Back to skill

Security audit

人生搞钱Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local career-report generator that handles sensitive résumé and salary data, but I found no hidden exfiltration, destructive behavior, or system persistence.

Install only if you are comfortable giving the agent résumé, career-history, and salary information and having derived profile/report files saved locally under projects/. Redact identifiers you do not need in the analysis, review the generated report before sharing or printing it, and delete the project output directory when you no longer need it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a career monetization analysis workflow, but its behavior includes repository/CI-style validation, schema checks, HTML structure inspection, and subprocess execution. This mismatch is dangerous because users may consent to a benign advisory skill without realizing it can perform code-adjacent or shell-backed operations, which weakens informed consent and can hide higher-risk execution paths.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document explicitly forbids introducing a multilingual system, which functions as a language/locale constraint. There is no corresponding user choice or opt-in mechanism documented here, so the policy is framed as a mandatory restriction rather than a user-selected preference.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly encourages users to submit highly sensitive personal information such as résumés and career histories, but provides no privacy notice, data minimization guidance, retention policy, or warning against including unnecessary sensitive data. In the context of an agent skill that generates reports from personal materials, this increases the risk of oversharing, unintended storage in local outputs or logs, and exposure of personal or employment-sensitive information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly asks users to send a résumé and career story, which commonly contain sensitive personal data such as employment history, contact details, education, and possibly salary information. While the README says user data should not be committed to the repository, it does not clearly warn users about the sensitivity of these materials, where they will be stored during processing, how long they are retained, or how to minimize included personal data, which creates avoidable privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill references reading and writing project files and invoking a render script, but it does not declare any tool scope or permission boundaries. That creates an authorization gap: an agent may be granted broader filesystem or shell access than users expect, increasing the risk of unintended file access, overwrites, or command execution through downstream components.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language description, title, and invocation examples are entirely in Chinese and imply operation in that language, but there is no indication that users may choose another language or locale. This creates a language/locale policy concern because the skill appears to enforce a specific language by default rather than documenting an opt-in or justified regional limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The schema title and descriptions are written entirely in Chinese and prescribe field names and output expectations in that language, but the file does not indicate that this skill is intentionally region-specific or that users can choose another language. Under the policy, imposing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The schema sets meta.language to zh-CN by default, which imposes a specific language/locale choice in a file that otherwise does not indicate this is a region-specific tool or that users may opt into another language. Per the policy, forcing a locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This HTML document declares lang="zh-CN", and the visible content throughout the report is presented only in Chinese. Under the policy for natural-language violations, forcing a specific language without user opt-in is a locale/language policy issue unless the constraint is clearly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The spec hard-codes Chinese-only output ("语言:中文") without indicating any user-language detection or override path. This can cause unsafe or inaccessible behavior for users who do not read Chinese, leading to misunderstood advice, inability to validate recommendations, and degraded user consent/agency rather than a direct security compromise.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown template is entirely written in Chinese, including field labels and instructions, with no indication that the skill supports other languages or that Chinese is a justified region-specific requirement. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instruction '优先中文来源且贴近用户市场' imposes a language preference as a default operational policy. This can violate language/locale neutrality because it does not mention user opt-in, alternatives, or exceptions for users who prefer non-Chinese sources.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide tells users their materials will only be used locally and not uploaded, but it also instructs the agent to persist sensitive profile data to projects/<run>/profile.json. Even if data is not transmitted off-device, persistent storage is a separate privacy and security risk because resumes, salary, work history, and constraints remain on disk and may be exposed to other local users, backups, logs, or later processes without clear user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L002 states the responsibility is for '中文适配', and the rest of the document consistently defines the report system around Chinese-only presentation conventions. This is a natural-language locale policy constraint presented as a requirement, but the file does not offer an alternative language/locale choice or describe it as user-selectable.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

L011 says typography is adjusted according to Chinese characteristics, which signals a fixed locale policy for report output. Because the document does not mention user opt-in or a configurable locale, this reads as a forced language/locale behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Line L11 states that all internal references must match this text exactly and must not produce localized variants. This is a natural-language policy concern because it enforces one language form rather than offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated HTML hard-codes lang="zh-CN" and uses a Chinese-only report title/content, while the script offers no option to select another language or locale. This is a natural-language policy concern because the skill imposes a specific language setting rather than allowing user choice or clearly documenting a justified regional restriction.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/verify_repo.py (reported line 138)May include surrounding context.

python
def render_smoke():
    out = Path(tempfile.gettempdir()) / "life-money-smoke" / "report.html"
    out.parent.mkdir(parents=True, exist_ok=True)
    proc = subprocess.run(
        [
            sys.executable,
            str(REPO / "scripts" / "render_report.py"),

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document branding and usage instructions are presented primarily in Simplified Chinese, with only a link to an English README rather than an explicit in-skill language choice. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The stylesheet explicitly prioritizes Chinese serif and sans-serif font stacks, and the surrounding comments indicate the report is designed for a Chinese-language presentation. For an all-file-types policy check, this can be a locale/language preference baked into the skill artifact without any visible opt-in or justification in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON contains user-facing natural-language content almost exclusively in Chinese, including notes, summaries, plans, and service descriptions. There is no indication that the language is optional, user-selected, or justified as a region-specific constraint, so it may impose a fixed locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all skill content, headings, and instructions in Chinese only. Under the policy rules, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This Python file contains its primary docstring, status messages, and validation errors entirely in Chinese, which imposes a fixed language on users. Under the policy, language constraints should either be optional/opt-in or explicitly justified as region-specific; neither is present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.