Back to skill

Security audit

lunheng

Security checks across malware telemetry and agentic risk

Overview

This legal drafting skill is coherent, but it automatically sends sensitive case material to configured external services while making inconsistent privacy and logging claims.

Install only if you are comfortable with legal case text being sent to the LLM/API endpoints you configure. Use a local or zero-retention endpoint for confidential matters, redact personal identifiers before drafting, avoid the web UI with untrusted generated HTML, and review all legal and sentencing output manually against current authoritative law.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (27)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The roadmap makes a privacy assurance that the system will not persist case data locally, but nearby planned features such as logging and learning from historical documents create a material risk that sensitive legal case data will in fact be retained or repurposed. In a legal-document assistant, this inconsistency is dangerous because users may rely on the non-persistence claim when handling personally identifiable and case-sensitive information, leading to undisclosed storage, audit trails, or model/profile contamination.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
This record’s title identifies one case, but the facts and analysis describe a different one. In a legal-writing assistant, mismatched case metadata can cause the system to cite or summarize the wrong precedent, producing materially incorrect legal output and undermining user trust.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The case title conflicts with the facts inside the same extracted entry, indicating data corruption or mis-association. Because this skill is for drafting judicial documents and legal reasoning, such contradictions can propagate false authorities, wrong issue framing, and inaccurate legal conclusions.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
This extracted title does not match the case described in the facts and analysis, so the record can mislead retrieval and downstream generation. In a legal domain, this is dangerous because users may unknowingly rely on the wrong precedent or cite an unrelated dispute as support.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The record documents a different case than the title indicates, which is a substantive integrity failure in the dataset. For a legal-assistance skill, this can contaminate case search, reasoning chains, and document drafting with incorrect case law references.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
This code builds a prompt containing party names, claims, facts, evidence, legal issues, and retrieved reference materials, then sends it to an external endpoint via urllib using a bearer token. In a legal-document skill, these materials are highly likely to contain sensitive personal and case information, so exporting them to a third-party LLM service can create serious confidentiality, compliance, and data-governance exposure if not explicitly controlled.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The UI inserts multiple server-provided fields into the DOM with innerHTML, including the generated draft when format=html and other result fields such as item names, messages, warnings, and element content. If the backend output or any upstream retrieved content is attacker-controlled or prompt-influenced, this enables stored/reflected XSS in a highly trusted legal-writing interface, which is especially dangerous because users may trust manipulated draft text, links, or scripts.

Natural-Language Policy Violations

Low
Confidence
83% confidence
Finding
The skill instructs the agent to assume a fixed identity and address the user as 'Your Honour' automatically, without user opt-in. While not a direct code-execution or data-exfiltration issue, forced persona framing can manipulate user trust, create misleading authority signals, and reduce transparency about the system's actual role—especially in a legal context where perceived expertise matters.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The interview collects professional role, court level, region, case distribution, and internal drafting/review preferences, then states these answers will be written to `practice_profile.md` without any warning, minimization, retention guidance, or access controls. In a legal-judicial context, this profile can reveal sensitive operational information about a user or institution and may be exposed to other skills or users if stored insecurely.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill hard-codes a required form of address ('Your Honour') for all replies, imposing a persona and interaction style without user opt-in. While not directly enabling code execution or data exfiltration, it can override user preferences, reduce transparency about the assistant’s role, and create inappropriate authority signaling in sensitive legal contexts.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The activation conditions are broad enough to trigger this high-authority legal persona at the start of nearly every session and on general legal topics, even when the user did not request that mode. In a legal-writing skill, this can override user intent, cause inappropriate role persistence, and increase the chance that authoritative or policy-laden instructions shape unrelated conversations.

Natural-Language Policy Violations

Medium
Confidence
94% confidence
Finding
The instruction to always address the user as 'Your Honour' and begin every reply that way forces behavior without consent and can dominate downstream responses. In a legal assistant, this is especially risky because it reinforces an inflated judicial-authority framing that may mislead users, reduce neutrality, and interfere with normal safety or usability expectations.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs the agent to fetch arbitrary webpage URLs via `web_fetch` without any privacy, consent, or data-handling constraints. In a legal-document assistant context, this can cause sensitive case information, user-provided URLs, or internal research targets to be sent to external services or retrieved from untrusted sources, creating privacy leakage and SSRF-like data access risks.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The instructions direct copying files from `~/下载/` into `workspace/output/` without warning the user or obtaining consent for local file manipulation. Even though the action is limited, it normalizes autonomous handling of local legal documents, which may contain highly sensitive personal or case information, and can create unintended duplication of confidential files.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The routing trigger uses very broad keywords such as “格式/排版/字体/字号”, which can capture many ordinary user requests without sufficient scoping to court-document formatting. In an agent skill that routes behavior based on keyword matches, this can misroute queries, override more appropriate knowledge sources, and cause the assistant to apply the wrong legal-document template or constraints.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The routing table uses very broad natural-language trigger phrases such as common verbs for editing or drafting, which can cause the skill to load the wrong knowledge source or invoke higher-impact workflows unintentionally. In a legal-document assistant, misrouting is more dangerous than in a general skill because it can lead to incorrect legal analysis paths, inappropriate document generation, or reliance on the wrong authority set.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The file transmits case and party data to an external LLM API but does not implement any explicit user-facing consent, privacy notice, or in-code safeguard preventing sensitive legal content from leaving the environment. Because the skill handles judicial/legal drafting, the context makes this more dangerous: even ordinary inputs may contain PII, case strategy, evidence summaries, or protected legal records.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The code sends the user's case cause and keywords directly to a third-party API, which may contain sensitive legal matter details, without any consent, warning, redaction, or tenancy/privacy controls. In a legal-document assistant context, even short queries can expose confidential case strategy, party information, or privileged work product to an external service.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The function sends full case text directly to an external LLM endpoint using a bearer-authenticated HTTP API, with no consent check, redaction, or user-visible disclosure. In this skill’s legal-document context, the text is likely to contain highly sensitive personal, financial, medical, or case-related information, so unintended third-party disclosure creates significant confidentiality and compliance risk.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The module sends extracted legal references derived from user-supplied document text to a remote LLM endpoint without any explicit user consent, disclosure, or local-only mode enforced by default. In a judicial drafting context, even seemingly limited legal citations can reveal case type, argument structure, or sensitive matter details, creating confidentiality and compliance risks if documents contain private or non-public information.

Missing User Warnings

Low
Confidence
78% confidence
Finding
The code queries external authority-verification services using law names extracted from user text, again without clear disclosure or consent. The data sent is narrower than full document content, so the exposure is smaller, but in legal workflows it can still leak sensitive subject matter or indicate what type of case or dispute is being processed.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The function sends full case text, which may contain highly sensitive personal and legal data, to an external LLM endpoint using a configured base URL. In a judicial-document assistant context, this is especially risky because case narratives commonly include names, IDs, financial information, medical facts, and dispute details, and the code provides no consent gate, minimization, or clear disclosure before transmission.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The code prints the first 200 characters of the LLM response and extracted JSON to stderr for debugging, which can directly expose confidential case facts in logs, terminals, CI output, or process supervisors. Because this skill handles legal case materials, even partial snippets may reveal identities, allegations, financial amounts, or evidence summaries and create a durable secondary leakage path.

Missing User Warnings

Medium
Confidence
98% confidence
Finding
The enhancer sends the full judgment text to an external LLM endpoint via `_call_llm`, and the prompt construction includes the complete original judgment plus optional style/context data. In a legal-document drafting skill, judgments can contain highly sensitive personal, evidentiary, and case details; transmitting them off-box without explicit consent, minimization, redaction, or tenant-controlled endpoint guarantees creates a real confidentiality and compliance risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This script generates concrete sentencing recommendations, including adjusted imprisonment ranges and procedural suggestions, without any prominent disclaimer that the output is only informational and not legal advice. In a legal-document assistant context, users may over-trust the result and use it in real cases despite the code relying on simplistic hard-coded tables and heuristic percentage adjustments that do not reflect binding law, local guidance, evidentiary nuance, or judicial discretion.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:35