Back to skill

Security audit

观远 BI · 马甲实战版

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Guandata BI helper with powerful but documented BI read/write and delete workflows, so users should install it only when they intend to give an agent that level of access.

Install only for Guandata workspaces where you are comfortable letting an agent use your authenticated official Guandata CLI profile. Use a least-privileged BI account, prefer dry-run/preview flows, review generated plans, and require explicit confirmations before any delete, overwrite, or bulk migration action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (162)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CHANGELOG.md (reported line 237)May include surrounding context.

md
### Changed

- **官方全家桶 07-01 版本对齐**(`@guandata/guanskill@0.1.10`,2026-07-01 发布)。本 skill 路由总表、manifest/README/package/marketplace 里的官方版本 pin 全部刷新:
  - **`guancli` 1.0.36 → 1.0.38**:新增 **Personal Access Token (PAT) 登录方式**,支持在自动化、CI 或无浏览器环境中用 PAT 完成认证;`auth` 相关命令增强 PAT profile 的状态展示和修改保护(避免把 PAT 配置误当普通登录处理);API 调用按当前认证上下文选身份,提升 PAT 场景下 ChatBI/指标/资源接口稳定性。(1.0.37 与 1.0.38 同内容,官方连发两版。)
  - **`guanvis` 0.1.28 → 0.1.29**:**筛选器级联联动**(上游筛选约束下游筛选项);画布布局可放置筛选器;**自定义图表的数据视图可作点击联动来源、页面筛选器可过滤自定义图表**;表格卡片支持只配维度字段,`init` 支持多数据集页面数据集别名;比较卡支持本期/对比期输出,发布覆盖保护可识别并修复异常线上资源、必要时跳过覆盖备份。
  - **`guanetl` 0.1.17 → 0.1.18**:创建 ETL 时目录类型诊断更清晰,识别误用工作流/经典数据流目录并提示使用智能 ETL 目录;更新智能 ETL / 数据集输出目录 / 工作流目录边界说明。
  - **`guands` 0.1.17 → 0.1.18**:`dataset import` 支持按列指定字段类型;`dataset replace-data` 增加 `--encoding` 和 `--delimiter`;导入参数校验忽略未导入列的类型提示。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 294)May include surrounding context.

md
### Fixed

- **🔴 删除顺序矛盾实测定案(P0 correctness)**:评审团发现 `SKILL.md` 对「ETL + 其输出数据集」的删除顺序自相矛盾——B-0.5 清理坑(line 219)与 Part D 删除段写「先删 ETL、反过来撞 6001」,而 B-7.1 / B-〇 step 10 / B-1 API 全图写「先删 ds、反过来撞 2002」。**2026-06-17 在 workshop513 真实实例做净零回归实测**(建两个一次性独立 DATAFLOW ETL、各测一个方向、测完全删):
  - `etl-first`(输出集还在就 `DELETE /api/etl`)→ **`2002 输出数据集已存在` 失败**;
  - `ds-first`(先 `DELETE /api/data-source/<输出dsId>`,ETL 还在)→ **`DataSource deleted` 成功、不报 6001**;再 `DELETE /api/etl` → 成功。
  - 裁决:**B-7.1 / line 233 / 255-256 正确(ds-first),line 219 与 Part D 删除段记反了**。已统一到 ds-first,并在 B-7.1 加实测复核锚点;澄清 `6001 依赖于该数据集` 只属删*输入*数据集或 churn `NOT_FOUND` 幽灵场景,不属正常输出集清理。删掉了草案误提的「按错误码自动判别顺序」兜底规则(红队证伪:套到 line 219 会反向推翻已实测的 ds-first)。
- **`guanetl delete` 命令引用清理**:README.md / README.en.md 路由表把 0.1.14 已移除的 `guanetl delete` 从命令串删除(本轮实跑 `guanetl --help` 确认 delete 不在命令列;README 自身 V3.0.5 changelog 已写「移除 delete」,路由表与之自相矛盾)。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 294)May include surrounding context.

md
### Fixed

- **🔴 删除顺序矛盾实测定案(P0 correctness)**:评审团发现 `SKILL.md` 对「ETL + 其输出数据集」的删除顺序自相矛盾——B-0.5 清理坑(line 219)与 Part D 删除段写「先删 ETL、反过来撞 6001」,而 B-7.1 / B-O step 10 / B-1 API 全图写「先删 ds、反过来撞 2002」。**2026-06-17 在 workshop513 真实实例做净零回归实测**(建两个一次性独立 DATAFLOW ETL、各测一个方向、测完全删):
  - `etl-first`(输出集还在就 `DELETE /api/etl`)→ **`2002 输出数据集已存在` 失败**;
  - `ds-first`(先 `DELETE /api/data-source/<输出dsId>`,ETL 还在)→ **`DataSource deleted` 成功、不报 6001**;再 `DELETE /api/etl` → 成功。
  - 裁决:**B-7.1 / line 233 / 255-256 正确(ds-first),line 219 与 Part D 删除段记反了**。已统一到 ds-first,并在 B-7.1 加实测复核锚点;澄清 `6001 依赖于该数据集` 只属删*输入*数据集或 churn `NOT_FOUND` 幽灵场景,不属正常输出集清理。删掉了草案误提的「按错误码自动判别顺序」兜底规则(红队证伪:套到 line 219 会反向推翻已实测的 ds-first)。
- **`guanetl delete` 命令引用清理**:README.md / README.en.md 路由表把 0.1.14 已移除的 `guanetl delete` 从命令串删除(本轮实跑 `guanetl --help` 确认 delete 不在命令列;README 自身 V3.0.5 changelog 已写「移除 delete」,路由表与之自相矛盾)。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 295)May include surrounding context.

md
- **🔴 删除顺序矛盾实测定案(P0 correctness)**:评审团发现 `SKILL.md` 对「ETL + 其输出数据集」的删除顺序自相矛盾——B-0.5 清理坑(line 219)与 Part D 删除段写「先删 ETL、反过来撞 6001」,而 B-7.1 / B-〇 step 10 / B-1 API 全图写「先删 ds、反过来撞 2002」。**2026-06-17 在 workshop513 真实实例做净零回归实测**(建两个一次性独立 DATAFLOW ETL、各测一个方向、测完全删):
  - `etl-first`(输出集还在就 `DELETE /api/etl`)→ **`2002 输出数据集已存在` 失败**;
  - `ds-first`(先 `DELETE /api/data-source/<输出dsId>`,ETL 还在)→ **`DataSource deleted` 成功、不报 6001**;再 `DELETE /api/etl` → 成功。
  - 裁决:**B-7.1 / line 233 / 255-256 正确(ds-first),line 219 与 Part D 删除段记反了**。已统一到 ds-first,并在 B-7.1 加实测复核锚点;澄清 `6001 依赖于该数据集` 只属删*输入*数据集或 churn `NOT_FOUND` 幽灵场景,不属正常输出集清理。删掉了草案误提的「按错误码自动判别顺序」兜底规则(红队证伪:套到 line 219 会反向推翻已实测的 ds-first)。
- **`guanetl delete` 命令引用清理**:README.md / README.en.md 路由表把 0.1.14 已移除的 `guanetl delete` 从命令串删除(本轮实跑 `guanetl --help` 确认 delete 不在命令列;README 自身 V3.0.5 changelog 已写「移除 delete」,路由表与之自相矛盾)。
- **References 目录行数回填**:`## 📚 References 目录` 表里 8 条偏差 >20% 的 `~N` 行数估值回填(part-c-html-dashboard ~390→~620、part-e ~620→~760、ai-native ~340→~260、restaurant 02 ~350→~700 / 03→~240 / 04→~410 / 05→~160 / 06→~350、restaurant README ~90→~70),保留 `~` 约等号语义。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 295)May include surrounding context.

md
- **🔴 删除顺序矛盾实测定案(P0 correctness)**:评审团发现 `SKILL.md` 对「ETL + 其输出数据集」的删除顺序自相矛盾——B-0.5 清理坑(line 219)与 Part D 删除段写「先删 ETL、反过来撞 6001」,而 B-7.1 / B-〇 step 10 / B-1 API 全图写「先删 ds、反过来撞 2002」。**2026-06-17 在 workshop513 真实实例做净零回归实测**(建两个一次性独立 DATAFLOW ETL、各测一个方向、测完全删):
  - `etl-first`(输出集还在就 `DELETE /api/etl`)→ **`2002 输出数据集已存在` 失败**;
  - `ds-first`(先 `DELETE /api/data-source/<输出dsId>`,ETL 还在)→ **`DataSource deleted` 成功、不报 6001**;再 `DELETE /api/etl` → 成功。
  - 裁决:**B-7.1 / line 233 / 255-256 正确(ds-first),line 219 与 Part D 删除段记反了**。已统一到 ds-first,并在 B-7.1 加实测复核锚点;澄清 `6001 依赖于该数据集` 只属删*输入*数据集或 churn `NOT_FOUND` 幽灵场景,不属正常输出集清理。删掉了草案误提的「按错误码自动判别顺序」兜底规则(红队证伪:套到 line 219 会反向推翻已实测的 ds-first)。
- **`guanetl delete` 命令引用清理**:README.md / README.en.md 路由表把 0.1.14 已移除的 `guanetl delete` 从命令串删除(本轮实跑 `guanetl --help` 确认 delete 不在命令列;README 自身 V3.0.5 changelog 已写「移除 delete」,路由表与之自相矛盾)。
- **References 目录行数回填**:`## 📚 References 目录` 表里 8 条偏差 >20% 的 `~N` 行数估值回填(part-c-html-dashboard ~390→~620、part-e ~620→~760、ai-native ~340→~260、restaurant 02 ~350→~700 / 03→~240 / 04→~410 / 05→~160 / 06→~350、restaurant README ~90→~70),保留 `~` 约等号语义。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 295)May include surrounding context.

md
- **🔴 删除顺序矛盾实测定案(P0 correctness)**:评审团发现 `SKILL.md` 对「ETL + 其输出数据集」的删除顺序自相矛盾——B-0.5 清理坑(line 219)与 Part D 删除段写「先删 ETL、反过来撞 6001」,而 B-7.1 / B-O step 10 / B-1 API 全图写「先删 ds、反过来撞 2002」。**2026-06-17 在 workshop513 真实实例做净零回归实测**(建两个一次性独立 DATAFLOW ETL、各测一个方向、测完全删):
  - `etl-first`(输出集还在就 `DELETE /api/etl`)→ **`2002 输出数据集已存在` 失败**;
  - `ds-first`(先 `DELETE /api/data-source/<输出dsId>`,ETL 还在)→ **`DataSource deleted` 成功、不报 6001**;再 `DELETE /api/etl` → 成功。
  - 裁决:**B-7.1 / line 233 / 255-256 正确(ds-first),line 219 与 Part D 删除段记反了**。已统一到 ds-first,并在 B-7.1 加实测复核锚点;澄清 `6001 依赖于该数据集` 只属删*输入*数据集或 churn `NOT_FOUND` 幽灵场景,不属正常输出集清理。删掉了草案误提的「按错误码自动判别顺序」兜底规则(红队证伪:套到 line 219 会反向推翻已实测的 ds-first)。
- **`guanetl delete` 命令引用清理**:README.md / README.en.md 路由表把 0.1.14 已移除的 `guanetl delete` 从命令串删除(本轮实跑 `guanetl --help` 确认 delete 不在命令列;README 自身 V3.0.5 changelog 已写「移除 delete」,路由表与之自相矛盾)。
- **References 目录行数回填**:`## 📚 References 目录` 表里 8 条偏差 >20% 的 `~N` 行数估值回填(part-c-html-dashboard ~390→~620、part-e ~620→~760、ai-native ~340→~260、restaurant 02 ~350→~700 / 03→~240 / 04→~410 / 05→~160 / 06→~350、restaurant README ~90→~70),保留 `~` 约等号语义。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 303)May include surrounding context.

md
### Changed

- **`page?force=true` 级联删页纳入 B-7.0 删除安全闸(P0 safety)**:Part D 删除段把「`DELETE /api/page/<pgId>?force=true` 唯一可行」补成条件句——级联删整页内嵌卡片且不可逆,须用户逐项确认;**仅当本地保有该 page 的 guanvis 源(`page.js` / card 定义)可 republish 重建时确认即可、无需对账;BI UI 手搭、本地无源的发布页按不可逆 DELETE 走 B-7.0 完整对账**。B-13 红线(line 667)DELETE 括号补上 `/api/page/<id>?force=true`。
- **跨工具 / 橱窗元数据 drift 修正**:`AGENTS.md` 三处(frontmatter 示例 `metadata.version` 3.0.0→3.1.2、`~940 lines`→`~1060 lines`、家族列表给 `guanadmin`/`guanexport` 加「2026-06-04 退出、当前 5 件」括注,不删历史叙述);`.claude-plugin/marketplace.json` 橱窗描述去掉已退役 Part A、补 Part D/E/ADS,`version` 1.6.0→3.1.2。
- **`description` 瘦身**:删末尾「Claude Code/OpenClaw/Codex/Hermes 通用。」(已在 manifest.compatibility 四端声明),脱离 974/1024 上限区。红队判定「治理 vs 重搭」是 AI-native ADS 差异化指纹,保留不删。
- `config.example.json` 加 `_note` 说明它对 v3 已是死字段(认证走 `guancli auth login`),但**保留字段不删**——`bin/install.js` uninstall 逻辑用它比对用户是否改过 config.json、改过则删前自动备份。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 401)May include surrounding context.

md
- **workshop513 实盘实测沉淀**(BI 8.2.1-hf6,全 7 个官方 skill 读写跑通)—— v3 路由全部验证正确;新增 2 条只有真跑才知道的硬边界:
  - **Part B**:`guanetl edit` 逆向在此实例 **5/5 全失败**(API direct-save / BI UI / guanetl 自己 create+save 出来的全中,生成空 `etl.go`、`-v` 无报错、紧接 `save` 有清空线上 ETL 风险)→ 改现有 ETL 继续走 Part B `guancli fetch`。最小复现已提交观远官方。
  - **Part D**:删 guanvis-published 页面唯一可行 `DELETE /api/page/<id>?force=true`(卡片内嵌 `page.cards`、`/api/card` 删报 1002、guanvis 拒覆盖空页);删 ETL `DELETE /api/etl/<id>` 连带删输出集(先 ETL 后 ds,别用 `guanetl delete --cascade`)。

### Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 401)May include surrounding context.

md
- **workshop513 实盘实测沉淀**(BI 8.2.1-hf6,全 7 个官方 skill 读写跑通)—— v3 路由全部验证正确;新增 2 条只有真跑才知道的硬边界:
  - **Part B**:`guanetl edit` 逆向在此实例 **5/5 全失败**(API direct-save / BI UI / guanetl 自己 create+save 出来的全中,生成空 `etl.go`、`-v` 无报错、紧接 `save` 有清空线上 ETL 风险)→ 改现有 ETL 继续走 Part B `guancli fetch`。最小复现已提交观远官方。
  - **Part D**:删 guanvis-published 页面唯一可行 `DELETE /api/page/<id>?force=true`(卡片内嵌 `page.cards`、`/api/card` 删报 1002、guanvis 拒覆盖空页);删 ETL `DELETE /api/etl/<id>` 连带删输出集(先 ETL 后 ds,别用 `guanetl delete --cascade`)。

### Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · CHANGELOG.md (reported line 401)May include surrounding context.

md
- **workshop513 实盘实测沉淀**(BI 8.2.1-hf6,全 7 个官方 skill 读写跑通)—— v3 路由全部验证正确;新增 2 条只有真跑才知道的硬边界:
  - **Part B**:`guanetl edit` 逆向在此实例 **5/5 全失败**(API direct-save / BI UI / guanetl 自己 create+save 出来的全中,生成空 `etl.go`、`-v` 无报错、紧接 `save` 有清空线上 ETL 风险)→ 改现有 ETL 继续走 Part B `guancli fetch`。最小复现已提交观远官方。
  - **Part D**:删 guanvis-published 页面唯一可行 `DELETE /api/page/<id>?force=true`(卡片内嵌 `page.cards`、`/api/card` 删报 1002、guanvis 拒覆盖空页);删 ETL `DELETE /api/etl/<id>` 连带删输出集(先 ETL 后 ds,别用 `guanetl delete --cascade`)。

### Notes

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The mention of raw DELETE /api/etl/ operations in an automation-oriented skill increases the risk of tool parameter abuse, especially if an agent extrapolates from the docs and issues deletion requests with the wrong IDs or scope. In this context, the skill's domain makes such guidance more dangerous because it targets production BI assets and ETL pipelines, not inert examples.

Content

Scanner excerpt · README.en.md (reported line 73)May include surrounding context.

md
- ✅ **Field usage dual-source audit** (page + ETL grep — looking only at dashboards **overestimates removable fields by 8×**)
- ✅ **POST /api/etl/direct-save** — full payload schema for create + update (same endpoint)
- ✅ **Real error retrieval** — `status:FINISHED` is just the trigger result; the real error lives in `GET /api/task/<id>.response.result.error`
- ✅ **Delete topology**: `DELETE /api/data-source/` MUST come before `DELETE /api/etl/`
- ✅ **v2→v3 batch refactoring SDK**: `transformV2ToV3()` 7-step rewrite + node ID remapping
- ✅ **CTO Zhang Jin's full-chain rewrite methodology**: 4 deliverables + 8 hard rules + 5-step workflow + three-layer verification + diff tracking 5-step + empty snapshot handling

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The mention of raw DELETE /api/etl/ operations in an automation-oriented skill increases the risk of tool parameter abuse, especially if an agent extrapolates from the docs and issues deletion requests with the wrong IDs or scope. In this context, the skill's domain makes such guidance more dangerous because it targets production BI assets and ETL pipelines, not inert examples.

Content

Scanner excerpt · README.en.md (reported line 73)May include surrounding context.

md
- ✅ **Field usage dual-source audit** (page + ETL grep — looking only at dashboards **overestimates removable fields by 8×**)
- ✅ **POST /api/etl/direct-save** — full payload schema for create + update (same endpoint)
- ✅ **Real error retrieval** — `status:FINISHED` is just the trigger result; the real error lives in `GET /api/task/<id>.response.result.error`
- ✅ **Delete topology**: `DELETE /api/data-source/` MUST come before `DELETE /api/etl/`
- ✅ **v2→v3 batch refactoring SDK**: `transformV2ToV3()` 7-step rewrite + node ID remapping
- ✅ **CTO Zhang Jin's full-chain rewrite methodology**: 4 deliverables + 8 hard rules + 5-step workflow + three-layer verification + diff tracking 5-step + empty snapshot handling

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 72)May include surrounding context.

md
- ✅ **字段使用度双源审计**(page + etl 双源 grep,避免**仅看板会高估 8 倍可裁字段**)
- ✅ **POST /api/etl/direct-save** create + update 同接口的完整 payload schema
- ✅ **task error 真错误定位**(`status:FINISHED` 是任务触发结果,真错误在 `GET /api/task/<id>.response.result.error`)
- ✅ **删除拓扑**:`DELETE /api/data-source/` 必须先于 `DELETE /api/etl/`
- ✅ **v2→v3 批量改造 SDK**:`transformV2ToV3()` 7 步重写 + 节点 ID 重映射
- ✅ **CTO 张进的全链路重写方法论**:4 件交付 + 8 条硬规则 + 5 步标准工作流 + 三层验收 + 差异追踪 5 步法 + 空快照处理标准

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 524)May include surrounding context.

md
- ✅ **字段使用度双源审计**(page + etl 双源 grep,避免**仅看板会高估 8 倍可裁字段**)
- ✅ **POST /api/etl/direct-save** create + update 同接口的完整 payload schema
- ✅ **task error 真错误定位**(`status:FINISHED` 是任务触发结果,真错误在 `GET /api/task/<id>.response.result.error`)
- ✅ **删除拓扑**:`DELETE /api/data-source/` 必须先于 `DELETE /api/etl/`
- ✅ **v2→v3 批量改造 SDK**:`transformV2ToV3()` 7 步重写 + 节点 ID 重映射
- ✅ **CTO 张进的全链路重写方法论**:4 件交付 + 8 条硬规则 + 5 步标准工作流 + 三层验收 + 差异追踪 5 步法 + 空快照处理标准

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · README.md (reported line 72)May include surrounding context.

md
- ✅ **字段使用度双源审计**(page + etl 双源 grep,避免**仅看板会高估 8 倍可裁字段**)
- ✅ **POST /api/etl/direct-save** create + update 同接口的完整 payload schema
- ✅ **task error 真错误定位**(`status:FINISHED` 是任务触发结果,真错误在 `GET /api/task/<id>.response.result.error`)
- ✅ **删除拓扑**:`DELETE /api/data-source/` 必须先于 `DELETE /api/etl/`
- ✅ **v2→v3 批量改造 SDK**:`transformV2ToV3()` 7 步重写 + 节点 ID 重映射
- ✅ **CTO 张进的全链路重写方法论**:4 件交付 + 8 条硬规则 + 5 步标准工作流 + 三层验收 + 差异追踪 5 步法 + 空快照处理标准

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 524)May include surrounding context.

md
- ✅ **字段使用度双源审计**(page + etl 双源 grep,避免**仅看板会高估 8 倍可裁字段**)
- ✅ **POST /api/etl/direct-save** create + update 同接口的完整 payload schema
- ✅ **task error 真错误定位**(`status:FINISHED` 是任务触发结果,真错误在 `GET /api/task/<id>.response.result.error`)
- ✅ **删除拓扑**:`DELETE /api/data-source/` 必须先于 `DELETE /api/etl/`
- ✅ **v2→v3 批量改造 SDK**:`transformV2ToV3()` 7 步重写 + 节点 ID 重映射
- ✅ **CTO 张进的全链路重写方法论**:4 件交付 + 8 条硬规则 + 5 步标准工作流 + 三层验收 + 差异追踪 5 步法 + 空快照处理标准

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill provides Guandata BI/ETL/querying/workflow/chart/mobile/SuperApp analytical capabilities. However, the supplied code chunk does not implement any BI querying, ETL processing, workflow management, chart troubleshooting, phoneLayout handling, metric writing, or SuperApp/LLM routing. Its primary function is packaging/deployment: installing, uninstalling, and listing the skill in local agent directories via filesystem operations. This is a materially different purpose from the declared operational BI enhancement layer, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a very broad operational Guandata skill with multiple BI/ETL/admin/governance/integration capabilities. The supplied code chunk is much narrower: it only renders an HTML executive dashboard from already-supplied data arrays. Its functions are limited to extracting rows/columns, formatting KPI and table/list HTML, escaping values, and mounting the result with CSS. While the description does mention custom charts and HTML dashboards, this specific code does not implement the majority of the declared functionality, and its primary purpose is a focused dashboard presentation component rather than a comprehensive Guandata operations layer. Therefore the description materially overstates and misrepresents what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

该代码块是一个非常具体的前端图表模板文件,用于在 HTML 看板中展示“月度渠道趋势”。它只做列识别、行聚合、生成 SVG/HTML 片段并挂载到页面,属于自定义图表/HTML 看板渲染实现。虽然声明中提到“自定义图表与 HTML 看板排障”,这与代码类型存在部分弱相关,但声明把技能整体描述为覆盖标准查数、ETL 治理、数据集管理、工作流、指标写入、SuperApp/ADS 架构判断等一整套复杂能力;而本代码并未实现这些核心能力,实际功能范围远小且主目的明显不同。因此应判定为描述与代码行为存在实质性不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
> **兼容工具**:Claude Code · OpenClaw · Codex · Hermes (gbrain) · 任何支持 `SKILL.md` frontmatter 的 agent。详见 [README · 兼容性](README.md#-兼容性--compatibility) 与 [AGENTS.md]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
面初始化保护。详见 [兼容说明](references/official-cli-compatibility.md);完整历史见 [CHANGELOG.md](CHANGELOG.md)。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1045)May include surrounding context.

md
面初始化保护。详见 [兼容说明](references/official-cli-compatibility.md);完整历史见 [CHANGELOG.md](CHANGELOG.md)。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to perform direct destructive API operations such as DELETE /api/etl/<id> outside a narrowly constrained wrapper. Even though safety notes are present elsewhere, embedding raw deletion procedures in a broadly activated skill increases the chance of irreversible destructive actions against production BI resources.

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

md
>
> 🧪 **实测边界(2026-06-04 · workshop513 · BI 8.2.1-hf6)**:guanetl `edit` 的 base→etl.go 逆向在 **0.1.12 / 0.1.13 完全失效**(空 `return []Node{}`,5/5 ETL 全复现、`-v` 无报错);`save` 的输出绑定 guard 也误触发。**0.1.14 两个 bug 均已修复**(2026-06-09 workshop513 实测:`ads_会员经营任务池` 6 节点 `edit→export→lint→save` 全链路通过)。改现有 ETL 现在可以走 `guanetl edit` 正常路径了。**B-0.5 绕过方案仍保留作 fallback 参考**(万一其他 BI 版本 / 节点类型仍触发)。
>
> ⚡ **0.1.14 修复确认**(2026-06-09 复测):① `edit` 空 `etl.go`(Wall 1)→ ✅ 已修,6 节点完整逆向为 `BasicInputDataset×4 + BasicSqlScript + BasicOutputDatasetInDir`;② `save` 输出绑定 guard 误触发(Wall 2)→ ✅ 已修,save 直接成功不再拦截。另:**0.1.14 移除了 `delete` 命令**,删 ETL 改走 BI UI 或直接 `DELETE /api/etl/<id>` API。**0.1.15(2026-06-15)进一步增强 `save` 输出数据集保护(保留级联相关配置)+ 对追加写入场景的行数据结构提前校验**——改 ETL 走 `guanetl edit` 正常路径更稳。**0.1.16(2026-06-17)再加 `save --dry-run` 保存影响预览 + `run` 执行前提示上游数据集失败态 + `preview` 提示 LEFT JOIN 桥接列全空样本**,改 ETL 前可先 `--dry-run` 看影响面。**0.1.17(2026-06-24)仅 `install-skill` 适配 WorkBuddy 目录,ETL 行为无变化。** **0.1.18(2026-07-01)建 ETL 时目录类型诊断更清晰(识别误用工作流/经典数据流目录、提示用智能 ETL 目录)。** **0.1.19(2026-07-08)新增 `move`(移 ETL 到指定目录,接口异常时读回确认)+ `run --run-upstream`(递归解析上游链路按拓扑顺序执行,配 `--dry-run`)+ `run --wait` 遇 40001「已在运行」改为查找并等待现有任务(减少级联触发后重复 run 的误判失败)+ `export` 静态检查 JOIN 键类型不一致 warning(STRING/LONG 隐式 coercion 风险)。** **0.1.21(07-24)JOIN 类型检查扩至 preview/save/run。** **0.1.22–0.1.27(07-25~08-10)** 写操作回显实际目标环境 + 多节点并行 preview + 运行中任务可直接跟踪 + 输出落位闭环 / JOIN 未知类型拦截 + `save` 影响报告字段级明细 + 首次运行后临时输出集完成生成再做字段检查。

> **2026-09-14 官方对齐**:`guanetl 0.1.34` 新建须明确两类目录,执行按 ETL ID 跟踪且不再提供全局 `task`;0.1.31 已修复历史节点 ID 下划线导出。上述为官方文档与命令核验,未重跑线上 ETL。详见 [兼容说明](references/official-cli-compatibility.md)。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicated finding still reflects a valid concern: the skill provides exact dataset deletion instructions for authenticated BI sessions. In context, that can enable irreversible cleanup of production resources.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
- **高级逃生**(仅在没法重建时):手工构造 `_exported.json` = fresh `_base` 的 actions + 保留 output `dataSource.dsId` + 你的**逻辑**改动,再 `guanetl save`。
- **认证别绕**:BI API 是 **cookie/session 认证**——写操作一律走 `guanetl save` / `guands`(它们持有正确会话)。

**清理坑**:~~`guanetl delete --cascade`~~(0.1.14 起无 delete 命令)。删 ETL + 孤儿输出集走 `DELETE` API,**顺序必须先删输出数据集、再删 ETL(与 B-7.1 一致)**;反过来先删 ETL → `2002 输出数据集已存在` 失败。**2026-06-17 · workshop513 实测定案**(独立 DATAFLOW ETL,净零回归):`DELETE /api/data-source/<输出dsId>`(ETL 还在)→ `DataSource deleted` 成功、**不报 6001**;再 `DELETE /api/etl/<id>` → 成功。churn 出的中间绑定是另一回事——删 ETL 后多为 `NOT_FOUND` 幽灵(`ds get`=1002 但 `ds delete`=6001,不可见、无害)。

## B-〇. 推荐工作流(先治理再重建)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

This duplicated finding still reflects a valid concern: the skill provides exact dataset deletion instructions for authenticated BI sessions. In context, that can enable irreversible cleanup of production resources.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
- **高级逃生**(仅在没法重建时):手工构造 `_exported.json` = fresh `_base` 的 actions + 保留 output `dataSource.dsId` + 你的**逻辑**改动,再 `guanetl save`。
- **认证别绕**:BI API 是 **cookie/session 认证**——写操作一律走 `guanetl save` / `guands`(它们持有正确会话)。

**清理坑**:~~`guanetl delete --cascade`~~(0.1.14 起无 delete 命令)。删 ETL + 孤儿输出集走 `DELETE` API,**顺序必须先删输出数据集、再删 ETL(与 B-7.1 一致)**;反过来先删 ETL → `2002 输出数据集已存在` 失败。**2026-06-17 · workshop513 实测定案**(独立 DATAFLOW ETL,净零回归):`DELETE /api/data-source/<输出dsId>`(ETL 还在)→ `DataSource deleted` 成功、**不报 6001**;再 `DELETE /api/etl/<id>` → 成功。churn 出的中间绑定是另一回事——删 ETL 后多为 `NOT_FOUND` 幽灵(`ds get`=1002 但 `ds delete`=6001,不可见、无害)。

## B-〇. 推荐工作流(先治理再重建)

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
templates/html-dashboard/charts/html_common.js:7

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
templates/html-dashboard/charts/html_executive.js:12

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
templates/html-dashboard/charts/html_trend.js:12