Back to skill

Security audit

Cn Lead Safety

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese-market intelligence QA helper; its citation checker is imperfect, but the package does not show hidden execution, persistence, exfiltration, or destructive behavior.

Install only if you want Chinese-market lead-discovery markdown to follow these sourcing and citation conventions. Treat the bundled verifier as a helpful citation-presence check, not proof that every number is accurate or every source is authoritative; review important financial figures manually against primary filings or trusted MCP data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verify_intelligence.py:69
Finding

Citation Verification Can Be Bypassed with Unrelated or Untrusted Citation Tokens

Content
View full analysis

Vulnerability Details

File Location: scripts/verify_intelligence.py, lines 69-72 and 124-169
Vulnerability Type: Insufficient semantic validation / integrity-control bypass
Risk Level: Medium

Complete Code Snippet

python
OFFICIAL_ANCHORS = (
    "http://", "https://",
)
python
def citation_window(line: str, next_line: str | None) -> str:
    return line + "\n" + (next_line or "")


def has_any(window: str, anchors: tuple[str, ...]) -> bool:
    return any(a in window for a in anchors)


def classify(window: str) -> str:
    """Return 'mcp' | 'official' | 'media' | 'forbidden' | 'none'."""
    if has_any(window, FORBIDDEN_ANCHORS):
        return "forbidden"
    if has_any(window, MCP_TOOL_ANCHORS):
        return "mcp"
    # Tushare cited without the aigroup-market-mcp prefix still traces to
    # the same installed tool — classify as mcp, not media.
    if "Tushare" in window or "tushare" in window:
        return "mcp"
    if has_any(window, OFFICIAL_ANCHORS):
        return "official"
    if has_any(window, MEDIA_ANCHORS):
        return "media"
    return "none"


def scan(text: str, strict_mcp: bool = False) -> list[tuple[int, str, str, str, str]]:
    """Return list of (line_no, number, unit, snippet, reason) failing the gate."""
    lines = text.splitlines()
    failures: list[tuple[int, str, str, str, str]] = []
    for i, line in enumerate(lines):
        next_line = lines[i + 1] if i + 1 < len(lines) else None
        window = citation_window(line, next_line)
        for m in HARD_NUMBER.finditer(line):
            verdict = classify(window)
            if verdict == "none":
                failures.append(
                    (i + 1, m.group(1), m.group(2),
                     line.strip()[:120], "no citation")
                )
            elif verdict == "forbidden":
                failures.append(
                    (i
...[truncated 3321 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove generic http:// and https:// strings from OFFICIAL_ANCHORS.
  2. Parse URLs with a standard URL parser and allowlist exact authoritative hostnames, including controlled subdomain handling. Reject user-info tricks, suffix confusion, redirects to untrusted domains, malformed hosts, and non-HTTPS links where HTTPS is available.
  3. Require each hard number to have a citation in the same sentence, structured footnote, or explicit claim-to-source identifier rather than accepting any token on the next line.
  4. Validate footnote references bidirectionally: the claim must reference an existing footnote, and that footnote must contain an allowed source associated with the claim.
  5. In strict mode, accept only validated MCP provenance records or URLs whose normalized host is on the official-source allowlist.
  6. Do not classify a line solely through broad substring matching. Parse citation syntax and preserve the source type, URL, publication title, filing date, and claim association as structured data.
  7. Add negative tests covering arbitrary URLs, unrelated next-line links, invalid URLs, deceptive subdomains, multiple unrelated numbers on one line, and citation tokens embedded in ordinary prose.
  8. Add a regression test asserting that the illustrative attack input fails in both default and strict modes.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill claims to enforce multiple safety guarantees, but the described attached verifier appears to check only nearby citations for hard numbers. That gap can cause operators or downstream agents to overtrust outputs as validated when key controls like UTF-8 literal enforcement, lexicon validation, tier-ordered sourcing, and anti-fabrication checks are not actually enforced, enabling fabricated or low-integrity intelligence to pass as 'safe.'

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file states that when lead-discovery output "走中文输出" it must follow these rules, and the description emphasizes enforced literal Chinese text for downstream deliverables. This establishes a language constraint, but the document does not offer the user a language choice or clearly justify a mandatory Chinese-only locale policy for all applicable uses.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is broad enough to activate on ordinary mentions of Chinese markets, company names, tickers, or data sources, even when the user did not ask for this skill. Overbroad auto-invocation can unexpectedly steer agent behavior, force a different workflow, and cause inappropriate file/script access or policy application in unrelated tasks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.