Back to skill

Security audit

Hutian Opc Business Model

Security checks for vulnerabilities and agentic risk

Overview

The skill’s business-plan analysis purpose is mostly coherent, but its generated HTML reports can execute unsafe injected or third-party scripts and it under-discloses handling of sensitive business-plan content.

Review before installing or using this skill with confidential business plans. Prefer PNG-only output or fix the HTML generator to escape untrusted fields, pin or vendor ECharts, and add a restrictive CSP before sharing generated reports. Remove the promotional runtime section and add clear privacy/redaction instructions for uploaded business documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_radar.py:184
Finding

Untrusted report metadata permits stored script injection in generated HTML

Content
View full analysis
{project_name} ``` ```python for dim, score in zip(dimensions, scores): score_class = "score-high" if score >= 7 else ("score-low" if score < 5 else "") html_content += f'{dim}{score:.0f}/10\n' ``` Dimension data is also embedded in an executable script block: ```python indicator: ''' + json.dumps(indicator_config, ensure_ascii=False) + ''', ``` ### Technical Analysis The HTML report generator treats values read from the input JSON file as trusted markup. In particular, `project_name` and each entry in `dimensions` are interpolated into HTML without contextual output encoding. An attacker-controlled dimension such as the following is interpreted as markup when the report is opened: ```html ``` The use of `json.dumps()` for the ECharts configuration does not provide safe HTML-script embedding. JSON serialization can preserve a sequence such as ``, allowing an attacker to terminate the existing script element and inject a new HTML or script element. Input validation only verifies that `dimensions` and `scores` exist and each contains nine entries. It does not validate dimension names, score types, score ranges, metadata length, or prohibited markup. ### Attack Path 1. An attac ...[truncated 1377 chars]
Remediation
View remediation
", "\\u003e") .replace("\u2028", "\\u2028") .replace("\u2029", "\\u2029") ) ``` 3. Prefer a template engine with automatic HTML escaping, such as Jinja2 with auto-escaping explicitly enabled. 4. Validate input against a strict schema: - Require exactly the expected nine dimension names, or map internal identifiers to fixed display labels. - Require scores to be finite numeric values between 0 and 10. - Restrict metadata to reasonable lengths. - Reject unexpected object and array types. 5. Add a restrictive Content Security Policy that disallows inline scripts and limits script sources. CSP should be defense in depth rather than a replacement for encoding. 6. Add regression tests using payloads containing ``, event-handler attributes, quotes, ampersands, and Unicode line separators. ]]>

T08 · Insecure Dependencies

Warning
Location
scripts/generate_radar.py:207
Finding

Generated reports execute a mutable third-party JavaScript dependency without integrity verification

Content
View full analysis
``` The same dependency pattern is prescribed by the report output template: ```html
``` ### Technical Analysis Generated HTML reports retrieve and execute JavaScript from a third-party CDN every time the report is opened. The dependency specifies only the major ECharts version (`@5`), so the resolved resource may change as new releases are published. No Subresource Integrity hash is supplied, and the generated report has no restrictive Content Security Policy. HTTPS protects the network connection but does not protect against: - Compromise of the CDN or its publishing infrastructure. - Compromise of the upstream package or maintainer account. - An unexpected or malicious release within the allowed major version. - DNS, account, or dependency-resolution failures at the trusted provider. Because the dependency executes as ordinary page JavaScript, it receives the same DOM and origin privileges as the report itself. ### Attack Path 1. An attacker compromises the ECharts package distribution path, the CDN account, or another component capable of modifying the URL's response. 2. The mutable `@5` resource begins serving attacker-controlled JavaScript. 3. A user opens a generated HTML report while connected to the network. 4. The browser retrieves the script from the CDN. 5. Because no integrity hash is present, the browser accepts and executes the altered response. 6. The malicious dependency reads or changes the r ...[truncated 703 chars]
Remediation
View remediation
``` 4. Generate and verify the integrity hash as part of a controlled dependency-update process. 5. Add a Content Security Policy that permits scripts only from explicitly approved sources and disallows unnecessary inline execution. 6. Record the exact dependency version and checksum in a lock file or software bill of materials. 7. Ensure reports fail safely when the dependency cannot be verified rather than silently falling back to another remote source. ]]>

T01 · Skill Instruction Hijacking

Note
Location
SKILL.md:636
Finding

Skill instructions introduce unrelated promotional behavior into agent outputs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个较完整的商业计划书分析工具,涵盖多种分析框架与自动评分;但提供的代码片段实际只是一个可视化脚本,前提是外部已提供九维度评分JSON。其主要功能是生成雷达图和HTML展示,并附带平均分和评级。虽然这与“对每个维度进行雷达图打分”中的可视化部分部分相关,但远不足以覆盖声明中的核心能力,因此存在明显描述与行为不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description and usage instructions are entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking region for compliance or other documented reasons. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes capabilities that require reading uploaded files and generating outputs, but it does not declare any explicit tool scope or permissions boundaries. In an agent environment, undeclared file read/write capability increases the chance of overbroad access, making it harder to constrain what files may be accessed or written and raising the risk of unintended data exposure or filesystem misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill asks users to upload business plans, which commonly contain confidential financials, strategy, customer data, and IP details, but it gives no privacy notice or warning that this content will be processed and quoted in outputs. That omission can cause unintentional disclosure of sensitive material in generated reports, citations, or downstream sharing workflows.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Conflicting instructions—'do not fabricate or assume values' versus later allowing inference—create ambiguity that can lead the agent to generate unsupported conclusions. In practice, such ambiguity weakens trust boundaries around evidence handling and increases the risk that speculative content is treated as factual output, especially in high-stakes commercial analysis.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document says results must not be fabricated, yet later permits 'reasonable inference' when product lines are missing. In a business-analysis skill, this can cause the system to present speculative classifications as if they were grounded in the uploaded plan, which may mislead decisions and mask uncertainty in sensitive investment or strategy contexts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The HTML report loads ECharts from a public CDN, which introduces a runtime network dependency and a third-party supply-chain trust boundary into an otherwise local file-generation workflow. If the CDN content is unavailable, tampered with, or blocked, the generated report may fail or execute attacker-controlled JavaScript when opened.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Introducing an external CDN dependency expands the attack surface beyond the stated business-analysis function by requiring trust in external hosted JavaScript for report rendering. This creates a supply-chain and availability risk: a compromised or replaced script can run in the user's browser with access to the generated report's contents.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructions, headings, and output templates only in Chinese, and does not indicate that users may choose another language. Under the natural-language policy rule, forcing a specific language without user opt-in can be a locale-policy violation when no justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all instructions, templates, and output formats exclusively in Chinese. Under the policy criteria, forcing a specific language without user opt-in can be a natural-language policy violation when no alternative language choice or opt-in is documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language and locale behavior that forces the generated report to use zh-CN, which matches the policy category for language/locale constraints. There is no user opt-in, configuration flag, or documented justification that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.