Back to skill

Security audit

geo-quickhook

Security checks for vulnerabilities and agentic risk

Overview

This sales-report skill is not a backdoor, but it deserves Review because it sends business inputs to external LLMs, can share reports through Feishu, and can produce misleading or unsafe HTML reports.

Install only if users understand that brand, competitor, and keyword data may be sent to the configured LLM provider and that reports may be shared externally through Feishu. Use a vetted endpoint, avoid confidential customer data unless approved, review the generated HTML before sending it, and treat the five-engine claims cautiously unless separate engine credentials and provenance are configured.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/quick_hook.py:228
Finding

Stored HTML Injection in Generated Reports

Content
View full analysis
{label}" ``` `scripts/quick_hook.py`, lines 318-332: ```python fatal_text = ( f'⚠️ For queries related to "{kw}", ' f'{brand} achieves only a ' f'{brand_score}% average top-3 visibility rate across 5 AI engines, ' f'while the industry average is already {industry_avg}% (current rank: #{brand_rank})' f'{citation_hook}' ) cards_html += f'''
🔍 "{kw}" · AI Top-3 Visibility Competitive Analysis (5 Engines)
{table_html} ``` `scripts/quick_hook.py`, lines 361-378: ```python return f''' GEO Quick Hook · {brand} * {{ box-sizing:border-box; margin:0; padding:0; }} bod ...[truncated 2992 chars]
Remediation
View remediation
{safe_label}" ) ``` 3. Escape all brand, competitor, keyword, engine, and citation strings used in: - Element text - The document title - Table cells - Warning messages - Dynamically generated labels 4. Prefer a maintained template engine configured with automatic HTML escaping rather than assembling the document with f-strings. 5. Add conservative input limits for brand names, competitors, and keywords. Reject control characters and unexpectedly long inputs. Character restrictions may provide defense in depth but must not replace output encoding. 6. Add regression tests using payloads containing tags, quotes, ampersands, and event handlers. Verify that generated reports contain encoded text such as `<` and do not create executable DOM elements. 7. Consider using a dedicated, isolated browser profile for untrusted generated reports and avoid exposing unrelated files through the same local HTTP server directory. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The UI and report text claim data was collected from '5 major AI engines,' but the implementation may send all requests to the same OpenAI-compatible endpoint and model. That discrepancy is a significant integrity issue and, in sales context, can deceive users into trusting a fabricated competitive comparison.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README describes sending brand and competitor inputs to OpenAI-compatible endpoints but does not warn users that potentially sensitive commercial data will be transmitted to third-party services. In a sales context, competitor lists, signing keywords, and client brand-performance data may be confidential, so the omission can lead to uninformed disclosure and compliance issues.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill is explicitly configured to use an external OpenAI-compatible API endpoint, which means user-supplied brand, competitor, and sales-analysis data may leave the local environment. External transmission is contextually sensitive here because the tool is aimed at pre-sales competitive intelligence and could process confidential business information without strong disclosure or endpoint restrictions.

Content

Scanner excerpt · README.md (reported line 23)May include surrounding context.

bash
export LLM_API_KEY="your-api-key-here"
export LLM_BASE_URL="https://api.openai.com/v1"   # or any OpenAI-compatible endpoint
export LLM_MODEL="gpt-4o"                          # or your preferred model

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented trigger phrases are broad and semantically fuzzy, such as '快速分析' and '给销售出个报告', which can cause accidental or unintended skill activation in unrelated conversations. Because this skill sends business-sensitive brand and competitor data to external AI services and is designed to generate persuasive sales material, unintended invocation increases the chance of unauthorized data processing and manipulative output generation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares executable behavior involving environment variables and file generation but does not declare any explicit tool scope or permissions boundary. That makes the runtime capabilities ambiguous and increases the chance an agent can access secrets or write files beyond what a user expects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are broad sales-language phrases like '快速分析' and '给销售出个报告', which are likely to appear in normal conversation and can cause unintended activation. Because the skill performs data collection, report generation, and external transmission steps, accidental invocation could expose business data or initiate actions the user did not intend.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to configure API credentials and then send generated output through Feishu, but it does not provide any privacy notice, consent checkpoint, or data-handling warning. In practice, this can transmit client names, competitor analysis, screenshots, and possibly sensitive business context to third-party services without explicit approval.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill explicitly configures an external API endpoint and is designed to send prompt content to that service. External transmission is not inherently malicious, but in this context the absence of disclosure and data-minimization controls means user-supplied client and competitor information may be sent off-platform unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

Environment variables must be set in advance:

bash
export LLM_API_KEY="your-api-key-here"
export LLM_BASE_URL="https://api.openai.com/v1"
export LLM_MODEL="gpt-4o"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

Usage example:

bash
export LLM_API_KEY="sk-xxxx"
export LLM_BASE_URL="https://api.openai.com/v1"
export LLM_MODEL="gpt-4o"

python3 quick_hook.py \

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill transmits user-supplied brand names, competitor lists, and keywords to an external LLM endpoint, which can expose potentially sensitive business information to a third party. In this context, the risk is heightened because pre-sales competitive analysis may involve confidential client strategy or prospect data, and the endpoint is configurable to any OpenAI-compatible service.

Content

Scanner excerpt · scripts/quick_hook.py (reported line 17)May include surrounding context.

python
# Read API configuration from environment variables (supports any OpenAI-compatible API)
LLM_API_KEY = os.environ.get("LLM_API_KEY", "")
LLM_BASE_URL = os.environ.get("LLM_BASE_URL", "https://api.openai.com/v1")
LLM_MODEL = os.environ.get("LLM_MODEL", "gpt-4o")

if not LLM_API_KEY:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code presents five named 'engines' but all entries use the same API key, base URL, and model, so the apparent multi-engine comparison may actually be one backend queried repeatedly under different labels. In this pre-sales skill, that is dangerous because it can create materially false evidence used to influence purchasing decisions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The report intentionally includes coercive, fear-based sales messaging such as urgency, credibility-gap warnings, and statements designed to pressure a prospect into signing. In this skill context, that goes beyond neutral analysis and can mislead recipients or be used for manipulative social engineering in customer-facing materials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code performs a file write to a user-visible location by creating an HTML report on the Desktop. While the action is part of the script's purpose, there is no explicit user-facing warning in the argument help, docstring, or comments near execution that a file will be created there.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The activation examples prominently include Chinese phrases, and the README does not state that other languages are supported or that Chinese is required for a justified region-specific use case. This can constitute a language-policy issue because it implicitly biases invocation toward a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description specifies Chinese trigger phrases and mixed-language operational text, but does not indicate that other languages are supported or that the Chinese locale is a deliberate, documented constraint. This can violate a language/locale policy when users are not given an opt-in choice or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The HTML template fixes the document language to English and all user-facing report text is emitted in English. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy issue when no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.