Back to skill

Security audit

ZDAT Chat Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is not plainly malicious, but it asks for public comment automation and lead-record handling without enough scoping, consent, or safety controls.

Review before installing. Only use this skill with accounts and workspaces where automatic public replies, scheduled checks, and lead-ledger records are acceptable. Require preview/approval before posting, restrict ledger access, and avoid printing sensitive lead rows in shared terminals.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents an operational comment-management skill with active capabilities: matching replies from a script library, writing lead records, and limiting proactive outreach across multiple social platforms. The supplied code only generates a simple daily report to stdout using hardcoded zero values and mentions external files by name. It does not read platform comments, generate or send replies, update any ledger, enforce quotas, or interact with Zhihu/Xiaohongshu/Weibo. This is a material description-behavior mismatch because the implemented primary purpose is daily summary output rather than interactive comment handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a multi-platform comment interaction and lead-handling skill with reply generation/matching, automatic ledger writing, and rate-limited proactive engagement. The supplied code does none of those core functions. It is a simple local ledger viewer that opens clue_ledger.xlsx and prints recent rows. This is a materially different primary purpose from the declared behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes file access and operational automation but does not declare any explicit tool scope or permissions boundaries. In an agent setting, missing scope declarations can allow broader-than-expected access to local files or environment-derived data, increasing the chance of unintended data exposure or misuse if the skill is invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are generic terms like '互动' and '评论管理', which can cause accidental invocation in unrelated conversations. Because the skill can automate replies and write lead data, unintended activation could lead to unauthorized actions on external platforms or improper processing of user content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill automates replies on third-party platforms and stores commenter information in a lead ledger, yet it provides no warning about external posting, data retention, or handling of personal data. This creates consent, privacy, and operational-risk issues because users may invoke the skill without understanding that it affects public accounts and records user-generated content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script’s user-facing description and all runtime output are hard-coded in Chinese, with no indication that the user can choose another language or that the skill is intended only for a Chinese-language environment. This matches the policy concern for language/locale constraints imposed without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script opens a local Excel ledger and prints its contents directly to stdout without any access control, masking, or warning that the file may contain sensitive lead/customer information. In the context of a comment-management and lead-tracking skill, this increases the chance of accidental disclosure through terminal logs, shared sessions, or operator screenshots.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module description and all user-facing output strings are fixed in Chinese, with no indication that language selection is optional or configurable. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description and user-facing output are written entirely in Chinese, and the file does not indicate that this language restriction is optional or tied to a documented region-specific use case. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code indicates that comments classified as "high_intent" will be written to a lead ledger ("写入线索台账"), which implies storing user-generated data. Although there is a console message, there is no broader user disclosure or warning that comment content may be retained for lead tracking, which is a privacy-relevant behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.