Back to skill

Security audit

诉讼策略与类案检索(得理科技)

Security checks for vulnerabilities and agentic risk

Overview

The skill’s legal-research purpose is coherent, but its scripts disable TLS verification while sending an API key and potentially sensitive case details to an external legal API.

Review before installing. Use this only if you are comfortable sending legal search terms to DeliLegal, and redact personal or privileged facts. The TLS verification bypass should be fixed before real use, and the API key should preferably be stored in an environment variable or secret store rather than a project-local config file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/search_cases.py:104
Finding

TLS Certificate and Hostname Verification Disabled

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
config.json:1
Finding

API Key Stored in a Plaintext Project-Local Configuration File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

声明描述的是一个较完整的诉讼分析与报告生成型技能,包含案件分析、争议焦点拆解、诉讼策略制定、法条与类案检索等复合能力。但提供的代码只调用单一案例检索 API,返回案例列表并做展示格式化。虽然其中“类案检索”这一子能力与声明部分重合,但代码未体现声明中的核心主功能——自动生成诉讼策略与类案检索报告,也未实现法条检索或庭前准备分析。因此描述明显高于实际行为,属于实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个较高层的诉讼分析/策略/类案检索技能,核心应包括基于案情进行争议焦点分析、制定诉讼策略,并结合类案与法条形成报告。但代码仅实现了“法规检索”这一子能力:向法律开放平台发送查询、获取法规列表并格式化展示。虽然声明中提到法条检索,代码确实覆盖该部分,但没有任何案件事实解析、争议焦点提炼、诉讼策略生成、类案检索或报告编排逻辑。因此代码行为只覆盖声明中的一小部分,且与其宣称的主要用途存在实质性偏差,属于描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script explicitly disables TLS certificate validation and hostname verification before sending the API key and user-supplied legal case queries. This enables man-in-the-middle interception or tampering of traffic, exposing credentials and potentially sensitive case facts; in a litigation-analysis skill, the transmitted content may include confidential or highly sensitive legal information, which increases the severity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script explicitly disables TLS hostname verification and certificate validation before sending both the legal query and the Bearer API token. This allows a man-in-the-middle attacker with network position or a malicious proxy/root CA environment to intercept or tamper with requests and responses, potentially stealing the API key and altering legal research results.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill documents use of file reads and outbound network access to load an API key from config.json and send queries to an external legal API, but it does not declare any explicit tool scope or allowed-tools policy. This weakens least-privilege controls and makes it harder for a host system to constrain or review what resources the skill may access, especially because case facts may contain sensitive personal or litigation information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown explicitly says to use the skill when the user mentions phrases like "案件分析", "诉讼策略", "类案检索", "法条检索", or "庭前准备", and also lists broad examples such as "打官司方案" and "胜诉率评估". These are common legal-assistance requests rather than narrowly scoped invocation commands, and the file does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs sending search queries and potentially long-form case material to an external legal API, but it does not provide a user-facing notice or consent step about transmitting potentially sensitive case facts. In the litigation context, those facts may include personal data, privileged strategy, or confidential dispute details, so silent transmission creates a meaningful privacy and confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guidance includes example case-search queries containing identifiable personal names and a full case number, but it provides no caution about minimizing, anonymizing, or lawfully handling personal and case-identifying data. In a litigation-analysis skill, users are likely to paste real pleadings, party names, IDs, contact details, and case numbers into search commands; normalizing that behavior without privacy guardrails increases the risk of unnecessary disclosure to downstream tools, logs, and third-party data sources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's docstring, CLI descriptions, help text, and output messages are written exclusively in Chinese, which imposes a specific language on users without presenting an opt-in or alternative locale. The policy specifically calls out forced language or locale behavior as a natural-language violation unless choice or clear justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code loads an API key from local configuration and sends the user's query content to a third-party legal platform over HTTP(S), but the CLI flow provides no user-facing notice that their input and credentials will be transmitted externally. For a code file, network transmission of user or system data should have some visible disclosure such as a prompt, print/log message, or explicit warning in the interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

All user-facing documentation and output strings in this file are written exclusively in Chinese, which effectively imposes a language/locale choice on users without opt-in. The policy allows locale constraints only when clearly documented and justified, or when users are given a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code performs a POST request to an external legal platform and transmits the user's search query together with an API bearer token, but there is no print/log message, confirmation prompt, or explicit warning near execution that user-entered queries are sent to a third-party service. For a code file, outbound network transmission of user data should have some visible disclosure unless the warning is otherwise provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script reads an API key from config.json and uses it for authenticated requests, but there is no visible runtime disclosure that the skill accesses local credentials. Access to sensitive credentials in code files should include at least a comment, docstring, or user-facing note describing the behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.insecure_tls_verification

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/search_cases.py:105

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
scripts/search_laws.py:108