Back to skill

Security audit

npa-valuation-engine

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local valuation toolkit for foreclosure and non-performing asset analysis, with no evidence of hidden execution, persistence, credential access, or data exfiltration.

Install only if you need a Chinese/China-market NPL and foreclosure valuation workflow. Keep borrower, debtor, litigation, collateral, and deal data minimized and local, review generated spreadsheets before relying on them, and treat outputs as decision support rather than legal, investment, or appraisal advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (44)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code is clearly related to the declared domain of distressed asset / judicial auction pricing, especially bid-cap estimation and quick quoting for NPL assets. However, the declared description substantially overstates the implemented functionality. The actual script is a lightweight command-line calculator using standard-library inputs and hardcoded presets. It computes present value, disposal cost, net present recovery, a bidding ladder, maximum bid, implied discount, and a rough IRR estimate. It does not implement several central declared features: no XLSX output, no auditable spreadsheet model creation, no three-scenario analysis, no MOIC, no repairability scoring, and no discount-caliber alignment logic. Therefore the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises a comprehensive valuation/pricing engine for auctioned and distressed assets, with specific finance functions: discount calibration, repairability scoring, three-scenario IRR/MOIC analysis, bid cap back-solving, and auditable Excel model output. The supplied code instead implements an NPL disposal decision-support tool centered on five weighted scores (asset quality, legal status, disposal efficiency, recovery certainty, cost efficiency), strategy matching, simplified recovery/IRR comparison across disposal strategies, and parameter sensitivity analysis. While the domain overlaps strongly with NPL/distressed assets and includes IRR-related outputs, several core declared capabilities are absent: there is no XLSX creation, no MOIC, no explicit bid ceiling computation, no discount-rate alignment or repairability scoring, and no true three-scenario valuation model. Therefore the description materially overstates and mischaracterizes the code’s actual functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description promises a comprehensive valuation/pricing engine for judicial auction and distressed assets, including advanced modeling outputs (three-scenario IRR/MOIC), bid-cap reverse calculation, reparability scoring, and auditable XLSX generation. The supplied code is much narrower: it is a console-based regional quick calculator using fixed lookup tables for city tiers and asset types, producing rough valuation and recovery estimates. While the domain overlaps strongly with NPL/distressed asset valuation, several central promised capabilities are absent, especially XLSX model generation and the more sophisticated scenario/scoring features. Therefore the description materially overstates what the code actually does.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises and documents shell-based execution paths (pip install, python scripts/..., optional soffice) but does not declare any explicit tool scope or permission boundaries. In an agent setting, undeclared execution capability increases the risk of over-broad command execution, dependency installation, or unintended local environment modification when the skill is invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description declares many trigger words such as “处置”, “尽调”, “IRR”, and “资产包”, several of which are broad terms that can appear in ordinary finance discussions unrelated to this specific skill. The file does not provide negative examples or context constraints to clarify when the skill should not activate, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is designed to process highly sensitive deal, debtor, collateral, legal, and recovery information, but it does not provide a clear warning or handling guidance for confidential data. This is dangerous because users may input personally identifiable, financial, or legally sensitive materials into the skill without minimization, redaction, consent, or retention awareness, increasing privacy, compliance, and confidentiality risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document presents all guidance, headings, and code comments in Chinese and does not provide any user opt-in, alternative language, or explanation that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all instructions and reference content exclusively in Chinese, which may force a specific language on users without offering an alternative or documenting a justified locale restriction. The policy explicitly calls for flagging language or locale constraints unless the user is given a choice or the regional limitation is clearly documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill file is written exclusively in Chinese and provides no indication that language selection is optional or that the content is intentionally limited to a Chinese-speaking audience. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is entirely presented in Chinese and does not indicate that the user can choose another language or locale. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s title and all instructional content are in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. This can violate language/locale policy when a skill implicitly forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file presents all instructions and examples exclusively in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. This can violate language or locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s title, usage text, prompts, help strings, and output labels are all hard-coded in Chinese, and the interactive/CLI experience does not provide any opt-in or alternative locale. This is a natural-language policy concern because it imposes a specific language on users without presenting a choice or clearly documenting that the skill is intended only for Chinese-speaking users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module docstring presents the skill entirely in Chinese and describes its purpose and outputs in that language, with no indication that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The docstring at L351-L354 says the function compares strategy outcomes, and the signature includes recovery_rate and annual_irr_target as key comparison inputs. However, the body never uses either parameter; it derives recoveries only from hardcoded strategy ranges and computes a simplified IRR without referencing the target, so the documented decision logic contradicts the actual implementation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

At L411-L412, the code comments indicate that boolean parameters should be inverted during sensitivity analysis. But because the preceding branch at L409 checks isinstance(..., (int, float)), Python booleans match that condition first and are multiplied by (1 + shock) rather than toggled, which contradicts the stated behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The user-facing demo prints headings, labels, and recommendations exclusively in Chinese, and there is no mechanism for users to select their preferred language. This is a policy issue because the skill's natural-language interface is fixed to one language without documented opt-in or justified locale restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring advertises python regional-valuation.py --batch --file assets.csv, implying CSV/file-based batch processing. However, the CLI defines only --batch and never defines --file or any file parsing logic, so the documented invocation cannot work and contradicts the actual implementation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code contains a batch_estimate function for bulk valuation, and the CLI exposes --batch as '批量模式', but main() never branches on args.batch and no input path is connected to that function. This makes the documentation and help text misleading about what the script actually does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and command usage are presented only in Chinese, and the same pattern continues in user-facing CLI descriptions and output. This forces a specific language for users without any opt-in or documented locale justification, which matches the natural-language locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Argument descriptions, table headers, status labels, and summary output are all emitted in Chinese only. Because the script does not offer a language selection or note that it is intentionally China/Chinese-only, it violates the language-choice policy for natural-language behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file’s natural-language interface, usage text, help, status messages, and conclusions are all hard-coded in Chinese. That can violate language/locale policy when users are not given an explicit opt-in or alternative language, and the file does not document that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/verify_model.py (reported line 73)May include surrounding context.

python
wb.save(forced)
    if shutil.which("soffice") is None:
        return forced, tmp, "no_soffice"
    subprocess.run(["soffice", "--headless", "--convert-to", "xlsx", "--outdir", outdir, forced],
                   capture_output=True, timeout=180)
    out = os.path.join(outdir, os.path.basename(forced))
    if not os.path.exists(out):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing instructions exclusively in Chinese, which can constitute a language/locale policy violation when no opt-in or scope limitation is provided. The file does not indicate that it is intended only for Chinese-speaking users or a China-specific compliance context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The template explicitly requests financial, legal, market, and business data that can include confidential or regulated information, but it provides no warning about sensitivity, minimization, storage, sharing, or redaction. In a valuation workflow for non-performing assets, these fields are highly likely to contain borrower, creditor, litigation, and asset details, increasing the chance of inappropriate collection or mishandling by users or downstream systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.