Back to skill

Security audit

Hutian Opc Guan Dan

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese-language Guandan card-game assistant with local game logic and learning-progress storage, with reliability gaps but no evidence of malicious behavior.

Install only if you want a Chinese-language Guandan assistant and are comfortable with local progress tracking. Treat the move advice and simulations as training aids rather than authoritative gameplay engines, because the inspected code has simplified validation and known crash-prone paths.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/game_simulator.py:217
Finding

Unvalidated move input causes denial of service and game-state corruption

Content
View full analysis
Tuple[str, List[Card], int]: """ 解析出牌字符串 返回: (牌型, 牌列表, 强度) """ move_str = move_str.strip() # 解析炸弹 if '炸弹' in move_str or '炸' in move_str: # 提取点数 rank = None for r in ['大王', '小王', '2', 'A', 'K', 'Q', 'J', '10', '9', '8', '7', '6', '5', '4', '3']: if r in move_str: rank = r break if '大王' in move_str or '小王' in move_str: return ('天王炸弹', [], 1000) elif rank: count = 4 # 默认四炸 for c in ['七', '六', '五', '四']: if c in move_str: count = {'七': 7, '六': 6, '五': 5, '四': 4}[c] break return ('炸弹', [], 500 + count * 10) # 解析天王炸弹 if '王炸' in move_str or '王炸' in move_str: return ('天王炸弹', [], 1000) # 解析牌型 if '单张' in move_str or move_str[0] in '♠♥♣♦': return ('单张', [], 14) # 简化处理 if '对' in move_str: return ('对子', [], 14) if '顺' in move_str: return ('顺子', [], 10) return ('单张', [], 3) def execute_move(self, seat: int, move_str: str) -> bool: """执行出牌""" if seat != self.current_player: return False player = self.players[seat] pattern, cards, strength = self.parse_move(move_str) # 验证出牌是否合法(简化版) # 实际实现需要更复杂的牌型验证 # 记录出牌 if self.current_round is None: self.current_round = GameRound(leader=seat) self.round_number += 1 self.current_round.plays[seat] = move_str self.current_round.pattern = pattern self.current_round.strength = max(self.current_round.strength, strength) # 更新当前玩家 self.current_player = (seat % 4) + 1 # 检查 ...[truncated 2517 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/strategy_engine.py:269
Finding

Invalid enum conversion crashes follow-up move generation

Content
View full analysis
List[MoveOption]: """跟牌出牌建议""" suggestions = [] analysis = self.analyze_hand() pattern = self.current_pattern strength = self.current_strength # 能压住的牌 can_beat = self._find_beatable_cards(analysis, pattern, strength) for card_info in can_beat[:2]: # 最多2个压制选项 suggestions.append(MoveOption( cards=card_info['cards'], pattern=PatternType(card_info['pattern']), reason=card_info['reason'], risk=card_info.get('risk', ''), priority=card_info.get('priority', 3), cooperation_value=card_info.get('coop', 3) )) # 过牌选项 suggestions.append(MoveOption( cards="过", pattern=PatternType.PASS, reason="对手牌力强,选择观望", risk="失去出牌机会", priority=1, cooperation_value=4 )) return suggestions def _find_beatable_cards(self, analysis: Dict, pattern: str, strength: int) -> List[Dict]: """找出能压制的牌""" beatable = [] # 简化实现:检查是否能用炸弹压制 if analysis['bombs']: bomb = analysis['bombs'][0] beatable.append({ 'cards': f"炸弹{bomb}", 'pattern': 'BOMB', 'reason': '用炸弹压制', 'risk': '消耗重要控制牌', 'priority': 5 if strength > 15 else 3, 'coop': 2 }) # 检查大牌压制 if pattern == '单张': for rank, count in analysis['by_rank'].items(): if count >= 1: value = self._get_rank_value(rank) if value > strength: beatable.append({ 'cards': f"单张{rank}", 'pattern': 'SINGLE', 'reason': f'用{rank}压制', 'priority' ...[truncated 2005 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill advertises hand recognition, card tracking, move recommendation, and replay analysis, but the finding indicates those core features are not actually implemented, while the real functionality is mostly limited to simulation. This mismatch is dangerous because it can mislead users and orchestrators into overtrusting outputs, invoking the skill in inappropriate contexts, or granting permissions based on claimed features rather than actual behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README describes activation in very broad terms such as hand recognition, card counting, move suggestions, training, and review without clearly defining when the skill should or should not be invoked. In an agent ecosystem, overly broad trigger language can cause unintended activation, increasing the chance of the skill being used in contexts the user did not explicitly request and potentially leading to confusion, overreach, or inappropriate assistance.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill references local scripts and template/reference files, which implies file read/write style capabilities, but it does not declare any tool scope or permissions boundaries. That creates an authorization and transparency gap: a runtime may permit broader file access than users or reviewers expect, increasing the chance of unintended data exposure or modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The activation condition is broad enough to match many generic card-game assistance or learning requests, which can cause the skill to be invoked outside its intended narrow context. Overbroad routing is a security and safety issue because it increases unnecessary exposure of the skill, may crowd out more appropriate skills, and can lead to incorrect or overconfident guidance being presented to users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Across the file, all user-facing commands, labels, and interaction examples are presented only in Chinese, with no indication that users may choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown template is entirely written in Chinese and structures the generated report in that language, with no indication that users can choose another language or opt in to a locale-specific format. The policy explicitly calls for flagging language or locale constraints when they are imposed without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template is entirely written in Chinese and provides no indication that users may choose another language or locale. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file presents all instructional content in a single language and does not indicate that the user can choose another language or that the content is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire markdown file is written in Chinese and does not indicate that language selection is optional or configurable. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python file contains the module docstring entirely in Chinese and continues to use Chinese-only user-facing labels and explanations throughout the skill. Under the policy for natural-language violations, forcing a specific language without user opt-in is reportable when no alternative language choice or locale selection is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file explicitly claims AI information isolation, but get_player_hand(seat) exposes any player's full private hand to any caller. In this skill context, that creates a real integrity/fairness flaw: any orchestration layer, prompt tool, or future AI logic can trivially bypass the intended hidden-information model and gain unauthorized game state, undermining simulations, coaching, and replay correctness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module-level natural-language description is entirely in Chinese and presents the skill as a Chinese-language experience, with no indication that users may choose another language or that the restriction is intentionally region-specific. The policy calls for flagging language or locale constraints when they are imposed without user opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language documentation and later user-facing reasoning text entirely in Chinese, presenting the skill as Chinese-only behavior. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation when no alternative language or locale choice is offered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

All user-facing descriptive content in the file is presented only in Chinese, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in can be a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template forces a specific language/locale for all user-facing content, and there is no indication that users can choose another language. Under the policy rule, fixed language output without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown template forces a specific language/locale for all headings, labels, and guidance text. Under the policy, a skill should not impose a language without offering the user a choice or clearly documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. The top-level docstring presents the skill only in Chinese, and the file does not indicate that this is a region-specific tool or that users may choose another language.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The reset docstring/comment and inline note indicate the tracker should be reset while preserving the current mode, but self.state = GameState() creates a fresh default state and self.state.game_mode = self.state.game_mode is a no-op that keeps the new default rather than the previous mode. This is an active contradiction between the code comment and runtime behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The engine persistently stores user learning progress to a local JSON file without any visible consent, notice, retention policy, or opt-out mechanism. While the stored data appears low sensitivity in this game-assistant context, undisclosed persistence can still create privacy and transparency issues, especially if multiple users share the same environment or the data is retained longer than expected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.