Back to skill

Security audit

保险计划书分析大师

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local insurance-analysis and report-export skill; the main caution is its local feedback/crash-log feature, not hidden data sending.

Install only if you are comfortable letting the skill run local Python scripts over sensitive insurance documents and write local reports. Review any feedback ZIP/.eml before sending it, use INS_FEEDBACK=0 if you do not want automatic local crash snapshots, and be aware the parser may try to install named Python parsing libraries if they are missing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (57)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill collects feedback, stores it locally, packages ZIP archives and .eml drafts, embeds an author email, and may open the system mail client. In the context of insurance documents, this creates a concrete exfiltration-adjacent path for sensitive metadata and user context, even if transmission still requires user action.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill collects feedback, stores it locally, packages ZIP archives and .eml drafts, embeds an author email, and may open the system mail client. In the context of insurance documents, this creates a concrete exfiltration-adjacent path for sensitive metadata and user context, even if transmission still requires user action.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill collects feedback, stores it locally, packages ZIP archives and .eml drafts, embeds an author email, and may open the system mail client. In the context of insurance documents, this creates a concrete exfiltration-adjacent path for sensitive metadata and user context, even if transmission still requires user action.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill collects feedback, stores it locally, packages ZIP archives and .eml drafts, embeds an author email, and may open the system mail client. In the context of insurance documents, this creates a concrete exfiltration-adjacent path for sensitive metadata and user context, even if transmission still requires user action.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill collects feedback, stores it locally, packages ZIP archives and .eml drafts, embeds an author email, and may open the system mail client. In the context of insurance documents, this creates a concrete exfiltration-adjacent path for sensitive metadata and user context, even if transmission still requires user action.

Content

No source excerpt is available for this finding.

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

os.system() and os exec-family calls run shell commands with the process's full privileges, enabling arbitrary command execution.

Content

Scanner excerpt · dist/保险计划书分析大师.zip!/保险计划书分析大师/scripts/extract.py (reported line 109)May include surrounding context.

python
# 3) 重执行带库 venv python(与 markitdown 同目录的 python.exe)
    py = _find_lib_python()
    if py and os.path.abspath(py) != os.path.abspath(sys.executable):
        os.execv(py, [py, os.path.abspath(__file__)] + sys.argv[1:])
    sys.stderr.write(
        "缺少解析库 openpyxl/python-docx/pdfplumber,且自动安装与带库解释器均不可用。\n"
        "请先运行:pip install openpyxl python-docx pdfplumber\n"

os.system() or os exec-family call

High
Category
Dangerous Code Execution
Confidence
91% confidence
Finding

The code re-executes a different Python interpreter discovered from the environment or PATH-adjacent locations, then forwards original arguments. If an attacker can influence those locations or replace the target interpreter, they can cause execution of untrusted code under the user's context.

Content

Scanner excerpt · scripts/extract.py (reported line 109)May include surrounding context.

python
# 3) 重执行带库 venv python(与 markitdown 同目录的 python.exe)
    py = _find_lib_python()
    if py and os.path.abspath(py) != os.path.abspath(sys.executable):
        os.execv(py, [py, os.path.abspath(__file__)] + sys.argv[1:])
    sys.stderr.write(
        "缺少解析库 openpyxl/python-docx/pdfplumber,且自动安装与带库解释器均不可用。\n"
        "请先运行:pip install openpyxl python-docx pdfplumber\n"

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documents broad execution capabilities including shell execution, file read/write, environment-variable use, browser invocation, and local script execution, but declares no explicit tool scope or permissions boundaries. This creates excessive implicit authority: if the skill is invoked in a permissive runtime, it could access or modify local files, spawn external programs, or persist data beyond what users expect from an insurance-analysis skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a Chinese-language insurance analyzer for consumers, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation section uses phrases like “帮我看看这款保险”, “分析一下值不值”, and “条款我看不懂”, which are common conversational requests and not clearly bounded to a specific context or invocation mechanism. Although the skill is insurance-specific overall, this trigger list lacks negative examples or tighter constraints, increasing the chance of unintended activation for general insurance discussion.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says the skill '只做产品分析,不自动出保险计划书', which narrows the skill to analysis rather than document production. However, the file defines a primary HTML deliverable and optional PDF/Word/Excel exports, meaning the skill also acts as a report-generation/export tool rather than only an analyzer.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Feedback collection and email-packaging are not necessary for insurance analysis and introduce persistent storage plus outbound-sharing preparation in a highly sensitive data domain. Even with stated sanitization rules, this creates unnecessary privacy risk and a pathway for accidental disclosure of insurance-related personal data.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · dist/保险计划书分析大师.zip!/保险计划书分析大师/scripts/build_policy.py (reported line 439)May include surrounding context.

python
irr = os.path.join(HERE, "irr.py")
        cmd = [sys.executable, irr, "--input", out, "--years", args.years, "--out", csvp]
        print("\n>>> 运行 irr.py:")
        subprocess.run(cmd)


if __name__ == "__main__":

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · dist/保险计划书分析大师.zip!/保险计划书分析大师/scripts/export.py (reported line 150)May include surrounding context.

python
os.path.abspath(src),
    ]
    try:
        r = subprocess.run(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE,
                           timeout=180)
    except Exception as e:
        return None, "调用浏览器失败:%r" % (e,)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · dist/保险计划书分析大师.zip!/保险计划书分析大师/scripts/export.py (reported line 244)May include surrounding context.

python
"--window-size=%d,%d" % (W, H),
            os.path.abspath(tmp),
        ]
        subprocess.run(cmd, stdout=subprocess.PIPE, stderr=subprocess.PIPE,
                       timeout=180)
    except Exception as e:
        return None, None, None, "SVG 转 PNG 失败:%r" % (e,)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · dist/保险计划书分析大师.zip!/保险计划书分析大师/scripts/extract.py (reported line 67)May include surrounding context.

python
"""
    try:
        import subprocess
        subprocess.run(
            [sys.executable, "-m", "pip", "install", "--quiet",
             "openpyxl", "python-docx", "pdfplumber"],
            check=False, timeout=180,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · dist/保险计划书分析大师.zip!/保险计划书分析大师/scripts/feedback.py (reported line 442)May include surrounding context.

python
if sys.platform.startswith("win"):
            os.startfile(path)  # noqa: S606
        elif sys.platform == "darwin":
            subprocess.run(["open", path], check=False)
        else:
            subprocess.run(["xdg-open", path], check=False)
        return True

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · dist/保险计划书分析大师.zip!/保险计划书分析大师/scripts/feedback.py (reported line 444)May include surrounding context.

python
elif sys.platform == "darwin":
            subprocess.run(["open", path], check=False)
        else:
            subprocess.run(["xdg-open", path], check=False)
        return True
    except Exception:
        return False

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.