Back to skill

Security audit

投后管理报告自动更新

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a straightforward Chinese-language report updater for user-provided financial and Word documents, with no hidden persistence, credential use, or remote execution found.

Install only if you want a Chinese-language workflow for local post-investment report drafting. Use copies of sensitive reports where possible, choose the output path deliberately, and review all generated financial analysis and investment recommendations before sharing or relying on them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明的核心用途是自动更新投后管理报告及相关分析,这通常需要整合财务报表、访谈纪要、生成分析内容并输出更新后的报告。实际代码没有任何报告生成、内容更新、财务计算、分析逻辑或多数据源整合功能,只是对单个 DOCX 文件进行结构化解析并输出文本/JSON。因此其主要目的与声明明显不符,属于实质性能力不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个面向投后管理报告更新的综合能力,涉及多源信息整合(财务报表、访谈纪要)、报告生成和经营/行业分析。而实际代码的核心功能只是解析 Excel 财务报表并提取少数关键指标,输出结构化 JSON。两者主目的存在明显差异:代码是底层数据提取工具,不能单独完成所宣称的报告更新与分析工作。虽然“根据新财务报表”这一部分与代码有关联,但整体能力描述远超代码实际行为,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The title and overview present the skill entirely as a Chinese content-update template, and the later writing guidance also prescribes Chinese phrasing and style without indicating user choice. Under the policy, forcing a specific language or locale without opt-in is a natural-language policy violation unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file presents all guidance and examples exclusively in Chinese, which effectively forces a specific language on users. The file does not state that the skill is region-specific or provide any opt-in or alternative language option, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's docstring, CLI help text, generated timestamp label, and section matching logic are all hard-coded in Chinese, which imposes a specific language/locale on users without opt-in. This matches the policy category for language or locale constraints that are not presented as optional or justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains natural-language strings that require Chinese to understand the script’s purpose and usage. The policy explicitly calls for flagging language or locale constraints when the skill forces a specific language without giving the user a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring presents the script purpose entirely in Chinese, and the command-line description/help text is also Chinese-only elsewhere in the file. For a general-purpose skill, this creates a language/locale constraint without opt-in or documented justification, which matches the policy category for forced language use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

该技能文件全文以中文编写,标题和全部指导内容均默认要求中文使用场景,但未说明这是面向特定中文地区/团队的限定文档,也未提供语言选择或用户可选本地化说明。按照规则,若技能强制特定语言且无用户选择或明确合理依据,可构成自然语言层面的政策问题。

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The module docstring describes the script at a high level as generating a new quarterly report from a template and analysis content. In code, it not only generates output but also selectively replaces existing paragraphs in the template and prepends a timestamp paragraph, which is a more specific behavior than the documentation suggests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generate_report docstring documents financial_data as either a JSON string or dictionary. However, main() explicitly supports a third form—a file path whose contents are read before being passed onward—so the documentation contradicts the actual accepted input contract.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.