Back to skill

Security audit

Requirement Validator 是一个数据驱动的需求验证工具,通过多维度分析帮你判断需求是否值得实现。

Security checks for vulnerabilities and agentic risk

Overview

This skill locally analyzes user-provided product feedback files to score requirement validity, with no evidence of hidden network access, persistence, credential use, or unrelated behavior.

Install this if you are comfortable running a local Python tool over product feedback data. Review any CSV/JSON content for sensitive user information before use, and provide explicit input and output paths when generating reports.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire skill description and usage guidance are presented only in Chinese, with no indication that users may choose another language or that the skill is intended exclusively for a Chinese-speaking or region-specific context. This creates a natural-language locale constraint that is not presented as optional or justified.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises executable usage that reads user-supplied CSV files and references editable configuration, but it does not declare an explicit tool/permission scope for file access. That mismatch can cause over-broad runtime assumptions or bypass governance checks, increasing the chance that the agent reads or writes files beyond what users expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill’s natural-language description and usage instructions are presented entirely in Chinese, which can amount to forcing a specific language on users without opt-in. The file does not mention language options, multilingual support, or a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The invocation example uses a very broad natural-language trigger (e.g. '帮我验证"导出PDF"这个需求') without clear activation boundaries, which can cause accidental or implicit skill activation in unrelated conversations. In an agent environment, ambiguous triggering can lead to unintended data requests or file processing based on casual user text.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file contains its primary description and user-facing interface text exclusively in Chinese, beginning with the module docstring and continuing throughout CLI help/messages. That can violate language/locale policy when the skill forces a specific language without giving the user a choice or documenting a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This YAML file uses Chinese-only natural-language labels and comments throughout, such as the section headers and metric descriptions. Under the policy, forcing a specific language without offering user choice or documenting a justified locale constraint can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The competitor names are encoded only in Chinese (e.g. "竞品A", "竞品B", "竞品C"), which reflects a fixed language choice in the skill data. Because SQP-3 applies to all file types and there is no indication here of user opt-in or a documented region-specific constraint, this can be a locale-policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.