Back to skill

Security audit

Data Prompt Coach 数据分析Prompt引导教练

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly disclosed, but it includes under-scoped web scraping, session/key simulation, external cloud writes, and elevated scheduled automation guidance that users should review carefully before installing.

Install only if you specifically need a data-analysis coaching skill that also helps generate web scraping, external storage, and automation templates. Before using it, review the crawler/key-simulation and Feishu templates, avoid private or login-protected targets, do not paste real cookies or tokens into chat, keep .env files out of source control, and remove or downgrade any scheduled-task examples that use elevated privileges.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (132)

Context-Inappropriate Capability

Medium
Confidence
79% confidence
Finding
The skill includes detailed scraping support, SPA API inspection, and dynamic API key/session emulation methods that go beyond passive prompt coaching and can materially facilitate data extraction from third-party services. Even though the document includes compliance language, these capabilities can be repurposed to automate collection against sites with weak controls or ambiguous authorization boundaries.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The index documents capabilities for SPA scraping, dynamic API-key simulation, incremental crawl design, HTML fallback extraction, and dual-write storage to Feishu Base, which materially expand the skill beyond a passive prompt-coaching/tutorial role. This broadening is dangerous because it normalizes operational data collection and external persistence behaviors that can be repurposed for unauthorized scraping, secret emulation, or exfiltration-like workflows under the guise of analysis assistance.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
A documented capability for 'dynamic API Key simulation' is highly sensitive because it suggests reproducing or imitating access tokens used by third-party services, which can facilitate bypass of intended access controls or scraping protections. In the context of a data-analysis prompt coach, this capability is unnecessary and increases the risk that the skill will assist with unauthorized access patterns rather than legitimate analysis.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The Feishu Base dual-write method adds external storage/integration behavior that is not aligned with a coaching-only skill and creates a path for data to be copied into third-party platforms. Even if intended for convenience, undocumented outbound persistence raises data leakage, compliance, and unauthorized retention risks, especially when users may provide sensitive datasets for analysis.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The test suite materially expands the skill from prompt coaching/tutorial distillation into operational web scraping, incremental sync, and external platform integration behavior. That scope drift is dangerous because downstream routing or future implementation may grant the skill permission to help users perform collection and synchronization tasks that were explicitly outside the advertised role, increasing misuse risk and user confusion about trust boundaries.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Testing for 'dynamic API key simulation' goes beyond benign prompt coaching and can normalize assistance for bypassing anti-automation or access-control mechanisms on third-party services. In context, references to expiring Algolia keys and simulating them create a concrete pathway for abuse against external platforms, making this substantially more dangerous than ordinary scraping guidance.

Context-Inappropriate Capability

Medium
Confidence
81% confidence
Finding
Feishu multidimensional table synchronization and dual-storage workflows introduce operational data handling capabilities that exceed a prompt-coach's stated scope. While not inherently malicious, they increase the chance the skill will facilitate movement of scraped or user data into external systems without clear governance, privacy controls, or authorization boundaries.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The spec explicitly contemplates database connections and writes ('邮件/IM API/数据库连接'), which conflicts with the manifest restriction against direct production database access. Even though phrased as a warning, it expands the skill's operational scope and can normalize generating automation that touches live systems and consumes real credentials.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The documented 'SQL(自动化)' scenario includes running SQL, exporting CSV, and uploading results, which materially exceeds a prompt-coaching/tutorial skill and directly conflicts with the manifest's 'Do NOT use for 直接接入生产数据库'. This enables users to operationalize unattended data extraction and dissemination from databases, increasing risk of misuse and data leakage.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
Including live database snapshot and dump operations in the backup checklist extends the template into direct database administration territory, outside the declared scope. This can encourage users to run sensitive export operations and create additional copies of regulated or confidential data without safeguards.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The template shows `schtasks /create ... /rl HIGHEST`, which instructs users to register scheduled tasks with elevated privileges. For a prompt-coaching/data-analysis tutorial skill, providing high-privilege persistence guidance is unnecessary and dangerous because it can be used to run arbitrary scripts with maximal local rights on a recurring basis.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The file is materially outside the declared purpose of a data-analysis prompt-coaching skill and instead provides an end-to-end crawler debugging playbook. That scope expansion increases the chance the skill is invoked for scraping and collection workflows the manifest explicitly says it should not support, creating misuse and policy-boundary bypass risk.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
These sections teach users how to recover dynamic API keys, replay authenticated request chains, preserve cookies, supply CSRF tokens, and mimic browser headers to get around anti-automation barriers. In the context of a non-scraping coaching skill, this is dangerous because it operationalizes bypass-oriented collection techniques that can facilitate unauthorized access or evasion of site protections.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
This template goes beyond prompt coaching and provides executable code for persistent local storage plus authenticated writes to an external Feishu service. In the context of a skill explicitly described as a prompt coach/tutorial distiller, that capability expansion increases the chance the agent facilitates real data exfiltration, unintended persistence, or operational actions the user did not expect from this skill.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file explicitly promotes Feishu Base dual-storage usage even though the skill metadata says it should not be used for direct production database access. That contradiction weakens trust boundaries and can cause the agent to steer users into live system integration despite declared safety constraints.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The template instructs users to load a personal access token from .env and then use it for authenticated API writes, which introduces credential handling and privileged external actions unrelated to a pure prompt-coaching role. Even if the token is not hardcoded, normalizing credential use inside this skill increases the risk of misuse, accidental leakage, and unauthorized writes.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The template explicitly instructs the AI to generate web-scraping prompts and crawler code, which materially expands the skill from data-analysis coaching into data acquisition and automation. In this context, that scope drift is dangerous because it enables code generation for scraping targets, including sites with dynamic loading, and increases the chance the skill is used for unauthorized collection or policy bypass adjacent behavior.

Description-Behavior Mismatch

Medium
Confidence
89% confidence
Finding
The template introduces cloud-storage integration, external table writes, and token-handling instructions that are outside the declared purpose of a data-analysis prompt coach. This broadens the operational surface area to include data exfiltration paths and secret-handling behavior, making misuse or accidental leakage more likely.

Context-Inappropriate Capability

High
Confidence
94% confidence
Finding
The section instructing the AI to assess SPA behavior, dynamic keys, and unique ID extraction is operational guidance for building scrapers rather than analyzing datasets. In a skill that claims to be a data-analysis coach, this is risky because it helps users adapt automation to more complex sites and can facilitate collection from targets that rely on client-side mechanisms.

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
Detailed instructions for Feishu cloud writes, batching, and token/QPS error handling move the skill beyond analysis guidance into implementation of external system integrations. That creates opportunities for unintended outbound data transfer and normalizes handling of authentication and rate-limit behavior in a skill not scoped for such operations.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The template explicitly steers the agent from data-analysis coaching into website reconnaissance and crawler generation, including identifying APIs and producing scraping code. That materially exceeds the declared skill scope and creates a capability expansion toward collecting third-party data, which raises abuse risk and weakens user and platform expectations about what the skill does.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The references to dynamic API identification and API-key simulation instruct the user to discover and reuse authentication material from live web applications. In the context of a data-analysis coach, this is unjustified sensitive capability that could enable unauthorized access patterns or misuse of embedded credentials.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The anti-blocking advice such as changing User-Agent, adding Referer, and retry backoff is operational scraping guidance intended to bypass or work around access controls and rate-limiting behavior. In this skill context, that makes the scraping workflow more effective and more dangerous, even if framed as troubleshooting.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
This section documents expansion from prompt-guided data analysis into web crawling, dynamic API identification/key simulation, and Feishu cloud storage. Those capabilities materially broaden the skill’s operational scope beyond its declared purpose, increasing the chance that the skill will be invoked for data acquisition against third-party sites or cloud persistence workflows that were not covered by the original safety boundary.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The addition of API-simulation and crawling methods is not merely educational metadata; it signals capability drift toward collection and automation behaviors that can be repurposed for unauthorized scraping or bypassing normal access patterns. In a skill marketed as a data-analysis prompt coach, this mismatch can mislead operators and downstream systems about the risk profile and permissible use cases.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/audit/security-compliance.md:141

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/methods/M23-dynamic-api-key-simulation.md:126