Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 95% confidence
- Finding
声明描述覆盖了多个生产力与自动化场景,包括日程管理、任务提醒、工作流模板和自动化机会识别;但代码只处理本地数据文件的加载、清洗、去重、统计与报告输出,没有任何与日历、提醒、任务追踪、计划安排或工作流编排相关的逻辑。虽然“数据整理自动化”这一子项与代码相符,但整体声明显著夸大了能力范围,导致描述与实际行为存在实质性不匹配。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed productivity helper with local scripts and workflow templates, with no evidence of hidden execution, exfiltration, or system persistence.
Install only if you want a Chinese-language productivity automation kit. Review and explicitly approve any template that would call external APIs, send messages, publish social content, update CRM or finance systems, or write output over existing files.
声明描述覆盖了多个生产力与自动化场景,包括日程管理、任务提醒、工作流模板和自动化机会识别;但代码只处理本地数据文件的加载、清洗、去重、统计与报告输出,没有任何与日历、提醒、任务追踪、计划安排或工作流编排相关的逻辑。虽然“数据整理自动化”这一子项与代码相符,但整体声明显著夸大了能力范围,导致描述与实际行为存在实质性不匹配。
代码的核心功能与“日程管理助手”相符,但与声明的更广泛“效率自动化工具箱”存在明显差距。该脚本只做任务录入、时间块排程、周计划模板生成和本地JSON保存,没有工作流自动化、流程模板编排、提醒通知、数据整理/清洗等功能。虽然描述中包含“日程管理”这一子项,代码确实覆盖了这一部分,但整体声明将技能包装为多功能自动化工具箱,而实际代码仅实现其中较窄的一部分,因此属于描述与实际行为不完全一致的能力夸大型 mismatch。
Without declared permissions the skill's intent is opaque and cannot be validated.
The trigger phrases are broad, generic productivity terms that overlap with ordinary conversation, increasing the chance of unintended skill activation. In an automation-oriented skill, accidental invocation can expose user task context, create files, or launch suggested workflows without the user intending to use this skill.
The manifest description and trigger phrases are entirely in Chinese, and the skill content is presented as if Chinese is the required operating language. There is no indication that users may choose another language or opt in to this locale, which can violate language-choice policy for generally applicable skills.
The embedded Bash example performs an external HTTPS request and includes an Authorization bearer token header, which is a genuine external transmission pattern. In the context of a productivity skill that claims no external API access by default, this is more dangerous because users may not expect network egress or token use from included automation snippets.
# Step 1: 数据采集
log "采集数据..."
DATA=$(curl -s -H "Authorization: Bearer $API_TOKEN" \
"https://api.example.com/endpoint" || echo "")
# Step 2: 数据验证
if [ -z "$DATA" ]; then
The quick-start examples use highly ambiguous natural-language requests such as planning work or setting reminders, which are common across many benign assistant interactions. This raises the risk of the skill being selected unexpectedly, especially because it spans broad productivity domains and may steer users into automations they did not request.
The skill's safety section claims it will not access external APIs unless explicitly authorized, yet the embedded Bash template performs a curl request with an API bearer token. This inconsistency can mislead users and downstream agents into trusting the skill's privacy posture while executing networked behavior that transmits data externally.
The document states it will not automatically send messages to third parties, but multiple workflow templates include sending emails, notifications, and social-media publishing. Misrepresenting outbound communication behavior can cause users to enable automations without understanding that data or content may be transmitted externally.
The manifest’s user-facing description and features are entirely in Chinese, with no indication that the skill supports other languages or that it is intentionally limited to a Chinese-speaking audience. This can violate language/locale policy when a skill imposes a language without user opt-in or explicit justification.
The manifest describes workflow templates, schedule management, task reminders, and data organization automation. This template goes beyond that scope by modeling automated multi-platform social media publishing, which is a distinct marketing/distribution capability not clearly encompassed by the stated purpose.
The module docstring is entirely in Chinese, and the script's labels/messages are also hard-coded in Chinese, which indicates the skill forces a specific language for interaction. The policy allows locale constraints only when users are given a choice or the regional limitation is clearly documented and justified, neither of which appears here.
Multiple comments and runtime messages are written only in Chinese, including status output and error text shown to the user. This enforces a specific language/locale experience without opt-in or documented justification, which matches the language-policy violation criteria.
The file presents operational documentation largely in Chinese, including headings, comments, and module descriptions, but does not indicate that the skill is region-specific or provide an English-only/Chinese-only opt-in. Per the policy, forcing a specific language or locale without user choice can be a natural-language policy violation.
This markdown file provides commands for data_automation.py and schedule_planner.py that produce output files such as result.json, cleaned.json, and schedule.json, but it does not warn users that running them may create or overwrite local files. For markdown files, user-facing documentation should disclose behaviors that could affect user data or system state.
This markdown file contains user-facing natural-language instructions and examples only in Chinese, which can constitute a language/locale policy issue when no opt-in or justification is provided. The file does not indicate that the skill is intended exclusively for Chinese-speaking users or a China-specific environment.
This shell script presents its user-facing operational instructions in Chinese only, including the usage guidance and README reference. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.
The module docstring presents the script purpose entirely in Chinese, and this establishes a fixed language for user-facing guidance. Under the policy, forcing a specific language without offering a language or locale choice is a natural-language policy violation.
The argparse description and argument help strings are all written in Chinese, so users are required to interact in that language. The file does not offer an alternative language or indicate that the tool is intentionally limited to a Chinese-speaking context.
The script appends status messages containing task-related information to a dated log file via tee -a, and later logs the task count and missing-file path. Although logging is visible in code, there is no user-facing warning, prompt, or accompanying markdown here informing users that reminder activity will create persistent local logs under logs/, which may be relevant if task metadata is sensitive.
No suspicious patterns detected.