Back to skill

Security audit

成本与存货技能包(免费版)

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local cost and inventory checking tool that reads user-provided accounting files and prints results without evidence of network use, persistence, credential access, or hidden mutation.

Install only if you are comfortable letting the skill read the client cost/inventory directories you explicitly provide. Treat its output as a local arithmetic/reconciliation aid, not an audit opinion, and review all items marked未执行 or listed under checks_not_run/sub_checks_not_run before relying on a clean result.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The finding shows the advertised batch self-check suite is actually only an engineering-material transfer/usage reconciliation module without the promised multi-client or 14-check behavior. The danger is a trust and integrity issue: operators may accept incomplete review evidence as if it were a comprehensive pre-close control.

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --sample # 单客户样例(内置,14 项全跑)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --sample # 单客户样例(内置,14 项全跑)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --sample # 单客户样例(内置,14 项全跑)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --sample # 单客户样例(内置,14 项全跑)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The implementation materially diverges from the skill’s advertised purpose: it performs a single fixed-asset reconciliation routine rather than the manifest-described batch cost/inventory review across all customers. In an accounting/compliance workflow, this kind of scope mismatch can cause operators to rely on incomplete controls, falsely believing all required customer checks were executed when they were not.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill metadata promises a batch pre-close check across all customers with 14 checks and per-customer conclusions, but this file only implements a single inventory-table checker with 6 executed checks. In an accounting/compliance workflow, this mismatch can cause operators to rely on incomplete coverage, falsely believing all required checks were run, which may let material errors pass undetected.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The implementation materially diverges from the advertised skill purpose: instead of running batch cost/inventory checks across customers, it processes a single pasted production yield/scrap table. In an automation pipeline, this can cause users to rely on a 'successful' result while the promised financial/inventory controls were never performed, creating silent audit and decision-making failures.

Natural-Language Policy Violations

Medium
Confidence
93% confidence
Finding
This code file contains extensive natural-language instructions and usage constraints in Chinese only, including the skill purpose, limitations, and disclaimers. Under the stated policy, forcing a specific language without offering the user a language/locale choice can be a policy violation.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The code states that the free tier runs 6 checks and the full tier adds 5, which is inconsistent with the manifest’s promise of 14 checks per customer. This can mislead users into trusting a control set that is substantially smaller than expected, weakening financial review and increasing the chance that material discrepancies go undetected.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
Although the documentation says no conclusion should be given when materials are insufficient, several checks return null and the overall function still reports success, effectively skipping validations when certain fields are missing or unparsable. In a financial verification context, silent partial execution is dangerous because it can produce an apparently authoritative result despite incomplete evidence.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file’s natural-language instructions, user advice, and disclaimers are entirely in Chinese, and the skill expects Chinese column names and guidance text with no indication that users may choose another language or locale. This creates a language/locale policy concern because the skill effectively constrains interaction to Chinese without documenting opt-in or offering alternatives.

Static analysis

No suspicious patterns detected.