Back to skill

Security audit

元典法条与案例检索

Security checks across malware telemetry and agentic risk

Overview

This legal research skill is largely disclosed and purpose-related, but it asks for overly broad Codex execution authority and stores sensitive legal and business research locally by default.

Install only if you are comfortable sending legal queries, case facts, company identifiers, and hallucination-check text to YuanDian/open.chineselaw.com and keeping local archives of results. Prefer balanced or economical mode, avoid the documented danger-full-access/no-approval Codex setup unless you have isolated the workspace, use --no-cwd-report or --no-report for confidential matters, keep scripts/.env out of shared folders and version control, and treat enterprise profiling as a separately authorized due-diligence action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tainted flow: 'record' from pathlib.Path.read_text (line 1114, file read) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Content
"ingest": True,  # 标记:从 MCP / 外部源消费,非直接 API
    }
    json_path.parent.mkdir(parents=True, exist_ok=True)
    json_path.write_text(json.dumps(record, ensure_ascii=False, indent=2), "utf-8")

    # 4. 走 _archive_write_report 生成 .md(archive + CWD)
    archive_md, cwd_md = _archive_write_report(
Confidence
83% confidence
Finding
json_path.write_text(json.dumps(record, ensure_ascii=False, indent=2), "utf-8")

Tainted flow: 'md_content' from pathlib.Path.read_text (line 2064, file read) → pathlib.Path.write_text (file write)

Medium
Category
Data Flow
Content
if args.output:
        output_path = Path(args.output)
        output_path.parent.mkdir(parents=True, exist_ok=True)
        output_path.write_text(md_content, "utf-8")
    else:
        cwd_copy = cwd / report_filename
        cwd_copy.write_text(md_content, "utf-8")
Confidence
71% confidence
Finding
output_path.write_text(md_content, "utf-8")

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The declared description says the skill is for law/article/case retrieval, but the document also exposes broad enterprise investigation, hallucination-detection submission, raw endpoint debugging, local archival, and report-generation behavior. This mismatch can mislead users and higher-level agents into authorizing data flows or investigative functions they would not expect, increasing the risk of over-collection and unintended disclosure of sensitive legal or corporate data.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill expands from legal/case retrieval into enterprise-search and company-background functions, including due-diligence style queries. In legal practice this can involve sensitive personal or commercial intelligence, and the broader scope is not obvious from the top-level description, creating a risk of unauthorized or disproportionate data gathering.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The '企业全息画像' section advertises full-profile aggregation and many risk dimensions, which materially exceeds ordinary law/case lookup. In context, this increases privacy and surveillance concerns because a user may invoke what appears to be a legal-research tool to build a broad dossier on a company without realizing the expanded scope.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The endpoint inventory includes numerous surveillance-style enterprise interfaces such as litigation, enforcement, tax, penalties, and serious-illegal records. Even if individually lawful, packaging them inside a skill presented as legal research materially broadens collection power and can facilitate bulk profiling or misuse of sensitive corporate and associated-person data.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest advertises capabilities beyond the stated skill purpose by including enterprise-information and hallucination-detection categories in addition to legal text and case retrieval. This broadens the effective data-access surface and can enable collection or use of unrelated data without clear user expectation, increasing the risk of scope creep and misuse.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The large set of enterprise-information endpoints materially exceeds a skill described as law/article and case retrieval. Even if legitimate APIs, undocumented expansion of accessible data domains can lead to over-collection, unexpected profiling, and use of corporate/legal intelligence features outside the user's intended request.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
A hallucination-detection endpoint is outside the narrow retrieval purpose described for the skill and introduces an additional processing capability not disclosed in the skill summary. While lower risk than the enterprise endpoints, hidden auxiliary analysis functions can alter data flows and send user content to services the user did not expect.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The workflow states that every actual retrieval may automatically write Markdown reports both to an internal archive path and the current working directory. This creates filesystem side effects outside the core search function, which can leak sensitive legal queries, case facts, paths, and citations into locations the user did not explicitly approve, increasing the risk of inadvertent disclosure or persistence of confidential matter data.

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The document gives conflicting guidance about where the consolidated report should be written: earlier sections describe consolidate writing to both CWD and archive, while the later mandatory workflow says the AI should manually write only the final report to the user’s target directory and keep intermediate artifacts internal. This ambiguity can cause an agent to place files in unintended locations, potentially exposing internal working data or polluting user case folders with files that were meant to remain in the skill workspace.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The file documents enterprise profiling, litigation, enforcement, tax, and other business-risk retrieval capabilities that go beyond the declared skill scope of legal/regulatory text and case search. This kind of scope drift is dangerous because downstream agents may invoke broader corporate-intelligence functions without users or platform controls expecting access to sensitive business-risk data, increasing the chance of unauthorized profiling or policy bypass.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The skill metadata says it is for legal/statute/case retrieval, but the code also exposes broad enterprise intelligence and risk-data lookup features. This capability mismatch is dangerous in agent environments because callers may invoke the skill expecting narrow legal research behavior while it can collect and export substantially more sensitive corporate data than disclosed.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The consolidate functionality performs bulk movement, copying, and rewriting of local files in the working directory and archive tree, which exceeds what is strictly necessary for legal lookup. In an agent context, this broad local file-management capability increases the blast radius of misuse, can rearrange user artifacts unexpectedly, and may help persist or spread untrusted content across directories.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The endpoint accepts arbitrary text for hallucination detection, and in a legal-search context that text may contain sensitive case facts, personal data, privileged communications, or internal legal analysis. The documentation does not warn users that this content is transmitted to an external service, creating a real privacy and confidentiality risk through uninformed disclosure rather than a direct code exploit.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The aggressive strategy explicitly authorizes automatic expansion and multi-stage retrieval while also stating '不限制' on point consumption, which can trigger extra paid searches without meaningful user confirmation. In a metered legal-research skill, this creates a real risk of unintended credit depletion and loss of user control, especially because the workflow earlier encourages repeated searches.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The document describes automatic disk writes, including a copy in the user's working directory, without a clear user-facing warning before the side effect occurs. In a legal-research context, query terms and generated reports may contain privileged or confidential case information, so silent persistence to disk can expose sensitive data to other tools, sync services, collaborators, or later misuse.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The workflow instructs the AI to clean up per-call working copies after report generation, but it does not require explicit user consent, confirmation of the deletion scope, or a safe-delete mechanism. In an agentic environment, ambiguous cleanup instructions can lead to unintended removal of files from the working directory, causing data loss or making it harder to audit how the final legal report was produced.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The tool automatically archives queries and full API responses locally, including potentially sensitive legal research terms, case identifiers, enterprise identifiers, and returned records, without prominent consent. This creates a privacy and data-retention risk because confidential research activity is silently persisted on disk and can later be discovered, copied, or consolidated.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The script sends user-supplied legal text, case numbers, company identifiers, and related research inputs to an external service without a clear privacy/data-sharing disclosure at the point of use. In legal workflows, these inputs may be confidential, so silent transmission to a third party can violate user expectations or policy restrictions.

Missing User Warnings

Low
Confidence
88% confidence
Finding
Generated reports are copied into the caller's working directory by default, which can unexpectedly create local artifacts containing sensitive legal research and retrieved data. While lower severity than network disclosure, it still increases accidental exposure through synced folders, source-control commits, or shared workspaces.

Credential Access

High
Category
Privilege Escalation
Content
2. 创建 API Key:登录后在个人中心创建 Key
3. 配置密钥:将 Key 填入以下文件

   scripts/.env
   ─────────────
   YD_API_KEY=sk-你的密钥(此处替换为真实 Key)
   # YD_STRATEGY=balanced
Confidence
86% confidence
Finding
.env

Credential Access

High
Category
Privilege Escalation
Content
echo "API Key 未配置"
  fi
else
  echo ".env 文件不存在"
fi

# 读取检索策略
Confidence
84% confidence
Finding
.env

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/validate-query-filters.py:56

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:65