Back to skill

Security audit

云指建站GEO优化助手

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent GEO audit purpose, but it needs review because it handles CMS write credentials and documents a way to bypass host validation for CMS mutations.

Install only if you are comfortable reviewing the MCP write-back flow first. Prefer read-only audit mode, avoid storing CMS Bearer tokens in plaintext config, do not use the documented direct JSON-RPC validation bypass, and run the crawler only against sites you intend to audit from a network environment that cannot reach sensitive internal services.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:33
Finding

Mandatory Unrelated Promotional Output Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
references/mcp-tools.md:110
Finding

Instructions Explicitly Bypass Host Tool Validation for CMS Writes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/geo_audit.py:450
Finding

Unrestricted URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
depth: continue visited.add(url) wait = DELAY_FLOOR - (time.time() - last_req) if wait > 0: ...[truncated 2783 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/mcp-tools.md:3
Finding

CMS Bearer Tokens Are Persisted in Plaintext Configuration

Content
View full analysis
.url` 与 `mcpServers..headers.Authorization`,或由会话提供的 MCP 服务注入)。 ``` ```markdown ### 拿到后如何处理 1. **写入配置(单一数据源)**:把地址写入 `mcp.json` 的 `mcpServers..url`,Token 写入 `mcpServers..headers.Authorization`(`Authorization: Bearer `)。若宿主已托管该 MCP 服务,则直接复用会话内已连接的同名服务,无需重复索取。 ``` ```markdown ### 安全红线 - Token 仅由 MCP 客户端放入 `Authorization: Bearer`,**不回显、不落文件(除 `mcp.json` 受信位置外)、不出现在任何报告/日志/截图**。 - 未拿到 Token 前,**只做只读分析,不调用任何写工具**(`save_ai_page` / FAQ 写入工具等)。 - 直连后端脚本(见文末)从 `mcp.json` 读 Token,保持单一数据源;仅可信本地环境使用。 ``` ### Technical Analysis The Skill recommends storing the complete `Authorization: Bearer ` value in `~/.workbuddy/mcp.json`. The guidance identifies the file as trusted but does not require restrictive filesystem permissions, secure secret storage, encryption, token expiration, or limited token scopes. A bearer token grants access to whoever possesses it. Storing it as ordinary JSON increases exposure through local account compromise, permissive file modes, backup systems, support bundles, synchronization software, or accidental repository inclusion. The direct-backend guidance further depends on reading this token from the file, increasing the number of components that may handle the credential. ### Attack Path 1. A user provides an MCP token for CMS modification. 2. The Agent or operator writes the full bearer token into `~/.workbuddy/mcp.json`. 3. The file is created or retained without an enforced restrictive permission mode. 4. Another local process, user, backup mechanism, or accidental file disclosure obtains the configuration. 5. The attacker extracts the bearer token. 6. The attac ...[truncated 669 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guidance explicitly allows synthetic aggregateRating values (ratingValue 4.5–5.0, reviewCount 80–100) as a placeholder, even though ratings are a trust signal that search engines and downstream AI systems may ingest as factual metadata. This creates a direct path for deceptive structured data, and the later disclaimer that it should not be shown on-page does not remove the risk because crawlers can still consume and surface it.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document contains contradictory rules: it declares a global red line against fabricated ratings and other factual fields, but elsewhere authorizes fabricated rating placeholders. Such inconsistency is dangerous in an automation-oriented skill because implementers or agents may follow the permissive instruction and produce deceptive schema that undermines content integrity and could trigger search-engine penalties or mislead AI summaries.

Content

No source excerpt is available for this finding.

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The skill instructs collection and storage of a user-supplied MCP endpoint and bearer token in a user-level config file under ~/.workbuddy/mcp.json. Accessing and modifying persistent credential configuration expands the blast radius beyond the current session, and a malicious or compromised skill could exfiltrate, reuse, or redirect credentials to attacker-controlled endpoints.

Content

Scanner excerpt · references/mcp-tools.md (reported line 3)May include surrounding context.

md
# CMS MCP 写回映射(mcp-tools)

本技能在「目标站为支持 MCP 的 CMS 且需执行修改」时,经 MCP 回写 GEO 优化内容。MCP 地址与 Bearer Token 由用户提供(写入用户级 `~/.workbuddy/mcp.json` 的 `mcpServers.<name>.url` 与 `mcpServers.<name>.headers.Authorization`,或由会话提供的 MCP 服务注入)。

## 向用户索取 MCP 地址与访问 Token(必读,写操作前必做)

MCP Config Access

High
Category
Agent Snooping
Confidence
94% confidence
Finding

The workflow repeats instructions to write the MCP URL and Authorization header into mcp.json as a 'single source of truth.' Persisting live bearer credentials in a general user config file makes credential theft or unintended reuse more likely, especially because the same file is later consumed by direct backend tooling.

Content

Scanner excerpt · references/mcp-tools.md (reported line 27)May include surrounding context.

text

### 拿到后如何处理
1. **写入配置(单一数据源)**:把地址写入 `mcp.json` 的 `mcpServers.<name>.url`,Token 写入 `mcpServers.<name>.headers.Authorization`(`Authorization: Bearer <token>`)。若宿主已托管该 MCP 服务,则直接复用会话内已连接的同名服务,无需重复索取。
2. **验证连通性(必须,写前第一动作)**:调用 `test` 工具进行连通性检测——
   - **通过**:服务可达、鉴权通过,继续用 `tools/list` 确认 `list_page`、`save_ai_page`、FAQ 工具等可用。
   - **失败**:立即停下,向用户反馈「地址或 Token 无效 / 无权限」,**不得猜测重试或降级到伪造数据**。

MCP Config Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

Although the text says the token should not be echoed or logged, it still endorses reading the token from mcp.json for a direct backend script. This normalizes local file-based secret access by auxiliary tooling, which weakens compartmentalization and makes accidental leakage, misuse, or bypass of normal access controls more likely.

Content

Scanner excerpt · references/mcp-tools.md (reported line 37)May include surrounding context.

md
### 安全红线
- Token 仅由 MCP 客户端放入 `Authorization: Bearer`,**不回显、不落文件(除 `mcp.json` 受信位置外)、不出现在任何报告/日志/截图**。
- 未拿到 Token 前,**只做只读分析,不调用任何写工具**(`save_ai_page` / FAQ 写入工具等)。
- 直连后端脚本(见文末)从 `mcp.json` 读 Token,保持单一数据源;仅可信本地环境使用。

## 前置要求(写操作前必做)
1. 已按上文「向用户索取 MCP 地址与访问 Token」完成索取、写入与连通性验证。

MCP Config Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

This line combines two risky behaviors: reading a bearer token from mcp.json and using it to perform raw JSON-RPC calls that bypass host validation. In context, that turns persistent credential access into a practical mechanism for invoking sensitive write/delete tools outside the intended security boundary.

Content

Scanner excerpt · references/mcp-tools.md (reported line 110)May include surrounding context.

md
JSON-LD 中的网址、Logo、图片地址必须是完整 URL(优先 `FnGetHost(1)` 拼接或 `FnGetCurrentUrl()`)。

## 直连后端提示
若宿主 `DeferExecuteTool` 的本地 ajv 校验因 `oneOf`/`coerceTypes` 误拦截带 `pageId` 的写工具(如 `save_ai_page`、`del_page`),可改用直连后端脚本(从 `mcp.json` 读 Token,POST JSON-RPC:`initialize` → `notifications/initialized` → `tools/call`)绕过宿主校验。仅在可信本地环境使用,且仍须遵守上述数据标签与真实数据红线。

## 写后验证
回写后:① 在 CMS 预览确认页面正常;② 重新 `analyze`(或 `validate` 对比基线)确认 GEO Score 提升、schema 类型出现、无模板绑定破坏。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to perform network crawling, local file reads/writes, and page modification workflows, but it does not declare any tool scope or allowed-tools boundaries. This creates an authorization ambiguity where an agent runtime may over-grant capabilities, increasing the chance of unintended network access, filesystem access, or write actions against external systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown states that the skill is limited to Twig version 1.3 and instructs the agent to write with that version in mind. This is a natural-language locale/technology constraint presented as mandatory, but the file does not offer user choice or explain why this fixed version is required for all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document states that industry detection is based on '12 个中文行业词库', which hard-codes a Chinese-language taxonomy rather than offering multilingual handling or user opt-in. This creates a language/locale policy concern because the skill behavior is constrained to Chinese without documenting a justified regional limitation for all use cases.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill guidance, prompts, and operational instructions are written in Chinese, including the copy-paste user-facing wording. There is no indication that users may choose another language or that the Chinese-only constraint is required for a documented region-specific purpose, which can violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document explicitly instructs operators to bypass host-side MCP tool validation by calling the backend JSON-RPC interface directly and reusing the bearer token from mcp.json. Even though it says 'only in a trusted local environment,' this undermines security controls enforced by the host, increases the chance of unsafe tool invocation, and can enable unauthorized or insufficiently validated write/delete operations if the skill or operator is mistaken or compromised.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The request headers hard-code Accept-Language: zh-CN,zh;q=0.9,en;q=0.8, causing the crawler to preferentially retrieve Chinese-localized content regardless of the user's locale. This is a natural-language locale policy concern because the tool imposes a specific language setting without offering opt-in, opt-out, or justification that the tool is region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The crawl routine fetches remote URLs, saves returned HTML pages to disk, and writes a manifest file, but this function and its CLI path do not include a confirmation prompt or clear user-facing warning about those side effects. Although the script's purpose implies crawling, the code itself does not disclose that it will persist site content locally in the chosen output directory.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.