Back to skill

Security audit

办公室 Token 洞察与提效助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local office-productivity and usage-ledger helper with disclosed file processing and confirmed ledger writes, not an exfiltration or persistence mechanism.

Install only if you are comfortable with a Chinese-language local office assistant that can read files you point it at, write report/ledger files, and optionally import local host usage traces. Keep network disabled as declared, review paths before running CLI commands, and use confirmation steps for any ledger writeback.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 202)May include surrounding context.

md
- **[C2] 加固安全预检红线(CI 闸门此前名不副实)**:
  - R1 补 `__import__("os"|"subprocess"|"builtins"|...)` 危险目标模块(旧正则仅认 `eval/exec/os.system/subprocess`,`__import__("os").system(...)` 可等价绕过)。仅匹配危险目标,避免误伤 `print(..., file=__import__("sys").stderr)` 等良性用法。
  - R2 将 `socket.socket` 扩为 `socket.`(覆盖 `create_connection`/`connect`),并补 `urllib3/pycurl/grpc/websocket/httplib2` 等客户端(旧正则漏掉裸 socket 联网)。
  - R3 放宽密钥长度门槛(8→4 字符),并新增对「api key / access token / client secret / private key / token / pwd」等**敏感名紧跟赋值号**的写法检测(完整模式清单以 `scripts/security_preflight.py` 的 R3 规则为准)。
  - **文档去夸大**:模块 docstring 明确这是「轻量静态启发式,非安全保证」,可被字符串拆分/环境变量/编码绕过,仅拦低级手滑,不在承诺中称「零风险」。
- **[R1] 会议纪要 `_DECISION_RE` 移除过宽关键词「确认」**(极常见中文词,导致「请确认参会」等行被误判为核心结论)。
- **[R3/R4] 清理死代码**:删除 `render_ppt_outline` 从未使用的 `chunks` 变量;移除 `executor.py` 未使用的 `field` 导入。

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README states the skill is 'local-first' and 'does not connect to the network,' but later documents implemented online SkillHub/ClawHub search features. This is a security-relevant integrity issue because users and reviewers may grant the skill higher trust, broader permissions, or more sensitive data based on a false no-network claim, creating a risk of unintended data exposure once online mode is used.

Content

No source excerpt is available for this finding.

Direct flow: pathlib.Path.read_text (file read) → pathlib.Path.write_text (file write)

High
Category
Data Flow
Confidence
80% confidence
Finding

Data flows directly from a source (env vars, files, network) to a sink (network output, exec, file write) without intermediate validation.

Content

Scanner excerpt · scripts/ledger_agent.py (reported line 175)May include surrounding context.

python
# 可回滚到任意历史版本。文件名形如 ledger.json.20260812T142501123456.bak
        ts = datetime.now().strftime("%Y%m%dT%H%M%S%f")
        backup_path = Path(str(p) + f".{ts}.bak")
        backup_path.write_text(p.read_text(encoding="utf-8"), encoding="utf-8")

    tmp = Path(str(p) + ".tmp")
    tmp.write_text(json.dumps(ledger, ensure_ascii=False, indent=2), encoding="utf-8")

Direct flow: pathlib.Path.read_text (file read) → pathlib.Path.write_text (file write)

High
Category
Data Flow
Confidence
80% confidence
Finding

Data flows directly from a source (env vars, files, network) to a sink (network output, exec, file write) without intermediate validation.

Content

Scanner excerpt · scripts/ledger_agent.py (reported line 214)May include surrounding context.

python
# 可回滚到任意历史版本。文件名形如 ledger.json.20260812T142501123456.bak
        ts = datetime.now().strftime("%Y%m%dT%H%M%S%f")
        backup_path = Path(str(p) + f".{ts}.bak")
        backup_path.write_text(p.read_text(encoding="utf-8"), encoding="utf-8")

    tmp = Path(str(p) + ".tmp")
    tmp.write_text(json.dumps(ledger, ensure_ascii=False, indent=2), encoding="utf-8")

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language trigger examples are generic everyday phrases such as asking for help writing a weekly report or summarizing meeting notes. In a host that supports automatic skill routing, broad triggers increase the chance of unintended invocation on ordinary conversation, which could cause the skill to process user content or initiate ledger-preview flows when the user did not explicitly intend to use this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger examples are broad, natural-language phrases that overlap with ordinary user requests, increasing the chance the skill activates in contexts the user did not intend. In a skill that can process local files, import host usage, and propose ledger writes, overbroad invocation raises the risk of accidental data handling, confusing cross-skill routing, and unintended state-changing prompts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README says users can trigger the skill by directly speaking common requests, but it does not clearly define trigger boundaries, exclusions, or arbitration with other skills. Because this skill spans analytics, task execution, and bookkeeping, ambiguous routing can cause unintended execution paths or access to local usage/data when the user only meant to ask a generic question.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The compliance section claims there is no external connectivity, yet other sections describe GitHub Pages/Netlify publishing and online hub search. Even if some features are optional or build-time only, contradictory assurances undermine security review and can mislead users about data flow, trust boundaries, and deployment exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description, trigger examples, and full README content consistently require Chinese-language interaction. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale restriction is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest uses Chinese-only user-facing strings such as the header comment, display_name, description, and category labels. This indicates a fixed language/locale experience, but the file does not mention any user choice, opt-in, or region-specific justification for requiring Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s instructional content is written entirely in Chinese, which effectively imposes a specific language for understanding and adoption of the skill contract. The document does not indicate that alternative languages are available or that Chinese is an optional, region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The natural-language comments are entirely in Chinese and provide no indication that other languages are supported or that this locale constraint is optional. Under the stated policy, forcing a specific language without user opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module-level documentation describes this as a 'pure function core' and explicitly says it only reads a user ledger to produce a Diagnosis object, while later documentation for diagnose() states it does not read files. However, the same module contains load_ledger(), which performs filesystem existence checks and opens a local file. This is an active contradiction in the file's own intent/documentation about side effects and I/O boundaries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code accepts arbitrary filesystem paths for input, ledger operations, and output, which contradicts the claim that it does not access files outside the skill directory. In a security-sensitive agent environment, this discrepancy matters because operators may rely on the stated boundary and inadvertently expose the skill to broader file read/write access than intended.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code accepts arbitrary filesystem paths for input, ledger operations, and output, which contradicts the claim that it does not access files outside the skill directory. In a security-sensitive agent environment, this discrepancy matters because operators may rely on the stated boundary and inadvertently expose the skill to broader file read/write access than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring and surrounding user-facing descriptions are entirely in Chinese, and the script's help and runtime messages continue this language assumption. Under the policy, forcing a specific language without offering a user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The docstring says "本函数本身不碰磁盘;是否写回由用户『确认』触发", implying the completion hook flow is non-writing by default. However, the related closure path implemented by on_executor_completed forwards apply to propose_ledger, which is explicitly documented to truly write back when apply=True, so the surrounding documentation presents the hook behavior as safer/non-writing than the code path actually allows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The argparse description, argument help text, and later printed status/error strings are fixed to Chinese, which constrains users to a single language experience. The file does not provide an opt-in language selection or a documented reason for the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains user-facing natural-language instructions, descriptions, warnings, and CLI help entirely in Chinese, including the module description and operational guidance. Under the policy, forcing a specific language without an explicit user choice or documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The docstring states the module 'only consumes' Diagnosis objects from diagnose.py and avoids other components, implying a narrowly scoped pipeline. However, import_host_usage imports host_cost providers and pulls host usage records, then converts and writes them into the ledger, which is a materially different input path than only consuming Diagnosis output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring explicitly says the follow-up answer returns Chinese text, and the rest of the user-facing output strings are also fixed in Chinese. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains natural-language documentation and output strings entirely in Chinese, including operational descriptions and scoring labels, with no indication that users can opt into another language. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is justified, which is not stated here.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The registry includes very broad aliases such as "文档", "数据", "代码", and "邮件", which are common words likely to appear in normal conversation outside a precise task-selection context. This can cause ambiguous or incorrect task routing, letting user input trigger the wrong capability and potentially causing unintended actions or data handling in downstream workflows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file title and the entire changelog are written in Chinese, which indicates a fixed language choice in user-facing natural language content. Under the policy rule, forcing a specific language without opt-in can be a locale-policy violation, and this file does not document any user choice or region-specific justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

All user-facing instructions and example invocations are presented in Chinese, and the file does not indicate that another language is supported or that Chinese is a required locale for a region-specific skill. This can violate language/locale policy when users are not given an explicit choice or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
CHANGELOG.md:13