Back to skill

Security audit

Cn Report Generator

Security checks for vulnerabilities and agentic risk

Overview

This is mostly a local Chinese report generator, but it silently adds unrelated branding to generated reports and overwrites fixed report files in the user’s home directory.

Review before installing. The skill reads local work logs and creates reports locally, with no observed network execution or credential handling, but it can overwrite reports under ~/reports and it adds unrelated branding to generated business documents. Monthly reports are advertised but not implemented.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
scripts/generate_report.py:116
Finding

Undisclosed Promotional Branding Injected into Generated Reports

Content
View full analysis

Vulnerability Details

File Location: scripts/generate_report.py:116-120 and scripts/generate_report.py:181-185
Vulnerability Type: Hardcoded promotional output injection
Risk Level: Medium

Vulnerable Code

Daily report generation at lines 116-120:

python
---
*Generated at: {datetime.now().strftime("%Y-%m-%d %H:%M")}*
*Qiance · Qianwan · Qiancheng 🦞*
"""

Weekly report generation at lines 181-185:

python
---
*Generated at: {datetime.now().strftime("%Y-%m-%d %H:%M")}*
*Qiance · Qianwan · Qiancheng 🦞*
"""

The snippets above are English renderings of the hardcoded report footer found at the cited locations; the source uses equivalent non-English display text.

Technical Analysis

The daily and weekly report generators unconditionally append an unrelated branding tagline to every generated report. The documented report templates do not disclose that this promotional content will be inserted, and the user has no configuration option to disable it.

This behavior compromises output integrity by modifying task-focused business documents with third-party branding. Because the footer is embedded directly in the report templates, it is added regardless of the contents of the source logs or the user's intent. This is classified as skill instruction hijacking because execution of the skill produces an undisclosed addition to the requested output.

Attack Path

  1. A user invokes the skill to generate a daily or weekly business report.
  2. The script reads the applicable workspace logs.
  3. generate_daily_report() or generate_weekly_report() constructs the report.
  4. The hardcoded promotional tagline is appended without user consent or configuration.
  5. save_report() writes the modified document under ~/reports/daily/ or ~/reports/weekly/.
  6. The user may distribute or publish the report without noticing the embedded branding.

Impact Assessment

The iss ...[truncated 426 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the hardcoded promotional tagline from both daily and weekly report templates.
  2. Keep default generated reports limited to content explicitly requested by the user.
  3. If branding is a legitimate product requirement, expose it through an explicit configuration option that defaults to disabled.
  4. Disclose any optional footer in the skill documentation and obtain user consent before including it.
  5. Add automated tests asserting that default report output contains only documented template content.
  6. Review all future output templates for undisclosed advertisements, links, endorsements, or unrelated material.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

整体主功能与声明大体一致:代码确实是在本地读取工作日志类文件,提取已完成、进行中、问题等内容,并生成结构化日报/周报文件,没有发现额外的高风险或无关能力。不过存在两个明显描述偏差:第一,声明称支持日报/周报/月报模板,但代码中 monthly 分支仅打印“月报功能开发中...”,并没有实现月报生成,因此属于能力夸大。第二,代码虽然读取了 MEMORY.md,但后续并未使用其内容构建报告;实际报告内容主要来自 daily log 和 in_progress.md,这与“从 MEMORY.md 和 daily log 自动生成”的描述不完全一致。基于评估标准,这些属于实质性的描述与行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes file read and file write behavior but does not declare any explicit tool scope or permissions boundary. This is dangerous because it leaves the agent's file access expectations implicit, which can lead to over-broad access, unsafe execution, or writes to unintended locations when the skill is invoked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The description, usage examples, and templates consistently prescribe Chinese-language report generation, and there is no indication that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to write generated reports into user home-directory paths without warning about file creation, overwrite behavior, or confirming destination safety. This can cause unintended file modification, clobber existing reports, or create sensitive documents in locations the user did not explicitly approve.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language descriptions and CLI output exclusively in Chinese, including the module docstring and usage instructions. Because the skill does not offer user opt-in for language selection or document a justified locale-specific constraint, it violates the language/locale policy requirement.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The top-level docstring's usage examples include 'python generate_report.py monthly # 生成月报', which tells users the command generates a monthly report. However, the actual monthly code path only emits a development-in-progress message and does not generate or save any report, directly contradicting that documentation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description says it supports 日报/周报/月报模板, implying monthly report generation is part of the delivered behavior. In the code, the monthly branch only prints '月报功能开发中...' and performs no report generation, so the implemented behavior falls short of the stated capability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes the skill as generating Chinese enterprise reports and reinforces this with a "chinese" tag, but it does not state that language selection is optional or user-controlled. This creates a natural-language policy concern because the skill appears to force a specific language/locale without explicit opt-in.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill is described as generating structured daily/weekly/monthly reports from local memory files, but the documentation appends vendor branding and a website link unrelated to that operational purpose. While this is in documentation rather than executable code, it introduces an unjustified capability/purpose signal outside the stated reporting scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The line invites users to visit an external diagnostic page, which is not necessary for a skill whose declared purpose is generating reports from MEMORY.md and daily logs. This is context-inappropriate relative to the manifest's narrowly scoped productivity function.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.