Back to skill

Security audit

会员运营 · 马甲实战版

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent membership-analytics reference skill with simulated data and advisory SQL; its main risks are privacy and business-decision caution when users adapt it to real customer systems.

Before using this with real customer or store data, treat member IDs, phone hashes, OpenID/UnionID, outreach history, reviews, and task assignments as sensitive. Validate all SQL against your own schemas, honor consent and do-not-contact rules, verify webhook recipients, and require human review before acting on recommendations such as store closure review, customer recovery, or staff/task assignment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (47)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · README.en.md (reported line 1)May include surrounding context.

md
# majia-huiyuan · Membership Ops Playbook <!-- plain-ok -->

[![Skill Version](https://img.shields.io/badge/skill-v1.4.5-blue)](./SKILL.md)
[![License: MIT](https://img.shields.io/badge/license-MIT-green)](./LICENSE)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The card is presented as row-level exception detail, but the query uses max() across many fields without grouping keys, which collapses multiple records into a synthetic summary row rather than preserving individual exceptions. In this skill context, that is especially dangerous because users may rely on the table for per-store/per-manager action, causing missed urgent anomalies or incorrect remediation assignments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The title and core instruction text are written entirely in Chinese, and L03 directs the agent on how to answer the user without indicating that other languages are allowed. This creates a language/locale policy concern because the skill appears to impose a specific language by default rather than offering user opt-in or choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file describes processing datasets containing member identifiers and member outreach data, then writing the results to an output dataset, but it does not include any warning about handling potentially sensitive personal or behavioral data. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data or privacy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction is written as a direct behavioral requirement to the assistant in Chinese and frames the task entirely in that language, without offering the user any language or locale choice. This is a natural-language policy concern because it imposes a specific language mode rather than documenting a justified region-specific constraint or allowing opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The ETL logic emits an operational recommendation of '启动关店评估' when store contribution profit is negative, but the skill provides no caution that this is a heuristic output based on simulated/demo-style thresholds and not a sufficient basis for high-impact business decisions. In this skill’s context, the recommendation is more dangerous because the skill is explicitly positioned as a data advisor for membership and store operations, so downstream users may treat the generated action text as authoritative and trigger harmful real-world actions without human review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file content is entirely framed as a Chinese-language instruction to the assistant ('你是一个ETL专家...') and does not offer the user any choice of language or locale. This creates a natural-language policy issue because the skill effectively imposes a language constraint without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file is written as an instruction to the agent in Chinese and does not offer any language or locale choice to the user. Under the policy, natural-language instructions that implicitly require a specific language without opt-in should be flagged unless clearly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file is written as an instruction prompt and begins with a Chinese-only directive to act as an ETL expert, with no indication that the user may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire user-facing content is written in Chinese and provides no indication that other languages are supported or that the file is intentionally limited to a Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README tells users to test the installed skill with Chinese-only example prompts, and the overall skill documentation is entirely presented in Chinese without stating that other languages are supported. This can indicate a language/locale constraint imposed on users without explicit opt-in or choice, which matches the policy-violation category for natural-language language restrictions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

该文件全文以中文直接规定阅读和使用方式,未看到任何关于语言选择、可切换 locale 或仅面向特定中文业务团队的说明。按照规则,若技能内容强制特定语言且没有用户 opt-in 或明确地域/合规理由,可构成自然语言层面的语言政策问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section operationalizes member outreach and task assignment using behavioral, lifecycle, coupon, and channel-migration data, but it does not explicitly require lawful basis, contact consent, opt-out handling, or purpose limitation before triggering outreach. In a CRM/member-operations skill, that omission can lead users to implement recontact workflows that process personal data and send messages to members who have not consented or have already refused contact, creating privacy, compliance, and customer-harm risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The negative-review recovery section recommends follow-up contact based on review content, ratings, and platform data, and even states such tasks should bypass normal anti-disturbance suppression. Without an explicit requirement to validate identity linkage, complaint-handling authority, and contact permission, this can result in sensitive customer-feedback data being used for direct outreach in ways that violate consent, platform terms, or privacy obligations; bypassing suppression further increases the chance of contacting members who have opted out or are in a sensitive service dispute.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown explains that store-level analysis results and assigned tasks are pushed to WeCom or Feishu groups through a webhook, which is a data transmission step that could affect privacy or expose operational information. Although the file notes human confirmation before sending, it does not warn readers about reviewing recipients, webhook destinations, or the sensitivity of the transmitted content.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document header states that 到店销售占比 was renamed to 到店销售额占比 DOUBLE and that a new 数据快照日期 DATE field was added, but the detailed schema and Malloy definition still show the old field and omit the new one. In a membership analytics skill, this schema drift can cause downstream SQL, BI models, and operational targeting logic to use stale or incorrect fields, leading to inaccurate dashboards, broken pipelines, or mis-segmentation of members.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The header at L001-L004 states that v1.4.1 currently outputs 56 columns including five new fields, but the dataset metadata at L018 and L030 and the field list that follows still document 51 columns. This is an active contradiction in the file's own documentation, not merely an incomplete description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file says the current output includes five added fields such as 投资起始日 and 数据快照日期, yet the Malloy source section at L346-L405 enumerates only the older 51 base columns and does not include those additions. Because the document frames this section as the source definition for the dataset, it contradicts the earlier statement about the actual current schema.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document begins entirely in Chinese and frames the dataset description in that language without any indication that users may choose another language or that the skill is intentionally limited to a Chinese-language context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file enumerates multiple identity-linking fields such as membership ID, card number, phone hash, OpenID, UnionID, enterprise contact ID, and payment-channel user ID without any privacy warning, minimization guidance, or handling restrictions. In the context of a member identity bridge and OneID-style identity resolution, this materially increases the risk of cross-system re-identification, unauthorized joining of identities, and misuse of sensitive customer data even if the values are described as simulated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file explicitly documents a 会员ID/member identifier field in a customer analytics dataset but provides no masking, minimization, access-control, or privacy-handling warning. In a membership/CDP/CRM context, even schema-level disclosure of persistent identifiers increases the risk of downstream misuse, overexposure, and linkage with other customer attributes such as city, level, and behavioral metrics.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Line L001 instructs the assistant in Chinese and frames the skill as operating as a BI expert, but the file provides no option for user language preference or opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The card is described as a de-duplicated store count, but the query only aggregates 门店ID directly and does not clearly perform a distinct count. This can misstate operational blast radius and drive incorrect prioritization or staffing decisions during exception handling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Both Top10 charts claim to rank by exception volume, but the queries sort by 门店ID instead of the computed count metric. That can surface the wrong categories or managers, misleading triage, accountability, and resource allocation in an incident-response style dashboard.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file's natural-language instructions and output labels are written entirely in Chinese, with no indication that another language is supported or that the locale restriction is intentional. Under the stated policy, forcing a specific language without opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.