Back to skill

Security audit

DW-Copilot

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent data-warehouse assistant, but its metadata collection guidance can overreach into broad database, API, web, or HDFS metadata using sensitive credentials.

Install only if users understand this is for a Chinese-language data warehouse environment. Require explicit table allowlists or explicit approval before any whole-database or recursive metadata collection, use HTTPS only, provide read-only scoped credentials through protected secret mechanisms, and avoid pasting live cookies or passwords into generated files or chat.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
resources/conventions/metadata-config.md:40
Finding

Metadata Collection Defaults Permit Excessive Database and Filesystem Enumeration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
resources/conventions/metadata-config.md:115
Finding

Metadata Collection Guidance Allows Insecure Transport and Plaintext Web Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
- **规范缺失时主动询问并更新**:公约文件未明确记录的能力或规范,必须询问用户确认,不得臆想;确认后补充到对应公约文件(平台能力 → `platform-conventions.md`,团队约定 → `project-conventions.md`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
- **规范缺失时主动询问并更新**:公约文件未明确记录的能力或规范,必须询问用户确认,不得臆想;确认后补充到对应公约文件(平台能力 → `platform-conventions.md`,团队约定 → `project-conventions.md`)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description and all user-facing instructions in SKILL.md are written entirely in Chinese, with no indication that users may choose another language. Under the policy, a skill that effectively enforces a specific language without opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Line L125 states that all fields must use Chinese descriptions, which is a natural-language locale requirement. The file does not offer user opt-in or explain that this convention is limited to a justified region-specific or compliance-specific context, so it appears to force a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown template is written entirely in Chinese and labels itself as a standard template, which implies a fixed language requirement for skill/task documentation. Under the stated policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file is entirely written in Chinese and explicitly states that this file is the only authoritative source for metadata collection method definitions. This can constitute a language policy issue because it forces a specific language for operational use without documenting any user choice, opt-in, or locale justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file contains natural-language instructions and conventions, and the title immediately shows the document is written in Chinese only. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in or a documented justification is a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.