Back to skill

Security audit

胡田 OPC导师 大赛标准化打分

Security checks for vulnerabilities and agentic risk

Overview

This skill is not proven malicious, but it asks agents to perform broad background checks and sensitive scoring workflows without clear consent, privacy boundaries, or reliable implementation.

Install only if you have explicit authority to process participant materials and any external checks. Treat the online verification module as requiring separate consent and source-by-source disclosure, avoid non-public social-security or tax records, and manually review all scores before using them in decisions. Do not rely on the included batch script as-is for real judging because it does not actually parse the submitted documents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
templates/打分报告模板.md:194
Finding

Forced Product Attribution in Generated Reports

Content
View full analysis

Vulnerability Details

File Locations:

  • templates/打分报告模板.md:194
  • templates/排名表模板.md:209

Vulnerability Type: Forced output manipulation
Risk Level: Medium

Complete Vulnerable Snippets

English rendering of templates/打分报告模板.md:194:

markdown
*This report was automatically generated by "Hu Tian - OPC Mentor - Competition Standardized Scoring Skill".*

English rendering of templates/排名表模板.md:209:

markdown
*This ranking table was automatically generated by "Hu Tian - OPC Mentor - Competition Standardized Scoring Skill".*

Technical Analysis

The bundled output templates unconditionally append author and product branding to generated reports. The attribution is not tied to a user-selected option and is unrelated to the core scoring result.

When the Skill uses these templates, the fixed text becomes part of official user-facing competition documents. This alters the output independently of the user's requested content and creates persistent promotional attribution whenever a report or ranking table is generated.

This is classified as instruction hijacking because the Skill package imposes content on the agent's final output rather than restricting itself to the requested analysis. The behavior does not alter system safety constraints, execute code, or persist across unrelated sessions.

Attack Path

  1. A user loads the Skill and requests a project report or ranking table.
  2. The Skill selects one of the bundled Markdown templates.
  3. Project-specific values are inserted into the template.
  4. The fixed attribution remains in the completed document.
  5. The branded statement is presented as part of the user's official output without separate consent.

Impact Assessment

The behavior can:

  • Insert unwanted promotional attribution into official evaluation documents.
  • Misrepresent who prepared or approved a report.
  • Reduce output neutrality.
  • Cause reputat ...[truncated 209 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove fixed author and product attribution from both templates.
  2. If attribution is required, expose an explicit option such as include_attribution, disabled by default.
  3. Inform the user before adding attribution to an exported document.
  4. Keep metadata separate from the substantive scoring report.
  5. Add tests confirming that reports contain no branding unless the user expressly enables it.

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:1087
Finding

Local-Only Privacy Assurance Conflicts with External Background-Investigation Workflow

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:1087, 1342, 1508, 1554, 1583
Vulnerability Type: Excessive and insufficiently authorized sensitive-data investigation
Risk Level: High

Complete Relevant Snippets

English rendering of SKILL.md:1087:

markdown
2. **Data privacy**: All documents are processed locally and will not be uploaded to external servers.

English rendering of SKILL.md:1342:

markdown
**Truth-seeking and pragmatism**: Information in business plans varies in quality and requires multidimensional online verification to ensure review quality. This module implements fully automated company background investigation and information cross-validation.

English rendering of SKILL.md:1508:

markdown
| Education authenticity | Query through the national higher-education verification service | Person not found |

English rendering of SKILL.md:1554:

text
Social-security record: verified as authentic

English rendering of SKILL.md:1583:

markdown
| Revenue growth trend | Annual business reports and tax data | Business-growth authenticity |

Technical Analysis

The Skill gives an unconditional assurance that documents remain local, but later defines a fully automated online background-investigation workflow. That workflow includes founder education, employment history, social-security records, company tax-related data, litigation, and other risk information.

External verification does not necessarily require uploading an entire document, but it generally requires transmitting identifiers extracted from that document, such as a founder's name, company name, education details, or employment history. The local-only statement does not disclose this distinction.

The instructions also fail to define:

  • Explicit consent requirements.
  • A lawful basis for processing personal information.
  • A restriction to public and authorized data ...[truncated 2275 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the unconditional local-only statement with an accurate data-flow disclosure.
  2. Require explicit, informed consent before any external verification.
  3. Limit verification to identified public sources that permit automated access.
  4. Prohibit access to private social-security, tax, education, or employment records unless the subject has provided documented authorization and access is legally permitted.
  5. Display every external destination and the exact fields that will be transmitted before making a request.
  6. Apply data minimization, purpose limitation, retention limits, and secure deletion.
  7. Separate public company verification from personal founder investigation.
  8. Add role-based access controls and auditable logs for sensitive queries.
  9. Do not use background-investigation results for automatic score changes without human review and an appeal process.
  10. Clearly mark the network-verification module as unimplemented until compliant integrations exist.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document claims all files are processed locally and never uploaded externally, but later specifies extensive online verification against external services. This is a security and trust issue because users may provide sensitive company, founder, and financial documents under a false assumption that no external lookups or data disclosures will occur.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The networking verification module directs the agent to compile detailed personal background, litigation, qualification, and business records from many external sources into consolidated reports. This kind of dossier-building materially increases privacy and compliance risk, and the context makes it more dangerous because competition evaluation may not provide a clear legal basis or informed consent for invasive background investigation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The batch processor does not parse or inspect the supplied documents at all and instead scores a hardcoded placeholder string. In a judging workflow, this silently produces fabricated results that appear legitimate, which can mis-rank submissions and undermine decision integrity at scale.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes behaviors that generate multiple output files and batch exports, implying file write capability, but it does not declare any explicit tool scope or permission boundaries. That mismatch can cause an agent runtime to grant broader-than-expected access or leave operators unaware that the skill may create or overwrite local files.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs the system to extract and structure sensitive founder, team, equity, revenue, and financing data from uploaded documents, but it does not define safeguards such as minimization, masking, retention limits, or access control. In a competition-review context, these materials may be highly confidential, so overcollection and broad reporting increase the risk of unnecessary exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes broad external lookups and aggregation of sensitive founder, company, qualification, and litigation data without a clear consent model, privacy notice, or limits on data use. This creates privacy, compliance, and data-minimization risks, especially when submitted competition materials may contain non-public personal and business information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill markets itself as AI-based standardized batch scoring, but the implementation is only a simple keyword-matching heuristic and does not perform meaningful analysis of document quality. This mismatch is dangerous because users may place unwarranted trust in automated rankings for high-stakes competition judging, leading to unfair or misleading outcomes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown template is entirely written in Chinese and presents a fixed-output reporting format with Chinese section headers and labels. Under the policy, forcing a specific language without offering the user a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template explicitly assigns a stigmatizing '忽悠指数' and publishes risk tiers such as '高风险项目清单', which can create reputational harm for participants if the score is inaccurate, subjective, or insufficiently explained. In the context of competition judging, this is more dangerous because the output may be treated as authoritative and shared with decision-makers or organizers without any caution about bias, uncertainty, appeal, or human review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language instructions and usage guidance are presented only in Chinese, and the file does not indicate that users may choose another language or that the skill is restricted to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a reportable locale/language violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill description, commands, outputs, and examples are written in Chinese, and there is no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and scoring criteria only in Chinese, with no note that the language is optional, user-selected, or justified by a specific regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This Python skill is written and labeled entirely in Chinese, and there is no natural-language indication that users may choose another language or that the skill is restricted to a Chinese-only context. Under the policy rule for language/locale constraints, forcing a specific language without opt-in can be a policy violation when not explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

All headings, labels, and boilerplate in the template are fixed in Chinese, with no indication that users may select another language or locale. Under the stated policy, hard-coding a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.