Back to skill

Security audit

Hutian Opc Investor Roadshow

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent investment-promotion and due-diligence toolkit, with clear business-data handling risks that users should manage outside the skill.

Use this skill only for authorized investment-promotion or due-diligence work. Treat collected phone numbers, emails, WeChat IDs, financials, contracts, bank records, and technical materials as confidential, store them only in approved systems, limit access and retention, and verify policy or scoring outputs before making business decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly guides collection of company information from third-party sources including工商信息、舆情、财务数据、专利和融资历史, but provides no privacy notice, data minimization guidance, retention limits, or authorization checks. In a招商/尽调 context this can lead users to aggregate sensitive business and possibly personal data without a lawful basis, creating privacy, confidentiality, and misuse risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The CRM follow-up module describes tracking contact stages, engagement timing, and conversion funnel data, but does not warn about consent, storage protection, access control, or limits on use of contact histories. This creates a realistic risk of unauthorized profiling or insecure storage of business contact and engagement data during招商 operations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions, labels, and examples only in Chinese, with no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-only regional context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The rubric states that annual revenue of 500-1000万 scores 2-3/8 (L117) and A轮 scores 2-3/6 (L126), but the example assigns 800万 a score of 5/8 and A轮后 a score of 4/6. The total is also labeled B+级 even though the defined result table only includes A/B/C/D/E grades (L174-L180), so the example actively conflicts with the documented scoring model rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script explicitly prompts a prospect to disclose potentially sensitive business information such as team size, revenue scale, and financing stage without any guidance on consent, data minimization, or secure handling. In a招商/lead-generation skill, this normalizes collecting commercially sensitive data during outreach and increases the risk of privacy violations, over-collection, and misuse or leakage of confidential business information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template explicitly solicits personal and business data such as names, job titles, mobile numbers, email addresses, WeChat IDs, decision-making influence, and company profile details, but provides no privacy notice, lawful basis, retention guidance, access controls, or handling restrictions. In a招商/CRM context this materially increases the risk of over-collection, unauthorized sharing, and non-compliant processing of sensitive contact and commercial information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The service ledger and follow-up sections are designed for ongoing accumulation of enterprise records, feedback, policy payout details, and development updates, which can contain both personal information and sensitive operational/commercial data. Because the skill gives no warning or safeguards around confidentiality, purpose limitation, retention, or secure recordkeeping, it could normalize storing sensitive data in an uncontrolled way over time.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file hard-codes the generated report text entirely in Chinese, including headings, field labels, and ratings. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a locale/language policy issue because users cannot select another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains user-facing natural-language descriptions and report text exclusively in Chinese, including the module docstring and generated output. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documentation is entirely in Chinese, including the title, description, and usage instructions, with no indication that users may choose another language or that the skill is limited to a Chinese-region context for compliance or operational reasons. This can conflict with language/locale policy requirements when a skill implicitly mandates a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The skill description and the entire operating guidance are presented only in Chinese and targeted to a specific local audience, but the file does not state that the language/localization constraint is intentional or offer an opt-in language choice. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown template presents all instructions, labels, and report text exclusively in Chinese, with no indication that users may choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.