Back to skill

Security audit

陌拜扫街情报参谋

Security checks for vulnerabilities and agentic risk

Overview

The skill’s sales-prospecting behavior is mostly disclosed, but it also tells agents to persistently rewrite the skill itself from ordinary user feedback, which creates review-worthy risk.

Review before installing. The lead-generation workflow is understandable, but only install it where an agent is allowed to search public business sources and create local output files. Do not let normal users trigger persistent edits to the installed SKILL.md without a separate review step, and sanitize CSV/XLSX cells before opening or sharing generated spreadsheets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/build_roster.py:42
Finding

CSV and XLSX Formula Injection Through Untrusted Business Records

Content
View full analysis

Vulnerability Details

File Location: scripts/build_roster.py, lines 42–49, with dangerous output operations at lines 62–66 and 87–89
Vulnerability Type: Spreadsheet formula injection
Risk Level: Medium

Complete Code Snippet

python
def normalize(row, idx):
    out = [idx]
    for k in KEYS:
        v = row.get(k, "")
        if v is None or str(v).strip() == "":
            v = FILL
        out.append(str(v).strip())
    return out

The normalized values are written directly to CSV:

python
def write_csv(path, data):
    with open(path, "w", newline="", encoding="utf-8-sig") as f:
        w = csv.writer(f)
        w.writerow(HEADERS)
        w.writerows(data)

They are also written directly to XLSX cells:

python
for r in data:
    ws.append(r)

Technical Analysis

The skill collects business information from public maps, directories, recruitment platforms, websites, and similar third-party sources. Fields such as business name, address, contact, business scope, and source are therefore potentially controlled by an external content provider.

normalize() converts these fields to strings but does not neutralize spreadsheet formula prefixes. Values beginning with =, +, -, or @ are passed unchanged to both output formats. When the XLSX workbook is created, a value beginning with = may be stored as a formula. CSV files can likewise be interpreted as containing formulas when opened in spreadsheet applications.

This crosses the trust boundary between untrusted third-party directory content and a spreadsheet interpreter running in the recipient's desktop context.

Attack Path

  1. An attacker publishes or modifies a business-directory field consumed by the skill, such as a business name or contact field, so that it begins with a spreadsheet formula marker.
  2. The skill retrieves that external record and places it into the input JSON used by build_roster.py.
  3. normalize() preserves the formula-prefixe ...[truncated 1127 chars]
Remediation
View remediation

Remediation Suggestions

  1. Introduce a centralized cell-sanitization function for every externally sourced textual value.
  2. If a value begins with =, +, -, or @, prefix it with a single quote or otherwise encode it as literal text according to the target format.
  3. For XLSX output, explicitly force untrusted cells to use the string data type rather than relying only on value prefixing.
  4. Apply the same policy consistently to CSV and XLSX generation.
  5. Consider handling leading tabs, carriage returns, line feeds, and whitespace before formula markers, because spreadsheet applications may normalize them.
  6. Add regression tests covering formula-prefixed values in every externally populated field and verify the resulting CSV and XLSX files contain literal text rather than formulas.
  7. Preserve the original value separately only if required for provenance, and never place an unsanitized version in an interpreted spreadsheet cell.

A suitable defensive pattern is:

python
def sanitize_spreadsheet_cell(value):
    text = str(value).strip()
    if text and text[0] in ("=", "+", "-", "@"):
        return "'" + text
    return text

For XLSX output, additionally set externally sourced cells explicitly as strings.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个完整的扫街情报与线索生成工具,重点能力应包括按区域/行业或锚点地址检索企业、筛选周边目标、组织关联企业、规划拜访路线,并输出可用于陌拜的话术。实际代码并不执行这些核心功能,而只是对外部已准备好的企业 JSON 数据进行整理和导出,附带简单排序、高亮和覆盖率统计。虽然输出字段中包含“建议切入话术”“关联企业”等列,但代码本身既不生成这些内容,也不做路线规划或地理检索。因此其主要行为与声明的主要目的存在实质差异,属于描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 297)May include surrounding context.

md
2. **写入**:直接编辑 `SKILL.md` 对应位置,保持与既有内容风格一致

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The skill explicitly instructs the agent to edit SKILL.md and emit files into output/, but the manifest does not declare a constrained tool scope such as allowed-tools or permissions. This creates an overbroad, implicit file access capability where a user-triggered prospecting skill can also write or alter local files, increasing the chance of unintended file modification or abuse through prompt injection.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The SKILL.md front-matter says to invoke the skill when the user asks for terms like “客户线索”, “目标客户清单”, and “企业联系人查询”, which are broad requests that could match many ordinary sales or research conversations. The file does not provide exclusion conditions or negative examples to distinguish when this skill should activate versus other prospecting or CRM-related skills.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to rewrite its own SKILL.md whenever users suggest process changes, turning an output-generation tool into a self-modifying one. Self-modification is dangerous because adversarial or careless user input can persistently alter future behavior, expand scope, weaken safeguards, or implant prompt-injection instructions into the skill itself.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The iteration section says nearly any user suggestion should trigger a persistent edit to the skill, which is an overly broad activation condition for a state-changing action. This makes it easy for ordinary conversation or adversarial phrasing to cause unauthorized behavioral drift in the skill over time.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs automatic modification of SKILL.md without clearly warning the user that a persistent skill file will be changed. Hidden or insufficiently disclosed state changes undermine user consent and make prompt-injection or social-engineering attacks more effective because the model is encouraged to persist changes silently.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill broadens from prospecting assistance into packaging, distribution, and release-management workflows for the skill itself. This scope expansion increases the attack surface by giving ordinary user interactions a path to influence deployment artifacts and operational packaging processes that should be restricted to maintainers.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The invocation description lists many broad, natural-language trigger phrases such as customer leads, contact lookup, target customer lists, and nearby enterprise visits. This can cause the skill to be invoked for loosely related sales-assistance requests, increasing the chance of overbroad activation, unintended data handling, or bypass of more appropriate tools with narrower scope. In this sales-prospecting context, the risk is elevated because the skill appears designed to gather business leads and contact-oriented intelligence, so accidental invocation could expose or process sensitive business information at scale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description and the rest of the document are framed entirely in Chinese and present fixed Chinese trigger phrases and response patterns, but do not state that the user may choose another language. This can violate language-choice policy when a skill effectively assumes a single language without explicit opt-in or documented locale justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.