Back to skill

Security audit

全行业标书智能生成助手 | 商务标

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed cloud connector for tender and bid documents, with sensitive file upload and API-key use matching its stated purpose.

Install only if you are comfortable uploading tender/bid files to biaoshu.zhiliaobiaoxun.com and storing an API key locally for that service. Review the cloud retention, billing, and account knowledge-base behavior before using it with confidential business documents.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
This is a mismatch because the declared description focuses on four end-user document workflows: tender interpretation, bid document generation, compliance review, and duplicate checking. The code does implement those, but it also exposes additional substantial capabilities not represented in the description, especially credential storage/management, account balance lookup, knowledge-base access, and generic job-management/report-generation tooling. These are more than minor implementation details because they are explicit user-facing commands and external service interactions beyond the declared purpose.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The entire skill reference is written as mandatory Chinese-language guidance, with no indication that users may choose another language or that the skill is region-specific. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy violation.

Static analysis

No suspicious patterns detected.