Back to skill

Security audit

Productivity Automation Kit

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed productivity helper with local scripts and workflow templates, with no evidence of hidden execution, exfiltration, or system persistence.

Install only if you want a Chinese-language productivity automation kit. Review and explicitly approve any template that would call external APIs, send messages, publish social content, update CRM or finance systems, or write output over existing files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述覆盖了多个生产力与自动化场景,包括日程管理、任务提醒、工作流模板和自动化机会识别;但代码只处理本地数据文件的加载、清洗、去重、统计与报告输出,没有任何与日历、提醒、任务追踪、计划安排或工作流编排相关的逻辑。虽然“数据整理自动化”这一子项与代码相符,但整体声明显著夸大了能力范围,导致描述与实际行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

代码的核心功能与“日程管理助手”相符,但与声明的更广泛“效率自动化工具箱”存在明显差距。该脚本只做任务录入、时间块排程、周计划模板生成和本地JSON保存,没有工作流自动化、流程模板编排、提醒通知、数据整理/清洗等功能。虽然描述中包含“日程管理”这一子项,代码确实覆盖了这一部分,但整体声明将技能包装为多功能自动化工具箱,而实际代码仅实现其中较窄的一部分,因此属于描述与实际行为不完全一致的能力夸大型 mismatch。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad, generic productivity terms that overlap with ordinary conversation, increasing the chance of unintended skill activation. In an automation-oriented skill, accidental invocation can expose user task context, create files, or launch suggested workflows without the user intending to use this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and trigger phrases are entirely in Chinese, and the skill content is presented as if Chinese is the required operating language. There is no indication that users may choose another language or opt in to this locale, which can violate language-choice policy for generally applicable skills.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The embedded Bash example performs an external HTTPS request and includes an Authorization bearer token header, which is a genuine external transmission pattern. In the context of a productivity skill that claims no external API access by default, this is more dangerous because users may not expect network egress or token use from included automation snippets.

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
# Step 1: 数据采集
log "采集数据..."
DATA=$(curl -s -H "Authorization: Bearer $API_TOKEN" \
  "https://api.example.com/endpoint" || echo "")

# Step 2: 数据验证
if [ -z "$DATA" ]; then

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The quick-start examples use highly ambiguous natural-language requests such as planning work or setting reminders, which are common across many benign assistant interactions. This raises the risk of the skill being selected unexpectedly, especially because it spans broad productivity domains and may steer users into automations they did not request.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's safety section claims it will not access external APIs unless explicitly authorized, yet the embedded Bash template performs a curl request with an API bearer token. This inconsistency can mislead users and downstream agents into trusting the skill's privacy posture while executing networked behavior that transmits data externally.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document states it will not automatically send messages to third parties, but multiple workflow templates include sending emails, notifications, and social-media publishing. Misrepresenting outbound communication behavior can cause users to enable automations without understanding that data or content may be transmitted externally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest’s user-facing description and features are entirely in Chinese, with no indication that the skill supports other languages or that it is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when a skill imposes a language without user opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes workflow templates, schedule management, task reminders, and data organization automation. This template goes beyond that scope by modeling automated multi-platform social media publishing, which is a distinct marketing/distribution capability not clearly encompassed by the stated purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring is entirely in Chinese, and the script's labels/messages are also hard-coded in Chinese, which indicates the skill forces a specific language for interaction. The policy allows locale constraints only when users are given a choice or the regional limitation is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Multiple comments and runtime messages are written only in Chinese, including status output and error text shown to the user. This enforces a specific language/locale experience without opt-in or documented justification, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents operational documentation largely in Chinese, including headings, comments, and module descriptions, but does not indicate that the skill is region-specific or provide an English-only/Chinese-only opt-in. Per the policy, forcing a specific language or locale without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file provides commands for data_automation.py and schedule_planner.py that produce output files such as result.json, cleaned.json, and schedule.json, but it does not warn users that running them may create or overwrite local files. For markdown files, user-facing documentation should disclose behaviors that could affect user data or system state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing natural-language instructions and examples only in Chinese, which can constitute a language/locale policy issue when no opt-in or justification is provided. The file does not indicate that the skill is intended exclusively for Chinese-speaking users or a China-specific environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell script presents its user-facing operational instructions in Chinese only, including the usage guidance and README reference. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring presents the script purpose entirely in Chinese, and this establishes a fixed language for user-facing guidance. Under the policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The argparse description and argument help strings are all written in Chinese, so users are required to interact in that language. The file does not offer an alternative language or indicate that the tool is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script appends status messages containing task-related information to a dated log file via tee -a, and later logs the task count and missing-file path. Although logging is visible in code, there is no user-facing warning, prompt, or accompanying markdown here informing users that reminder activity will create persistent local logs under logs/, which may be relevant if task metadata is sensitive.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.