Back to skill

Security audit

Hutian Opc Investor Dd

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly an investor due-diligence reference package, but one reference file contains embedded file-write tool-call markup that could cause unintended persistent edits in vulnerable agent runtimes.

Install only if your agent treats reference markdown as untrusted text and cannot execute embedded tool-call tags from retrieved content. Before use, remove or quarantine the contaminated fragment in artifact/references/投资协议要点库.md around the file-write markup, and handle LP or investor identity data only when authorized and necessary.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
references/投资协议要点库.md:863
Finding

Embedded Forged File-Write Tool Call in a Reference Document

Content
View full analysis
# 投资协议要点库 ``` The first line translates to: “Now create three new reference files.” ### Technical Analysis The reference document unexpectedly transitions from investment due-diligence material into an imperative instruction directing the agent to create files. It then embeds model-specific tool-call markup that invokes `write_file`. Reference files should supply passive domain information. They do not need filesystem-write privileges to support the Skill’s declared investor due-diligence functionality. Consequently, this instruction violates least-privilege expectations and represents a prompt/tool-call injection embedded in trusted Skill content. If an agent treats reference text as executable instructions, the forged markup may be interpreted as a legitimate tool request. The embedded content continues through the remainder of the file and resembles leaked Skill-generation output rather than valid investment-agreement documentation. There is no evidence that the repository itself automatically executes the call, but exploitation is possible in agent runtimes that do not clearly separate untrusted reference content from authoritative instructions. ### Attack Path 1. A user loads or invokes the investor due-diligence Skill. 2. The agent reads `references/投资协议要点库.md` as trusted contextual material. 3. The agent reaches line 863 and interprets the file-creation statement as an instruction rather than reference data. 4. The following forged `` and `` markup is parsed or imitated as a tool invocation. 5. The agent attempts to create or overwrite reference files using its available filesystem permissions ...[truncated 929 chars]
Remediation
View remediation
`, ``, and ``. 5. Require explicit user authorization before any filesystem mutation. Reading a Skill or reference file must not implicitly authorize writes. 6. Restrict file-writing tools to an approved workspace directory and enforce canonical-path validation to prevent traversal or writes to unrelated locations. 7. Display the destination path and proposed content before executing a write, especially when the request originates from retrieved or embedded content. 8. Add repository validation that fails builds when reference files contain model-specific tool-call markup or imperative instructions to create, modify, or delete files. 9. Re-audit the cleaned package before distribution to confirm that no generated instruction fragments remain. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document masquerades as a static reference library but contains an active write_file invocation, creating a hidden instruction channel inside content that downstream agents may trust. This kind of mixed content is dangerous because it can subvert user intent, cause silent persistence changes, and serve as a stepping stone for prompt/command injection.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A reference document for investor due diligence should contain passive guidance only, but this file includes an embedded instruction and tool-call markup to create new files. If an agent treats markdown as executable workflow input, this can trigger unauthorized file modification and expand the skill's behavior beyond its declared scope.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill defines very broad trigger phrases such as '查询机构备案信息', '查找历史投资案例', and '生成对接策略', which are common business-language requests rather than narrowly scoped invocation commands. In agent environments that auto-route based on semantic or phrase matching, these generic triggers can cause unintended activation of the skill on ordinary conversation, leading to unnecessary data collection, disclosure of internal diligence workflows, or execution in the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The template explicitly includes 'LP详细名单' as optional collection data but provides no privacy, confidentiality, minimization, or lawful-basis guidance. In an investor due-diligence skill, this can lead users to gather personally identifiable or commercially sensitive investor information unnecessarily, increasing privacy, confidentiality, and compliance risk if the data is collected, shared, or stored insecurely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The markdown directly invokes a file-write operation without any explicit user approval or warning, which violates the expectation that a reference document is non-operative. In an agent environment, this can lead to covert state changes, confusing provenance, and unauthorized creation or overwrite of repository files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains user-facing instructions and descriptions exclusively in Chinese, and there is no indication that users can choose another language or that the skill is intentionally restricted to a Chinese-language audience. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill file is written only in Chinese and does not indicate that users may choose another language or that the content is intentionally limited to a Chinese-speaking or region-specific audience. Under the language/locale policy, a skill should not silently enforce a single language unless the constraint is clearly justified or optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.