Back to skill

Security audit

Ai Company Coo 2.0.0

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its COO operations purpose, but it asks for broad file, network, and agent-messaging authority without enough scoping or user control.

Install only if you want a COO-style agent that can maintain operational memory, write OKR/report artifacts, and coordinate with other agents. Before using it with real company data, restrict file access to dedicated memory, OKR, report, and audit-log paths; require explicit approval before reading USER.md or memory files unrelated to the current task; and constrain network or inter-agent messages to approved destinations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
AGENTS.md:7
Finding

Automatic Access to User Profile and Persistent Agent Memory

Content
View full analysis

Vulnerability Details

File Location: AGENTS.md, lines 7-10
Vulnerability Type: Excessive access to persistent user and session data
Risk Level: Medium

Evidence

md
- **每次会话启动时**:
  1. 读取 SOUL.md — 确认 COO 身份与当前职责
  2. 读取 USER.md — 了解 CEO/董事会的最新战略方向
  3. 读取 memory/YYYY-MM-DD.md(今日 + 昨日)— 追踪 OKR 进展与待办

Technical Analysis

The skill instructs the agent to read USER.md and the current and previous daily memory records at the beginning of every session. These reads are mandatory and are not conditioned on whether the requested task requires historical memory, user-profile information, or strategic context.

This behavior violates least-privilege and data-minimization principles. The declared skill interface requires only a task description, but the startup process expands the effective input to include persistent user and organizational data. Such data may include prior tasks, strategic plans, operational risks, or other information unrelated to the current request.

The finding does not establish that data is deliberately exfiltrated. However, once the files enter the active model context, their contents can influence outputs and may be included in reports, tool requests, or inter-agent communications.

Attack Path

  1. A user or another agent activates the COO skill for an ordinary operational task.
  2. The startup instructions cause the agent to read USER.md.
  3. The agent also reads the current and previous daily files under memory/.
  4. Sensitive historical or strategic information enters the active model context even if it is unrelated to the task.
  5. A crafted task, follow-up prompt, or downstream agent request induces the agent to summarize, quote, or forward information from that context.
  6. The unrelated persistent information is exposed through the response, an inter-agent message, or an external report.

Impact Assessment

Exploitation could provide access to user-prof ...[truncated 547 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove unconditional startup reads of USER.md and daily memory files.
  2. Require an explicit task dependency before accessing persistent records.
  3. Ask for user confirmation before reading user-profile or historical-memory files containing sensitive information.
  4. Read only explicitly identified records and only the minimum relevant sections.
  5. Introduce a sensitivity classification and redact credentials, personal information, confidential strategy, and unrelated historical content before adding records to model context.
  6. Prevent persistent-memory content from being included in inter-agent or external messages unless the user separately authorizes the disclosure.
  7. Record the reason, file, requesting task, and destination whenever persistent information is accessed or transmitted.
  8. Treat content loaded from memory as untrusted data rather than executable instructions.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:56
Finding

Unscoped Filesystem Read and Write Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 56-60
Vulnerability Type: Overly broad filesystem authorization
Risk Level: Medium

Evidence

yaml
permissions:
  files: [read, write]
  network: [api]
  commands: []
  mcp: [sessions_send, subagents]

Technical Analysis

The skill requests generic filesystem read and write capabilities without restricting them to the operational files it legitimately maintains. The documented use cases concern a narrow collection of OKR records, progress reports, decision logs, and memory files, but the permission declaration does not provide path-level or operation-level boundaries.

If the runtime interprets this declaration as workspace-wide authorization, a misdirected request, prompt injection in an operational document, or compromised collaborating agent could cause the skill to read or modify unrelated files. Disabling command execution reduces the likelihood of direct arbitrary code execution, but it does not prevent confidentiality loss, data corruption, or modification of configuration and instruction files through the file tools.

The network and inter-agent capabilities increase the potential consequences of excessive read access because file contents placed in context could subsequently be sent through an API or sessions_send. No automatic exfiltration mechanism or malicious endpoint was found, so this finding is limited to the excessive permission boundary itself.

Attack Path

  1. The skill is activated with unrestricted read and write file capabilities.
  2. An attacker supplies a crafted operational request, or malicious instructions are encountered in a document processed by the agent.
  3. The instructions identify an unrelated workspace file and represent it as necessary for an operational report or update.
  4. The agent uses its broad read permission to retrieve the file or its broad write permission to alter it.
  5. Read content may ...[truncated 868 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace generic filesystem permissions with path-scoped allowlists.
  2. Grant read access only to necessary inputs and write access only to dedicated output locations, such as:
    • memory/okr-tracker.md
    • okr/**
    • reports/coo/**
    • logs/coo-decision-log
  3. Separate read and write allowlists so that source instructions and configuration files remain read-only.
  4. Deny access by default to credentials, environment files, unrelated agent memory, repository metadata, and other agents' workspaces.
  5. Require explicit user approval for any file outside the allowlisted operational directories.
  6. Prevent path traversal and resolve symbolic links before enforcing path restrictions.
  7. Apply atomic writes, backups, schema validation, and append-only controls to audit logs.
  8. Log every file access with the resolved path, operation, task justification, and requesting agent.
  9. Add output controls that block file contents from being transmitted through APIs or inter-agent messages without destination-specific authorization.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill file is written in Chinese and provides no indication that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill identity file is written in Chinese, including role descriptors and status metadata, with no indication that users may select another language or that the skill is intended only for a Chinese-language environment. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description and the entire skill guidance are written in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language or China-specific compliance context. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list includes broad, common terms such as “运营”, “OKR”, and “智能化”, which can cause the skill to activate in many unrelated conversations. Because this skill has write, network, and MCP messaging capabilities, accidental invocation could lead to unintended operational guidance, file changes, or cross-agent actions beyond the user's intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest grants file write and network API access, plus MCP capabilities like sessions_send and subagents, but the description does not clearly warn users that the skill can modify files or communicate externally. In an agent setting, this increases the risk of users invoking a governance/planning skill without understanding that it can persist data, route messages, or trigger downstream actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown skill specifies all role instructions, workflows, and operational policies in Chinese, but it does not indicate that the user may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the language/locale policy rule, forcing a single language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description is written entirely in Chinese and presents the skill identity and functionality in that language without indicating that users can choose another language or that the skill is intended only for a Chinese-speaking or region-specific context. This creates a natural-language locale policy issue because it implicitly enforces a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document is explicitly a COO skill file, but the section header says "CHO 强制 KPI" and the table beneath appears to define performance metrics for this skill. That inline documentation contradicts the surrounding identity and purpose of the file, creating intent ambiguity about whether the metrics apply to COO or CHO.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.