Back to skill

Security audit

房地产风险分析专家

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for real-estate data collection and risk analysis, but it includes operational anti-bot/WAF bypass guidance and persistent agent-behavior updates that need review before installation.

Install only if you intend to use it for authorized real-estate due-diligence work. Before use, remove or tightly gate the WAF/token-replay/CDP bypass playbooks, add explicit authorization and rate-limit requirements, re-enable TLS verification, and require confirmation before writing memory, updating skills, or changing automation prompts.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (60)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
声明描述的是一个覆盖采集、去化、货值、授信尽调等多个环节的完整房地产风险分析工作流;但给出的代码并没有执行这些分析或采集任务。它只是在本地定义一组33城的静态元数据,计算简单计数汇总,然后拼接HTML/JavaScript生成一个可视化对比大屏。虽然内容与“跨城房源备案价采集”主题相关,但范围远小于声明,且缺失声明中的核心能力(去化、穿透、失真核查、授信量化等)。因此该代码片段的实际行为与声明用途存在明显且实质性的不匹配。

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
该代码的主要用途与声明存在明显偏差。声明描述的是一个覆盖采集、去化、货值、授信尽调的“全链路”房地产风险分析技能,强调跨城市抓取、对抗WAF、去化率口径、开发商穿透、授信量化等复杂能力。但实际代码仅处理一个已有 Excel 文件,读取若干固定工作表并生成 HTML 可视化看板。它没有网络采集、没有城市级抓取逻辑、没有反爬/WAF处理、没有开发商主体穿透检索,也没有实现声明中的去化率与授信核心分析模型。虽然代码确实涉及房源备案数据、预售证、剩余货值、异常告警和外部价格对比等房地产分析的部分内容,但这些更多是对既有表格结果的展示与轻量统计,而不是声明所称的完整风险分析工作流。因此应判定为描述与实际行为不匹配。

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
The declared description presents a broad end-to-end real-estate risk analysis skill with multiple analytical modules and acquisition capabilities across many cities. The supplied code chunk does not implement that workflow. Instead, it performs a narrow ETL/reporting task: opening a local Shenzhen government PDF, extracting table rows for second-hand residential reference prices, doing deduplication and basic summary statistics, and exporting JSON/Excel. This is related to one small part of the declared domain—property/reference price data—but it lacks nearly all major claimed functions such as multi-city acquisition, scraping bypass techniques, sell-through analytics, developer ownership/project penetration, presale checks, and credit/valuation modeling. Therefore the description materially overstates and misrepresents the actual behavior of this code chunk.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
代码与描述存在明显能力范围不一致。代码本身聚焦于“按企业/品牌检索”的P3/P4环节:调用贵阳官方REST接口抓取预售证信息,或薄封装调用广州/深圳已有脚本,随后生成带来源标注的Excel,并做非常有限的证级校验与项目汇总。描述则宣称一个覆盖采集、去化、货值、授信、失真核查、授信尽调的全链路房地产风险分析系统。代码没有看到备案价抓取、去化率计算、库存/现金回笼分析、授信触发点测算、开发商穿透分析实现,也没有完整的风险评估逻辑。虽然描述中提到“查楼盘房源备案价、算去化率、排查房企在售项目与现金流、做房地产授信尽调”,但该代码只实现了官方预售证/项目信息采集与Excel整理,属于声明能力中的一个较窄子集,因此应判定为描述与实际行为不匹配。

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding
声明描述的是一个覆盖采集、分析、授信尽调的房地产风险分析全链路系统,核心能力应包括数据采集、业务指标计算、企业/项目穿透分析和授信测算。但提供的代码块只是一个独立的验证脚本,针对已给定的 houses/permits 数据做质量检查,不进行网络采集、不计算去化率、不做开发商检索、不做货值或授信分析。虽然数据质量校验可能是该大系统中的辅助环节,但当前代码的实际主要功能与声明的主要用途相差很大,因此构成明显描述-行为不匹配。

Ae1

High
Category
analysis-evasion
Content
;⑧ 新增 `scripts/price_integration.py` 外部价格整合与货值测算(D/E 类缺价城市闭环,--demo 自测通过);⑨ 修正 `scripts/by_developer.py` 广州适配器空跑 bug(`--search` 备案名优先 + `--search-dev` 兜底,新增 `--
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
;⑧ 新增 `scripts/price_integration.py` 外部价格整合与货值测算(D/E 类缺价城市闭环,--demo 自测通过);⑨ 修正 `scripts/by_developer.py` 广州适配器空跑 bug(`--search` 备案名优先 + `--search-dev` 兜底,新增 `--
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
;⑧ 新增 `scripts/price_integration.py` 外部价格整合与货值测算(D/E 类缺价城市闭环,--demo 自测通过);⑨ 修正 `scripts/by_developer.py` 广州适配器空跑 bug(`--search` 备案名优先 + `--search-dev` 兜底,新增 `--
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
by_developer.py` 脚本工厂(P3+P4 一键);④ 拆分 `references/`(类型库/瑞数专项/待办清单),主文档去重瘦身;⑤ 新增 `scripts/validate.py` 质量校验模块并接入工厂;⑥ 工厂增强(深圳注入 PERMITS 修复静默空跑、采集后自动 validate、新增 `-
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
by_developer.py` 脚本工厂(P3+P4 一键);④ 拆分 `references/`(类型库/瑞数专项/待办清单),主文档去重瘦身;⑤ 新增 `scripts/validate.py` 质量校验模块并接入工厂;⑥ 工厂增强(深圳注入 PERMITS 修复静默空跑、采集后自动 validate、新增 `-
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
by_developer.py` 脚本工厂(P3+P4 一键);④ 拆分 `references/`(类型库/瑞数专项/待办清单),主文档去重瘦身;⑤ 新增 `scripts/validate.py` 质量校验模块并接入工厂;⑥ 工厂增强(深圳注入 PERMITS 修复静默空跑、采集后自动 validate、新增 `-
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
`references/城市接入checklist.md` 填表式城市接入模板(六步:入口→反爬→API→字段→脚本→收口),探测 SOP 加索引;⑧ 新增 `scripts/price_integration.py` 外部价格整合与货值测算(D/E 类缺价城市闭环,--demo 自测通过);⑨ 修正 `scripts
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
`references/城市接入checklist.md` 填表式城市接入模板(六步:入口→反爬→API→字段→脚本→收口),探测 SOP 加索引;⑧ 新增 `scripts/price_integration.py` 外部价格整合与货值测算(D/E 类缺价城市闭环,--demo 自测通过);⑨ 修正 `scripts
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
HTML 看板(6 图表 + KPI + 质量校验 10 项 + 楼层梯度回归 + 6 决策模块 + 四筛选 + 排序分页),可离线/发给客户。通用生成器 `build_house_dashboard.py` 一条命令复用(自动探测表头/动态列映射/动态状态配色/兼容两种剩余货值结构)。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
HTML 看板(6 图表 + KPI + 质量校验 10 项 + 楼层梯度回归 + 6 决策模块 + 四筛选 + 排序分页),可离线/发给客户。通用生成器 `build_house_dashboard.py` 一条命令复用(自动探测表头/动态列映射/动态状态配色/兼容两种剩余货值结构)。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
HTML 看板(6 图表 + KPI + 质量校验 10 项 + 楼层梯度回归 + 6 决策模块 + 四筛选 + 排序分页),可离线/发给客户。通用生成器 `build_house_dashboard.py` 一条命令复用(自动探测表头/动态列映射/动态状态配色/兼容两种剩余货值结构)。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
> `references/real-estate-guide.md` 五-B;本节约方法论与"下次怎么继续"。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
> `references/real-estate-guide.md` 五-B;本节约方法论与"下次怎么继续"。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- `scripts/build_cross_dashboard.py`:**跨城对比大屏**(2026-08-11,少数综合场景用)——33 城覆盖能力综合展示,改 `CITIES` 数组即更新。
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The skill's stated purpose is real-estate risk analysis and filing-price/data collection, but this case asset teaches a specialized anti-bot evasion technique: harvesting a WAF-issued token and using it to call enumeration endpoints directly. That capability is not merely ordinary web collection detail; it is a reusable bypass pattern for defeating access controls, which is unjustified by the business-analytics purpose as stated.

Missing User Warnings

High
Confidence
97% confidence
Finding
The document explicitly promotes a method to continue automated data collection by using a headless-acquired token to directly call enumeration APIs after the SPA is challenged by WAF. Because this behavior can affect third-party systems, privacy, and system integrity, the markdown should include a clear warning about authorization, terms-of-use, and potential impact before presenting the workaround.

Ssd 4

High
Confidence
95% confidence
Finding
The text frames the method as a practical fallback, but its cumulative intent is to preserve unauthorized automated access after the platform's challenge flow blocks the normal SPA session. The sequence of obtaining a token from a challenged session and replaying it against enumeration endpoints is a gradual, operational bypass pattern rather than a neutral discussion of security concepts.

Ssd 2

High
Confidence
91% confidence
Finding
The wording presents the technique as a lightweight workaround, but semantically it describes using a token issued during a challenged session to access backend enumeration interfaces the normal client can no longer reach. This is a reformulated access-control evasion pattern that relies on meaning and operational context more than obvious attack keywords.

Ssd 4

High
Confidence
97% confidence
Finding
Individually, the steps look like troubleshooting and data collection, but together they form a concrete progression for defeating the challenged session path: launch headless, capture token from requests, then replay it across building and house-list endpoints. This is a classic gradual-deception pattern where the harmful endpoint access emerges from the full sequence rather than any single sentence.

Missing User Warnings

High
Confidence
94% confidence
Finding
This section gives concrete request patterns for repeatedly calling three external endpoints with a captured token, but does not warn the user about rate limiting, authorization, or the operational/legal risks of automated enumeration. For markdown files, omissions of warnings about behavior affecting privacy or system integrity should be flagged.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/by_developer.py:99