Back to skill

Security audit

Quality Daily / Weekly / Monthly Report

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed quality-report generator that may create local Excel and PowerPoint report files, with no evidence of hidden access, exfiltration, or persistence beyond intended outputs.

Before installing, be aware that the skill can generate realistic sample business metrics and may save Excel/PPT files locally. Treat any sample figures as placeholders, verify all operational data before sharing reports, and use specific prompts like 品质周报 or quality KPI report to avoid accidental activation from generic report requests.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (12)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly says the skill can generate realistic mock data when no real data is available, but it does not require clear labeling of fabricated content or warn about decision-making risks. In a business quality-reporting context, this can lead users to unknowingly circulate invented KPIs, defect counts, or complaint metrics as real operational data.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes generic phrases like 'quality report', '日报', '周报', and '月报', which can cause the skill to activate for broad, ambiguous user requests unrelated to this specific workflow. Because the skill may then generate mock business data and potentially create/save Excel or PPT outputs, accidental invocation can lead to unintended actions, user confusion, or workspace artifact creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill behavior explicitly allows generating and saving .xlsx and .pptx files to the workspace, but the high-level description does not clearly warn users about this side effect. Hidden file-creation behavior is risky because users may invoke the skill expecting text output only, resulting in unexpected persistence of generated content and possible handling of sensitive operational data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document instructs the model to generate the report in Chinese context and labels, including a mandatory output section for producing the report, but it does not provide any user option to select language or locale. Under the policy, a fixed language requirement without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file is explicitly Chinese-only and requires the user to respond with Chinese menu choices without offering any language fallback or adaptation. This can exclude users, cause misunderstanding for non-Chinese speakers, and create unsafe workflow errors if users cannot correctly understand reporting options or required next steps.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill hard-codes a Chinese-only template selection prompt ("请选择模板") when the user asks for weekly or monthly reports, without offering a language choice or adapting to the user's language. This can cause usability and accessibility failures, and may lead users to misunderstand options or proceed with the wrong template, especially in multilingual environments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The README describes user-facing template selection text as '请选择模板' and points to a Chinese-only display example, while the document otherwise mixes English and Chinese and does not state that the user can choose their preferred language. This may create a locale/language policy issue because the skill appears to impose a specific language for interaction without opt-in or justification.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
96% confidence
Finding

The trigger '日报' is extremely short and context-free, so it is likely to match many unrelated requests for daily reports outside quality reporting. This increases the chance of accidental skill routing and unintended generation of mock data or files.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
96% confidence
Finding

The trigger '周报' is overly generic and can capture many weekly-report requests that are not about quality management. In this skill, such accidental activation is more problematic because the workflow may proceed to structured reporting and file generation with little initial disambiguation.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
96% confidence
Finding

The trigger '月报' is too broad to safely identify this particular quality-report skill and may intercept unrelated monthly reporting tasks. Although the direct security impact is limited, it can still cause unintended file creation, misleading mock data output, or disclosure of business-format assumptions in the wrong context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description explicitly says to use the skill for '品质日报/周报/月报' alongside English phrasing, which signals a specific language/locale expectation. There is no accompanying statement that users may choose their preferred language or output locale, so this can be read as a language-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire template and generation instruction are written only in Chinese, and L147 instructs generating the report in that format without any opt-in or alternative locale. This can violate a language/locale policy when users are not explicitly given a choice of output language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.