Back to skill

Security audit

案件评估报告(得理科技)

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it needs review because its legal search scripts can send sensitive queries and API keys to a third-party service without server identity checks.

Review before installing. Do not use this with confidential or privileged matter details until TLS verification is fixed, and redact names, identifiers, account data, trade secrets, and unnecessary facts before any external search. Configure a real API key carefully, rotate it if previously used on untrusted networks, and verify all legal results against official sources.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search_cases.py:92
Finding

TLS Certificate and Hostname Verification Disabled in External API Clients

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
config.json:1
Finding

Shipped API-Key Placeholder Bypasses Placeholder Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:111
Finding

External Legal Search Can Transmit Identifying or Confidential Case Material Without Mandatory Redaction

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个较完整的案件接案评估能力,核心产出应是结构化案件初评报告,并包含多项分析与预测功能。实际代码的主功能非常单一:接收关键词或长文本,调用外部案例检索 API,返回裁判文书列表并格式化展示。虽然声明中提到“司法裁判检索”,这与代码有部分重合,但这只是声明能力中的一个子环节,且代码没有实现其余关键分析能力。因此主目的和实际行为存在实质性不一致,应判定为 mismatch。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个综合性的接案评估/案件初评工具,核心能力应包括案件材料分析、风险识别、裁判检索以及结果预测和成本测算。而代码仅实现了“法律法规检索”这一单一功能,且检索对象是法规而非案件、证据或司法裁判。代码中没有任何关于案件信息输入建模、报告生成、评估逻辑、概率/周期/成本计算、争议焦点提炼或补证建议的实现。虽然法规检索可作为案件评估的辅助环节,但当前代码的主要目的与声明的主要用途存在明显且实质性的偏差,因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly disables hostname verification and certificate validation before sending an authenticated HTTPS request with a bearer API key. This enables man-in-the-middle interception and tampering, allowing an attacker on the network path to steal the API key, read sensitive legal queries, or modify returned case results.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code explicitly disables both certificate validation and hostname verification before sending an authenticated HTTPS request with a Bearer API key. This enables man-in-the-middle interception or response tampering, allowing an attacker on the network path to steal credentials, alter legal search results, or inject misleading regulatory content into downstream case assessments.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

By disabling TLS verification without any warning, the script silently weakens transport security for all users and conceals the risk that API traffic may be intercepted or modified. In a legal-intake context, this is especially sensitive because search terms may reveal confidential dispute facts and poisoned responses could skew legal analysis or case acceptance decisions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill instructs use of local files (config.json, reference docs) and external API-backed scripts, but it declares no explicit tool scope or permission boundaries. Without clear permissions/allowed-tools, an agent runtime may grant broader-than-necessary file and network access, increasing the chance of unintended data exposure or misuse during handling of sensitive legal matter inputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is designed to process highly sensitive legal case facts, evidence, identities, and strategy information, and it may transmit search content to an external legal API. Without an explicit privacy/confidentiality warning, data-minimization guidance, or consent step, users may disclose privileged or personal information that is then unnecessarily shared outside the local session.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file title and instructions are entirely written in Chinese and prescribe a fixed response format for legal assessment outputs, but they do not indicate that language selection is optional. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction explicitly requires the output to use Chinese ("使用正式、清晰、可供律师复核的中文"). Under the policy, forcing a specific language is a natural-language locale violation unless the skill offers a language choice or clearly documents a justified regional constraint; this file does not provide either within the template.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The document title and all operational guidance are presented exclusively in Chinese, which effectively constrains use of the skill to a specific language/locale. The file does not indicate that the user may choose another language or that the Chinese-only constraint is an explicit, justified regional requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and command-line help text are written in Chinese only, which imposes a specific language on users without any opt-in or explanation of a region-specific requirement. This is a natural-language policy issue because the skill does not present an explicit language/locale choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The docstring, CLI help text, and user-facing output are presented exclusively in Chinese, with no indication that users can select another language or that the skill is intentionally limited to a Chinese-speaking context. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a skill for generating a案件初步评估报告 based on case facts, evidence, claims, jurisdiction, and related risk/cost/probability analysis. This script instead implements a generic法规检索 client that sends user queries to a third-party legal platform and formats search results, which is a materially distinct end-user capability rather than merely internal report-generation logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description is written to generate reports specifically for '中国大陆' dispute-resolution scenarios, and the skill content consistently mandates that role and output context. While the legal scope is justified, the file provides no explicit user choice on output language/locale, creating a potential locale-policy issue if broader language flexibility is expected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The formatter docstring and comments describe the API result as using a standard nested body/data structure, with compatibility for an older top-level data format. However, search_cases returns json.loads of the raw HTTP response directly, while error paths return a synthetic object with body as a string, so the documented structure does not consistently match actual function inputs and behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/search_cases.py:104

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/search_laws.py:107