Back to skill

Security audit

INSP 公司 HR 知识库

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly static internal HR knowledge skill, but it embeds a corporate Wi-Fi password and broad internal business procedures in a published package.

Review before installing. Remove the Wi-Fi password from the skill, rotate that credential, and move network access details to an authenticated IT channel. Consider splitting finance/procurement/system SOPs into narrower role-scoped skills or adding clear access controls before publishing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:326
Finding

Hardcoded Corporate Wi-Fi Credential

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 326-328
Vulnerability Type: Plaintext hardcoded credential
Risk Level: High

markdown
#### 9.1 WiFi 信息
- **WiFi 名称:** inspiring
- **密码:** 52inspiring

Technical Analysis

The Skill embeds a corporate Wi-Fi SSID and password directly in a plaintext Markdown file. Any user or system with access to the Skill package can retrieve the credential without authentication or authorization checks.

This is particularly concerning because the document identifies itself as company-internal and states that its contents must not be shared externally. Packaging the password with the Skill expands the secret's exposure to artifact repositories, audit systems, backups, logs, and every environment where the Skill is installed.

Attack Path

  1. An unauthorized party obtains the Skill package through accidental publication, repository access, backup exposure, or redistribution.
  2. The party opens SKILL.md and reads lines 326-328.
  3. The party recovers the SSID inspiring and password 52inspiring.
  4. When within range of the wireless network, the party attempts to authenticate using the disclosed credential.
  5. If the credential remains valid and no additional access controls are enforced, the party gains the network access assigned to that Wi-Fi network and can attempt internal service discovery or attacks against reachable systems.

Impact Assessment

Successful exploitation may permit unauthorized connection to the corporate wireless network. The precise privileges and reachable scope depend on network segmentation, client isolation, firewall policy, and any additional identity controls. Potential consequences include unauthorized use of corporate network resources, internal reconnaissance, attacks against reachable employee devices or services, and use of the network as a launch point for further intrusion.

The artifact does not establish that th ...[truncated 157 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the SSID and password from SKILL.md and all distributed copies of the Skill.
  2. Immediately rotate the exposed Wi-Fi password and invalidate the disclosed value.
  3. Review repository history, artifact stores, backups, logs, and published packages for retained copies of the credential.
  4. Replace the credential section with instructions directing authorized employees to an authenticated IT portal or support channel.
  5. Store wireless credentials in an access-controlled secret-management system rather than documentation or Skill configuration.
  6. Prefer per-user or per-device authentication, such as WPA2-Enterprise or WPA3-Enterprise with 802.1X, over a shared password.
  7. Segment guest, employee, and sensitive internal networks; enforce client isolation and least-privilege firewall rules.
  8. Add automated secret scanning to source-control and artifact-publication workflows to prevent future plaintext credential exposure.
  9. Review wireless authentication logs for unexpected access associated with the exposed credential.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document directly exposes the company WiFi SSID and password even though the skill's stated function is HR policy lookup. Publishing network credentials in a broadly invocable skill can enable unauthorized network access, lateral movement, and further compromise if the skill is accessible to users who do not strictly need this secret.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as an HR knowledge lookup tool, but it includes finance SOPs, procurement approval thresholds, project numbering schemes, and operational workflow details outside that scope. This unnecessary expansion increases the chance that users or downstream systems disclose or rely on sensitive internal business information that is not needed for HR queries, violating least-privilege and increasing exposure of internal processes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger conditions are broad enough to match many general workplace questions, which can cause this skill to be invoked outside narrowly intended HR use cases. Because the skill contains sensitive internal operational and financial content, overbroad invocation materially raises the risk of unnecessary disclosure to users asking only loosely related questions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language instructions and examples are entirely Chinese, which can amount to an implicit language constraint for users. The file does not indicate that Chinese is optional, user-selected, or required for a documented region-specific reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The description and tags are written entirely in Chinese, indicating the skill is targeted to a specific language/locale, but the file does not mention any user choice, opt-in, or justification for this restriction. Under the policy, language constraints should either be optional for users or clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.