Back to skill

Security audit

门店目标追踪分析

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended for retail target tracking, but it loads unreviewed Python code from a hard-coded local path before running.

Review before installing. The main concern is that the skill imports executable code from a hard-coded local directory outside the package, so you cannot tell from this artifact alone what code will run. Only install after replacing that dependency with a packaged, reviewed client or otherwise verifying and controlling the exact api_client module path.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
analyze.py:11
Finding

Import-Time Arbitrary Code Execution Through an Untrusted External Module Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
analyze.py:143
Finding

API Query-Parameter Injection Through Unencoded Caller-Controlled Values

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

整体上,这段代码的意图与声明高度相关:它加载门店日目标、按日/周/月汇总目标、调用 BI 接口获取实际业绩、计算达成率与风险等级,并提供单店/批量告警检查,基本属于所述的‘门店目标追踪分析工具’。但从审计角度看,存在实质性描述-行为偏差。最重要的是实现错误:analyze_period() 的返回值使用了未定义变量,analyze() 对 analyze_period() 的参数传递也错位,这意味着主要功能按现状并不能可靠工作。其次,描述将预警状态概括为“黄绿黄灯”,而实现是五档风险;同时代码还包含未声明的多层级(区域/省/市/集团)业绩查询能力。最后,T-N 延迟并非整个分析链路的通用配置,而是仅在告警检查中体现。因此应判定为存在 mismatch,主要原因是主能力实现与声明之间存在可用性和范围上的实质不一致。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code prepends an absolute external workspace path to sys.path and imports api_client from there, bypassing normal dependency boundaries. This can load unintended or tampered code from a user-specific filesystem location, creating a code-integrity and supply-chain risk with the privileges of the skill runtime.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill description is written in Chinese and provides no indication that users may interact in other languages or choose a preferred locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill includes explicit file paths and usage patterns that imply local file reading, but it does not declare any tool scope or allowed-tools boundary. In an agent environment, undeclared file access increases the chance of over-broad data exposure, accidental access to unrelated local files, and unclear enforcement of least privilege.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad enough to activate on ordinary business-performance questions, which can cause the skill to run in contexts the user did not clearly intend. In agent systems, over-broad routing can expose local data sources unnecessarily or produce actions based on the wrong skill, increasing the risk of inappropriate data access and misleading outputs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill metadata describes store target tracking, but the implementation can query city, province, region, and group-level BI data. This is a scope-expansion issue: a caller expecting store-only analytics could unintentionally expose broader organizational data if the skill is invoked with different level values.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill constructs an API endpoint and sends it via get_copilot_data, which transmits store and date-scope information over the network. In this file there is no confirmation prompt, user-facing disclosure, or comment/docstring warning that remote data access will occur when the analysis runs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

Natural-language policy requires avoiding forced language or locale constraints unless the user opts in or the restriction is clearly justified. Here, the skill metadata and trigger descriptions are presented solely in Chinese, and the document does not indicate that the skill is region-specific or provide an alternative language option.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code file contains natural-language documentation entirely in Chinese and presents the skill description and example usage in that locale without indicating any user language choice. Under the policy for natural-language violations, forcing a specific language without opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module-level natural-language description specifies the skill entirely in Chinese, which can amount to a forced language/locale choice without user opt-in. No alternate language option or justification for a Chinese-only audience is provided in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.