Back to skill

Security audit

薪酬社保与人力技能包(免费版)

Security checks for vulnerabilities and agentic risk

Overview

This is a local payroll and HR checking skill that reads user-provided payroll text and reports issues without network use or persistence, but its results should not be treated as a complete audit.

Use this only with payroll/HR data you are comfortable processing locally through the agent. Review the not-run and sub_checks_not_run sections before relying on results, and do not treat a clean result as legal, tax, social-insurance, or audit assurance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (43)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The skill makes strong capability claims in SKILL.md—full 14-check payroll/HR validation, per-client conclusions, and file+line traceability—while the static findings indicate the packaged implementation only covers a narrow subset at a time. In a payroll/HR context, users may rely on the tool to approve salary, tax, social-insurance, or migrant-worker payments, so missing checks can cause silent under-review and false assurance rather than a mere documentation error.

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --sample # 单客户样例(内置)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --sample # 单客户样例(内置)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --sample # 单客户样例(内置)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
node scripts/run.mjs --sample # 单客户样例(内置)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The file explicitly states it is only a free subset and withholds parts of the advertised checking capability, while the skill metadata promises a much broader 14-item payroll/HR review. This creates a security-relevant integrity gap: users may rely on the tool for compliance or audit assurance that it does not actually provide, causing material payroll, tax, or social-insurance errors to go undetected.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The file-level documentation and all user-facing explanatory text are written only in Chinese, which imposes a locale/language constraint on users without indicating any choice or opt-in. Under the policy, language-specific behavior should either offer a choice or clearly document a justified region-specific constraint.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The file’s natural-language instructions, warnings, inputs, and outputs are all written exclusively in Chinese, and the code returns Chinese-only user-facing messages and disclaimers. There is no indication that users may choose another language or that the locale restriction is intentionally limited to a Chinese-only compliance context.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The disclaimer states the tool checks consistency between the wage table and special-account payout totals, but the code only computes `net_total` and `payout_total` and never compares them or emits a finding. In a payroll/compliance workflow, this can cause users to rely on a control that does not actually exist, allowing payout mismatches to pass unnoticed and undermining auditability.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This file contains extensive natural-language descriptions, contract text, and operational guidance only in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill’s header and contract are entirely written in Chinese, and the implementation returns user-facing advice/messages only in Chinese throughout the file. This creates a language/locale policy concern because the skill does not offer user opt-in or an alternative locale, and no region-specific justification is documented in the file.

Static analysis

No suspicious patterns detected.