Back to skill

Security audit

会议纪要验真器|定了啥,谁真接活了?

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for Chinese meeting-minutes review, but its Markdown renderer can let meeting text alter the generated minutes document.

Review generated Markdown carefully before sharing or pasting it into Feishu or another Markdown-capable tool. Prefer the HTML output when possible, and do not use this skill for externally shared or high-stakes meeting records unless Markdown escaping is fixed or the source text is trusted and sanitized.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/render_receipt.py:136
Finding

Unescaped Meeting Content Enables Markdown Document Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/render_receipt.py:136-145, 285-297, 565-588, 625-639, 665-685
Vulnerability Type: Unescaped untrusted content in Markdown output
Risk Level: Medium

Vulnerable Code

python
def _md_list(items: list[str], empty: str) -> str:
    if not items:
        return f"- {empty}"
    return "\n".join(f"- {item}" for item in items)


def _md_numbered(items: list[str], empty: str) -> str:
    values = items or [empty]
    return "\n".join(f"{index}. {item}" for index, item in enumerate(values, start=1))
python
for evidence in item["evidence"]:
    locator = evidence.get("timestamp") or evidence.get("paragraph")
    quotes.append(
        f"> [{locator}] {evidence['speaker']}:\n"
        f"> “{evidence['quote']}”"
    )
python
values = {
    "title": view["title"],
    "confirmed_decisions": _md_list(
        view["confirmed"], view["decision_empty"]
    ),
    "owned_commitments": _md_list(
        view["owned"], "暂无明确接下项。"
    ),
    "open_loops": _md_list(
        view["open_loops"], "当前没有待确认事项。"
    ),
    "confirmation_message": view["confirmation_message"],
    "evidence": _evidence_markdown(data, view["neutral"]),
}
return _replace(template, values).rstrip() + "\n"

The same unsafe pattern is used by the personal and executive Markdown renderers:

python
values = {
    "title": view["title"],
    "current_decisions": _md_list(
        view["current_decisions"], "本场未形成明确结论。"
    ),
    "commitments": _md_list(
        view["commitments"], "会议材料未提供可核对的执行事项。"
    ),
    "confirmation_message": view["confirmation_message"],
    "evidence": view["evidence"],
}
return _replace(template, values).rstrip() + "\n"
python
values = {
    "title": view["title"],
    "executive_summary": view["executive_summary"],
    "decisions": _md_numbered(
        view["decisions"], "本场未形成明确结论。"
    ),
    "progress": _md_numbered(
        view["progress"], "会议材料未提供已确认的责任事项。"
    ),
    "risks":
...[truncated 3129 chars]
Remediation
View remediation

Remediation Suggestions

  1. Implement a context-aware Markdown escaping function for all untrusted scalar values. At minimum, neutralize backslashes, backticks, asterisks, underscores, braces, brackets, angle brackets, parentheses, hash signs, plus signs, hyphens, periods in list contexts, exclamation marks, pipes, and blockquote markers.

  2. Normalize or reject embedded carriage returns and line feeds before inserting source-derived values into headings, list items, blockquotes, and numbered lists. If multiline evidence must be retained, prefix every resulting line with the intended quotation marker after sanitization.

  3. Block raw HTML in source-derived fields rather than relying on downstream Markdown-renderer configuration.

  4. Validate links and image targets with an explicit allowlist. Reject dangerous schemes such as javascript:, data:, and file:. Consider disabling all source-derived links and images because they are unnecessary for the meeting-audit workflow.

  5. Keep trusted template Markdown separate from untrusted text. Apply escaping when constructing _decision_text, _commitment_text, _open_loop_text, and evidence blocks, or immediately before each value is inserted into a Markdown context.

  6. Add defense-in-depth validation that detects prohibited Markdown constructs in receipt fields. Rendering-time escaping must remain the primary control because schema validation alone is context-insensitive.

  7. Add regression tests covering:

    • Injected headings and horizontal rules.
    • Multiline unordered and numbered lists.
    • Markdown links and images.
    • Raw HTML tags.
    • Blockquote termination.
    • Backtick and fenced-code injection.
    • Unsafe URL schemes.
    • Embedded newline and carriage-return payloads.
    • Speaker, locator, title, confirmation-message, decision, task, and risk fields.
  8. Preserve the existing use of html.escape() for HTML rendering and add a restrictive Content Security Policy to standalone HTML as addit ...[truncated 23 chars]

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向会议内容理解与责任/决议判定的技能,核心能力应包括语义分类、证据摘录、行动项责任归属和纪要生成。代码却只做结构化 JSON 中截止日期表达的解析与标准化,依据 meeting.date 将中文日期短语转换为 ISO 日期,并生成解析报告。这可能是会议行动项处理流水线中的辅助步骤,但从该代码片段本身看,其主要目的与声明的主要功能明显不同,且缺少声明中几乎所有关键能力。因此属于明显不匹配,而不是仅仅的底层支持实现细节。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill analyzes meeting transcripts/notes to determine commitment status, task ownership, and action items with evidence quotes. The supplied code does none of that. It contains regex-based sanitization logic for credentials and contact information, supports redacting exact custom terms, reads/writes files or stdin/stdout, and can generate a redaction summary report or exit with failure if sensitive content is found. This is a materially different primary purpose, not a supporting implementation detail of meeting-minutes verification. Therefore the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a content-understanding skill: given meeting transcripts, notes, or records, it should determine what was decided, who committed to tasks, distinguish nuanced statuses like confirmed/provisional/proposed/unconfirmed/'I’ll take a look', and provide quote evidence while generating usable minutes. The supplied code does not implement that extraction or summarization behavior. Instead, it validates whether an already-produced JSON 'receipt' conforms to a schema and semantic business rules. It checks IDs, required fields, allowed enums, evidence object shape, summary counts, cross-references, close-status consistency, and safety/redaction properties. This is a materially different primary purpose: validation of a structured artifact rather than analysis/summarization of meeting content. The redaction scan is also an undeclared capability, though supporting to validation. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
_DIR}`,并在加载内容后附上 `[Skill directory: …]`,此时用其中的绝对路径替换 `{baseDir}`。其他宿主未展开时,改用当前 `SKILL.md` 所在目录的绝对路径。不要把原样占位符交给 shell,也不要假设终端当前目录刚好位于 Skill 根目录。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file mandates fixed Chinese phrases for the opening and closing (整理好了。 and 这条确认消息可以直接发群,发送前核对人名和时间。) without indicating that the user can choose another language. This is a natural-language locale policy issue because the skill imposes a specific language rather than documenting a justified region-specific constraint or offering opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains all user-facing instructions in Chinese and does not indicate that the skill is region-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file is written entirely in Chinese and presents mandatory operational rules without any indication that language choice is optional or that the skill is intentionally region-specific. Under the policy rule for natural-language constraints, forcing a specific language/locale without user opt-in is a violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The entire skill reference is written only in Chinese, and there is no natural-language indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is entirely framed as mandatory Chinese output and visual rules, including fixed Chinese opening, closing, status text, and copy conventions. Because it prescribes a specific language/locale behavior without user opt-in or an explicitly justified region-specific constraint, it creates a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The entire safety guidance and all prescribed example outputs are written as mandatory Chinese phrasing, including required response templates such as “未观察到明确确认” and “当前只观察到表达意向”. There is no indication that the skill is region-specific or that users may opt into another language, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file defines extensive user-facing labels and messages entirely in Chinese, and later uses them to render Markdown and HTML outputs. There is no visible option for users to select another language or any comment/docstring explaining that the skill is intentionally limited to a Chinese-speaking context, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The template headings and fixed labels are entirely in Chinese, which imposes a specific language on generated output. Under the policy, language constraints should either be optional for the user or clearly documented as justified for a region-specific use case; neither is present in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown template uses Chinese section headings and labels throughout, which imposes a specific language on generated content. The file does not indicate that the language is optional, user-selected, or justified by a region-specific requirement, so it constitutes a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The HTML root sets lang="zh-CN", and the visible interface text throughout the template is in Chinese, which indicates the skill output is fixed to a specific language/locale. The file does not show any user opt-in, language selection, or documented region-specific justification, so this may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown template uses Chinese section headings and user-facing guidance throughout, which effectively forces a specific language for generated output. The file does not indicate that Chinese is optional, user-selected, or required for a justified region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The title and entire document prescribe Chinese meeting discourse signals, which effectively constrains the skill content to a specific language/locale. There is no accompanying statement that this is optional, user-selected, or limited to a clearly documented region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The neutral_language_mode field introduces a language or tone policy dimension, but the schema does not indicate whether this mode is user-selected, optional, or constrained by a justified locale policy. Because SQP-3 applies to all file types, this natural-language policy ambiguity is worth flagging where a language-related behavior is encoded without clear opt-in semantics.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The HTML declares lang="zh-CN" and presents titles, labels, and status text in Chinese throughout the template. This can violate language/locale policy when users are not given an opt-in choice and no region-specific justification is present in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML declares lang="zh-CN" and the visible document title and labels are entirely in Simplified Chinese, indicating the skill output is fixed to a specific language/locale. The provided file does not show any user opt-in, alternative locale handling, or documentation that this is intentionally limited to a China-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The font-family forces inclusion of locale-specific Chinese fonts ("PingFang SC", "Noto Sans CJK SC", "Microsoft YaHei") in the default rendering stack. For the natural-language policy category, this can be interpreted as imposing a specific language/locale preference without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The font-family declaration prioritizes Chinese-script fonts such as "PingFang SC", "Noto Sans CJK SC", and "Microsoft YaHei" for all users. This is a natural-language/locale choice embedded in the file and there is no indication of user choice or a documented region-specific requirement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.