Back to skill

Security audit

银行授信准入审查专家

Security checks for vulnerabilities and agentic risk

Overview

This bank-credit review skill is mostly coherent, but it needs Review because it handles high-impact lending judgments while using under-scoped persistence, external data calls, and some sensitive soft-risk factors.

Install only in a controlled banking or credit-review workspace. Confirm that external data connectors are approved for the customer data involved, require user approval before writing persistent rules or database updates, and avoid using family status, social reputation, social-circle, or regional-culture factors as decision variables unless your compliance policy explicitly permits and audits them.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
该代码与声明存在明显用途偏差。声明描述的是一个银行授信准入审查技能,核心应包括:基于企业资料执行红线快筛、形成结构化初审报告、做四维风险审查并给出准入结论。实际代码则是一个离线SQLite命令行工具,围绕“行业基准”展开:接收已获取的MCP JSON、入库、计算行业分位数、做企业对行业的相对位置比较,并输出查询结果和库更新报告。虽然 compare 子命令会生成一定的分析性文本,且内容与授信审查场景有关,但它本质上只是‘行业对标辅助模块’,并未覆盖声明中的关键功能,尤其缺少连续三年亏损/高负债/净资产为负的一票否决判定、外部风险/管理层股权等维度整合、最终准入结论与尽调清单。因此这不是轻微实现细节差异,而是主能力范围显著缩窄且重心转向基础数据基准工具,构成描述与行为不匹配。

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
该代码块的实际职责较窄,聚焦于授信审查中的两个子分析:流动资金贷款额度合理性测算和刚性负债偿债安全性分析。虽然这些内容可作为授信审查的辅助组成部分,与银行风险场景相关,但它并没有实现声明中最核心的能力:三条一票否决红线快筛、完整准入初审框架、多维非财务风险审查、外部权威数据拉取,以及最终准入结论与尽调建议的完整输出。因此这不是“描述略宽于实现”的轻微偏差,而是主功能层面的明显不一致。

Ae1

High
Category
analysis-evasion
Content
基准库文件:`data/industry_benchmark.db`(当前已覆盖房地产业 / 软件和信息技术服务业 / 批发业 2025 年报,共 120 家上市公司)。首次使用或扩充样本后,按"Agent 调 MCP 取数 → 保存原始 JSON → `ingest` 入库 → `compute` 重算"流程更新;`
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基准库文件:`data/industry_benchmark.db`(当前已覆盖房地产业 / 软件和信息技术服务业 / 批发业 2025 年报,共 120 家上市公司)。首次使用或扩充样本后,按"Agent 调 MCP 取数 → 保存原始 JSON → `ingest` 入库 → `compute` 重算"流程更新;`
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
基准库文件:`data/industry_benchmark.db`(当前已覆盖房地产业 / 软件和信息技术服务业 / 批发业 2025 年报,共 120 家上市公司)。首次使用或扩充样本后,按"Agent 调 MCP 取数 → 保存原始 JSON → `ingest` 入库 → `compute` 重算"流程更新;`
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Natural-Language Policy Violations

High
Confidence
98% confidence
Finding
The text explicitly recommends incorporating地域信用文化、区域风险、地方风气等地域性因素 into lending judgments, and elsewhere even cites examples like regional credit culture and localized risk scoring. In a bank credit admission skill, this can operationalize proxy discrimination against applicants based on region or locality rather than individualized, lawful creditworthiness factors, creating serious fair-lending, compliance, and reputational risk.

Natural-Language Policy Violations

High
Confidence
99% confidence
Finding
The material endorses use of sensitive social and relational attributes such as household structure, spouse attitude, social reputation, social circle quality, local residence duration, and access to friends-and-family support in credit assessment. In an underwriting skill, these attributes can function as proxies for protected characteristics or socio-economic exclusion, leading to discriminatory decisions that are hard to justify under fair lending, privacy, and data minimization principles.

Lp3

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding
The skill explicitly instructs the agent to read and update multiple local files (`references/*.md`, `data/industry_benchmark.db`) and to generate reports, but it does not declare any `permissions` or `allowed-tools` scope. This creates an implicit file read/write capability boundary that is not transparently constrained, increasing the risk of over-broad workspace access, unintended file modification, or rule/checklist poisoning if the runtime grants default file access.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list is extremely broad and semantically overlapping, covering generic banking, credit, approval, and negative-list terminology. In a sensitive financial workspace, this can cause accidental activation on ordinary discussions, leading the agent to read local reference files, produce compliance-like conclusions, or write persistent rule/checklist artifacts when the user did not intend to invoke this skill.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The document is written entirely in Chinese and directs the Agent to produce report sections in that language and format, but it does not indicate that language selection is optional or constrained by a documented regional requirement. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The entire skill document is written as a mandatory Chinese-language operating guide, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

External Transmission

Medium
Category
Data Exfiltration
Content
**调用模板**:
```bash
curl -s -X POST https://www.codebuddy.cn/v2/tool/financedata \
  -H "Content-Type: application/json" \
  -d '{"api_name":"daily_basic","params":{"ts_code":"000001.SZ","trade_date":"20260810"},"fields":""}'
```
Confidence
89% confidence
Finding
The skill explicitly instructs use of an external endpoint (`codebuddy.cn`) for financial data retrieval, which can transmit user-supplied query parameters and potentially sensitive customer identifiers or due-diligence context outside the primary workspace. In a bank credit review setting, this is more dangerous because inputs may contain confidential enterprise information, and the document does not require data minimization, consent, classification checks, or approved-vendor/privacy controls before external transmission.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The entire skill documentation is written in Chinese and all user-facing examples, required report phrasing, and operational guidance assume Chinese output and terminology. There is no indication that language choice is optional or that the locale restriction is intentional and documented as a region-specific requirement.

Natural-Language Policy Violations

Medium
Confidence
97% confidence
Finding
The entire skill file is written as mandatory operational guidance in Chinese and does not state that language selection is optional or limited to a China-specific deployment context. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The title and instruction text specify a fixed Chinese-language reporting template, including wording that implies every review output must include this format. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The document title and all operative instructions are written exclusively in Chinese, with no indication that language selection is optional. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale violation unless clearly justified as region-specific.

Natural-Language Policy Violations

Medium
Confidence
98% confidence
Finding
The file title is entirely in Chinese ("规则库 / 检查清单沉淀") and the operational instructions throughout the document are written only in Chinese, which effectively constrains the skill's usage and outputs to a specific language/locale. There is no indication that users may choose another language or opt in to this locale constraint.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
This markdown file is entirely in Chinese and does not state that the skill is intended only for Chinese-speaking users or provide any language/locale choice. Under the policy rule, forcing a specific language without opt-in can be a natural-language policy violation unless the locale constraint is documented and justified.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
The file title and all substantive guidance are written exclusively in Chinese, with no indication that users may choose another language or locale. Under the stated policy, a skill that imposes a specific language without user opt-in can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
This markdown file is entirely written as operational guidance in Chinese and does not indicate any user choice, opt-in, or locale limitation. Under the language/locale policy rule, natural-language instructions that effectively require a specific language without documented opt-in can be considered a policy violation.

Natural-Language Policy Violations

Low
Confidence
84% confidence
Finding
This markdown file contains user-facing instructions exclusively in Chinese and does not provide any opt-in, alternative locale, or justification for a language restriction. Under the stated policy, forcing a specific language without user choice can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The file content is entirely Chinese and provides no indication that language choice is optional or user-selected. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Missing User Warnings

Low
Confidence
86% confidence
Finding
The template explicitly states that the report is based on user-provided and authorized data sources, but it does not instruct the operator or downstream agent to handle enterprise financial, credit, litigation, and ownership data as confidential or to minimize sensitive data exposure. In a bank credit review context, this omission can lead to accidental over-collection, excessive retention, or inclusion of sensitive client information in generated reports or logs, increasing privacy, confidentiality, and compliance risk.

Natural-Language Policy Violations

Low
Confidence
89% confidence
Finding
This markdown file presents all instructions and policy content exclusively in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. That can conflict with language/locale policy expectations requiring user opt-in or explicit justification for a fixed language.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The title and the entire document content are presented only in Chinese, with no indication that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Static analysis

No suspicious patterns detected.