Back to skill

Security audit

feasibility-report-engine

Security checks for vulnerabilities and agentic risk

Overview

The skill can help produce feasibility reports, but it also encourages concealed AI ghostwriting and under-scoped handling of sensitive business documents.

Install only if you are comfortable reviewing and controlling every outbound step. Do not use the anti-bot bypass guidance, get explicit permission before sending client documents or screenshots to third-party model APIs, disable knowledge-base retention for confidential projects, and disclose AI assistance where contracts, law, or professional standards require it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个覆盖可研报告全流程的生产系统,核心能力包括大纲判型、数据采集、财务六表测算、正文撰写和交付前验收。实际代码只是一个DOCX格式化脚本:读取输入Word,构建新封面和签署页,插入目录域,设置标题/正文样式,复制原文档正文,并添加页眉页脚分页字段。这与声明中的主要目的相比明显过窄,且缺失了声明中的关键业务能力。代码与“报告排版”这一子环节相关,但不足以支撑整体描述,因此属于明显的描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

描述强调的是端到端可研报告生产流水线,核心包括大纲判型、联网调研、财务六表联动、按大纲写作 Word 报告、排版体检和视觉验收。而实际代码只是一个财务测算 Excel 模板生成器,重点在工作簿样式、参数输入区和简化财务公式。虽然它与“财务测算”这一子能力相关,但远不足以覆盖所宣称的整体能力,且主要输出也只有 XLSX 文件,没有 Word 成稿或数据采集等功能。因此描述与代码行为存在明显且重大的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a comprehensive feasibility-report production system with document-type judgment,联网 research, financial modeling, linked tables, drafting, formatting checks, and final delivery of both Word and Excel outputs. The supplied code chunk is much narrower: it is a standalone script that creates a professionally formatted Word template with a prewritten chapter skeleton and placeholder text. While this partially overlaps with the 'professional formatting' portion of the description, it does not implement most of the claimed pipeline or outputs. The mismatch is material because the declared primary purpose is an end-to-end feasibility study generation system, whereas the actual code is only a formatting/template generator.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description promises an end-to-end feasibility report production system with outline classification, due diligence, formula-linked financial modeling, report authoring, formatting cleanup, and final delivery of a Word report plus Excel financial tables. The actual script is far narrower: it is a standalone generator for one ancillary document ('编制说明与资料需求清单'), essentially a templated 1–2 page explanatory note. It uses python-docx to create formatted text and leaves signature lines blank; there is no evidence of outline判型,联网尽调,财务测算,六表联动,正文成稿,排版体检, or multi-model visual acceptance. While the header comment says this file is 'one of' a delivery trio, based solely on this code chunk the implemented behavior does not accurately represent the declared skill’s primary purpose. Therefore this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个端到端的可研报告生产与交付系统,核心能力应包括报告生成、财务建模、排版和交付产物产出。实际代码的主功能则是对已有报告文本做机械式质量检查,属于交付前质检环节中的一个很小子集。虽然声明中提到“交付前有一道体检”,这与代码的自检器性质有一定相关性,但代码远不足以支撑其被描述为完整流水线。其主要目的、输入输出、功能范围都与声明存在实质性差异,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个端到端可研报告生产与交付系统,核心能力应包括内容生成、结构判型、数据采集、财务建模、排版和最终交付。给出的代码块则仅是一个针对Word文档的轻量QA/验收辅助脚本:直接读取docx压缩包中的document.xml,抽取段落文本,缓存为txt,按基线JSON做词项命中检查,并提供grep与统计功能。这与声明的主要用途存在实质性差异。唯一较弱的关联是描述中提到‘交付前有一道体检/验收’,而该脚本可被视为其中一个文本验收子工具;但单独这段代码远不足以支撑所宣称的整体技能目的,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ssd 4

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These instructions normalize covert ghostwriting and deliberate concealment of AI involvement for externally delivered professional reports. In the context of financing, approval, and formal submission documents, this materially increases the risk of deception, misrepresentation, and evasion of accountability.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill prescribes anti-bot bypass, Cloudflare challenge handling, and interactive browser control to obtain data beyond normal access paths. Those instructions expand the skill from report writing into access circumvention, which can violate site restrictions, collect protected information, and expose the operator to legal and security risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs collection, storage, and organization of project materials but provides no explicit privacy warning, consent mechanism, or retention limitation. Because feasibility-study inputs commonly include commercial, contractual, land-use, and regulatory documents, silent storage meaningfully increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill recommends sending full documents to multiple third-party model APIs for review and visual inspection without a clear warning that sensitive data will be transmitted externally. This is dangerous because project reports often contain proprietary financials, contracts, and strategic plans that could be exposed across multiple vendors without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction to store valuable project data in a knowledge base lacks any consent, retention, or access-control guidance. That creates a significant risk of unauthorized reuse, long-term retention of confidential client materials, and cross-project data leakage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script’s embedded guidance explicitly states '无任何 AI 痕迹' and frames concealment of AI involvement as a required operating rule. In a document-generation skill for formal feasibility reports, this is dangerous because it encourages deceptive provenance, undermines disclosure obligations, and can facilitate misrepresentation of authorship or review status to clients, regulators, lenders, or other decision-makers.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/vision_check.py (reported line 81)May include surrounding context.

python
tmpd = tempfile.mkdtemp(prefix='vision_')
    pdf_path = os.path.join(tmpd, 'doc.pdf')
    subprocess.run(['soffice', '--headless', '--convert-to', 'pdf', '--outdir', tmpd, docx_path],
                   capture_output=True, timeout=300, env={**os.environ, 'HOME': os.path.expanduser('~')})
    pdfs = [f for f in os.listdir(tmpd) if f.endswith('.pdf')]
    if not pdfs: return [], tmpd
    try:

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · 使用说明_README.md (reported line 82)May include surrounding context.

md
| python-docx | docx 读写 | pip install python-docx |
| xlsxwriter | 测算套表 | pip install xlsxwriter |
| pymupdf (fitz) | docx→PDF 渲染(视觉验收用)| pip install pymupdf |
| LibreOffice soffice | docx→PDF 渲染/交付 | sudo apt install libreoffice-writer |
| 视觉模型 key(可选)| 排版看图验收 | 任一:DeepSeek/DashScope/智谱/小米 |

> `report_qa.py` 与 `pipeline_check.py` **只用 Python 标准库**,不装任何依赖即可运行。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill describes capabilities requiring environment access, file I/O, network access, and shell execution, but it does not declare an explicit tool/permission scope. That creates an authorization ambiguity where downstream runtimes or reviewers may not understand the actual power the skill expects, increasing the chance of overbroad execution in sensitive environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The listed trigger words include broad phrases such as “可行性研究”, “立项报告”, and “财务测算”, which can appear in ordinary discussion or in contexts outside this specific skill. The file does not provide negative examples or tighter scope constraints to distinguish when this skill should activate versus related reporting or finance skills.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger section says the skill applies when a client wants a feasibility report, project initiation report, or due-diligence report, but these are neighboring yet distinct deliverables. Although sibling skills are listed later, the activation rule itself does not clearly state where this skill stops and another skill should be used, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs users to conceal AI involvement, remove provenance metadata, and support undisclosed ghostwriting for external delivery. This is dangerous because it normalizes deception and makes downstream auditing, attribution, and fraud detection materially harder, especially for formal financing or regulatory documents.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs automatic transmission of deliverables to external chat or IM channels as an operational rule, which broadens exposure of potentially sensitive project documents. Without explicit consent, destination validation, and data classification checks, this creates unnecessary exfiltration risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

A plain-language instruction to send generated files directly into the user's chat channel creates a direct outbound data path for sensitive deliverables. In a business-document skill, that becomes more dangerous because the files may contain non-public financial, legal, or strategic information and the instruction does not include verification or approval safeguards.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire skill content is presented only in Chinese and provides a ready-to-send template without offering any language or locale choice. Under the policy for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script copies the source document to the destination and immediately opens the destination for modification, then later saves all formatting and content changes back to that file. Although the docstring describes the formatting pipeline, it does not explicitly warn that running the script will rewrite the output DOCX and alter document contents/structure such as cover fields and metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This section erases runs for '编制单位', replaces detected date text with placeholders, blanks '文件编号', and removes the '资料密级' paragraph entirely. These are destructive content changes to potentially important user data, but there is no explicit caution or confirmation that these fields will be removed or replaced when the script runs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script writes the generated document directly to the user-supplied destination path with out.save(DST) and provides no confirmation prompt, overwrite check, or prior user-facing warning in the file. Because this is a file-writing operation that can replace existing content, it should be disclosed or guarded.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all workbook sheet names, labels, and instructions are written in Chinese, indicating a fixed language/locale behavior. There is no indication that users can opt into another language or that the locale restriction is documented as a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.