Back to skill

Security audit

Data Quality Audit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a transparent financial QA workflow with expected data-fetching and report-writing behavior, and I found no hidden persistence, credential use, or destructive actions.

Install only if you want a China-market financial deliverable QA workflow. Review the generated audit report manually, especially FLAG/FAIL decisions, because the rule matching and source comparisons can still produce false positives or miss context-specific accounting issues.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to perform an independent cross-source audit with PASS/FLAG/FAIL output, but the implemented behavior reportedly only parses markdown tables and does not actually refetch, verify, or generate the promised audit artifacts. In a financial QA context, this can create false assurance that a deliverable was independently audited when it was not, allowing material data errors to pass through client-facing workflows.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The rules rely on broad metric-name substrings in applies_to, which can cause the audit script to match the wrong provenance rows or unrelated fields. In a QA skill that emits PASS/FLAG/FAIL decisions, this can produce false failures or false passes, undermining the integrity of the audit and potentially allowing incorrect financial deliverables to be approved or valid ones to be blocked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Most rule descriptions and many applies_to values are written only in Chinese, which imposes a specific language/locale in the skill content. The file does not offer a language choice or document that the skill is intentionally limited to a Chinese-language or region-specific workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description and title explicitly scope the skill to "CN banker" deliverables and present the skill in Chinese, but do not state that this locale restriction is optional or user-selectable. This can be a natural-language locale policy issue because the skill appears to enforce a specific regional/language context without an explicit opt-in in the file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring consistently describes this file as a helper for the data-quality-audit skill, but the argparse description string claims it is for 'lead-discovery / data-quality-audit'. That inline documentation misstates the skill identity and can mislead operators about the script's intended use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.