Back to skill

Security audit

Contract Clause Extractor

Security checks for vulnerabilities and agentic risk

Overview

This skill claims to analyze contracts, but its script can produce canned legal-risk conclusions without actually reading the contract content.

Do not rely on this skill for real contract review unless it is clearly treated as a demo. It does not show evidence-based extraction, so its risk ratings, parties, clause counts, and negotiation suggestions may be fabricated; use a real parser/reviewer and qualified legal counsel for actual contracts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
" [ -f "$file" ] || die "File not found: $file" echo "=== Clause Segmentation ===" echo "File: $file" echo "" echo "Detecting clause boundaries (Article / Section / 第X条 / 1.1)..." local clauses_found=$(( RANDOM % 20 + 10 )) echo "Found $clauses_found clauses" echo "" echo "Next: contract-clause-extractor.sh classify $file" } ``` Classification returns fixed counts unrelated to the supplied contract: ```bash cmd_classify() { local file="${1:-}" [ -z "$file" ] && die "Usage: contract- ...[truncated 5680 chars]:101
Finding

Fabricated Contract Analysis Produced Without Inspecting Contract Content

Content
View full analysis
" [ -f "$file" ] || die "File not found: $file" echo "=== Clause Segmentation ===" echo "File: $file" echo "" echo "Detecting clause boundaries (Article / Section / 第X条 / 1.1)..." local clauses_found=$(( RANDOM % 20 + 10 )) echo "Found $clauses_found clauses" echo "" echo "Next: contract-clause-extractor.sh classify $file" } ``` Classification returns fixed counts unrelated to the supplied contract: ```bash cmd_classify() { local file="${1:-}" [ -z "$file" ] && die "Usage: contract-clause-extractor.sh classify " [ -f "$file" ] || die "File not found: $file" echo "=== Clause Classification ===" echo "File: $file" echo "" echo "Classified clauses across 12 standard categories:" echo " Payment Terms 1 clause(s)" echo " Delivery/Performance 2 clause(s)" echo " Breach & Penalties 1 clause(s)" echo " Confidentiality 2 clause(s)" echo " Intellectual Property 1 clause(s)" echo " Non-Compete / Non-Solicit 1 clause(s)" echo " Jurisdiction & Dispute Resolution 2 clause(s)" echo " Termination 2 clause(s)" echo " Force Majeure 1 clause(s)" echo " Liability & Indemnity Caps 2 clause(s)" echo " Acceptance Criteria 1 clause(s)" echo " Renewal & Term 1 clause(s)" echo "Total: 17 classified clauses" echo "" echo "Next: contract-clause-extractor ...[truncated 4522 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The metadata and help text advertise bilingual extraction and contract PDF processing, but the implementation largely returns static demo text and canned translations rather than analyzing documents. Because the skill is positioned as a legal-risk extraction tool, this mismatch is especially dangerous: users may rely on false summaries for contract negotiation, compliance, or risk acceptance decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script presents itself as a contract clause extractor and risk annotator, but many commands emit fixed, sample-like results unrelated to the supplied file. In a legal-review workflow, this can mislead users into trusting fabricated classifications or risk summaries, causing incorrect business or legal decisions based on nonexistent analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language description emphasizes bilingual CN/EN support and repeats CN/EN-only handling elsewhere, which can amount to a locale constraint. While the domain may often involve Chinese and English contracts, the document does not clearly frame this as an explicit user opt-in or narrowly justified regional limitation in the primary description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This JSON includes bilingual category fields such as name_zh alongside English names, but the file provides no natural-language indication that Chinese output is optional, user-selected, or required for a region-specific workflow. Because SQP-3 applies to all file types and covers language/locale policy concerns, embedding a specific locale without opt-in or justification is a policy-quality issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.