Content-Type": "application/json",
            "Authorization": f"Bearer {api_key}"
        }
        response = requests.post(url, headers=headers, json=payload, timeout=30)
        result = response.json()

        if "choices" in result and len(result["choices"]) > 0:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script transmits user-supplied construction/project text to third-party LLM services without any consent flow, warning, redaction, or policy gate. In this skill context, user prompts may contain sensitive commercial data such as project scope, pricing assumptions, supplier details, or bid information, making silent exfiltration materially risky.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The function documentation says it generates a temporary bearer token using Tencent Cloud signature v3, but the implementation merely concatenates SecretId and SecretKey. This can cause operators to misuse long-lived cloud credentials as if they were safe temporary tokens, increasing the chance of credential exposure to logs, downstream HTTP auth headers, or incompatible endpoints.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring specifies the skill entirely in Chinese and ties it to Chinese regional standards and source material, with no indication that users can choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script unconditionally deletes the existing quota.db before recreating it, which can cause irreversible local data loss if the database contains important or manually modified data. While this is not a code execution issue, it is a real destructive behavior and becomes more risky because the skill manages reference/pricing data that users may expect to preserve.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 16)May include surrounding context.

text
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The description presents the skill as a Chinese engineering-costing skill and the entire instruction set, triggers, and examples are Chinese-only, with no indication that users may choose another language. This can violate a language-choice policy when a skill implicitly forces a locale without opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifested purpose is to query quotas, calculate pricing, and generate quotation sheets. Embedding a direct 'contact the author' distribution path for a proprietary database adds an out-of-band acquisition capability that is not needed to execute the skill itself and is not part of the stated functional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written in Chinese and scoped to a specific Chinese provincial standard, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/llm_semantic_match.py:360