Back to skill

Security audit

私域专家团 · 马甲实战版

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed private-domain operations toolkit with scoped local archives, reports, and update behavior; I found no evidence of hidden exfiltration, destructive actions, or deceptive behavior.

Install only if you want a Chinese private-domain operations assistant that can create local plaintext customer archives and reports. Prefer explicit commands such as /siyu-save, /siyu-restore, /siyu-report, and /siyu-update, review saved reports before sharing them, and avoid storing sensitive customer data unless you are comfortable with local unencrypted files under ~/.siyu.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (25)

Lp3

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding
The skill instructs the agent to read multiple local files and module paths, but no explicit permissions are declared. That creates a trust and containment gap: an integrator or reviewer may assume the skill is metadata-only while it actually relies on filesystem access, increasing the chance of unintended file exposure or overbroad runtime grants.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill presents itself as a broad private-domain operations expert and claims strict real-time verification for dynamic facts, but the observed behavior includes local knowledge-base querying, schema validation, and limited static compliance scanning rather than the full represented capability. This mismatch is dangerous because users may overtrust outputs as current, comprehensive, or externally verified when the implementation may not actually provide that assurance.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
This sub-agent explicitly centers on conversion funnel metrics, caliber definitions, and instrumentation (e.g., UV→加微→首单→复购, 可埋点指标, 真实 SOP/阈值, and a bound skill named conversion-caliber), which conflicts with the parent skill boundary that says explicit metric definitions, formulas, SQL, data dictionaries, and related data-validation work must be routed elsewhere. That mismatch can cause the wrong agent to handle restricted data-analysis tasks, leading to boundary bypass, inconsistent outputs, and policy noncompliance.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The file embeds concrete pricing, capacity, and platform-rule claims as static knowledge even though the skill manifest explicitly requires real-time verification with evidence for vendor/product/price/policy/platform-rule facts. If the agent relies on these stale values, it can mislead users about current enterprise WeChat limits, fees, or operational constraints, causing bad purchasing or implementation decisions.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
This knowledge file contains metric definitions and benchmark material even though the manifest says content centered on indicator definitions, formulas, SQL, data dictionaries, and membership/dashboard metrics should be handled by a different skill. That routing mismatch can cause the wrong skill to answer with out-of-scope benchmark guidance, increasing the chance of inaccurate advice and bypassing the intended specialized controls.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill explicitly defines conversion metrics, numerators/denominators, and time windows, which overlaps with the parent manifest's stated boundary that metric definitions, formulas, SQL, and data-calculation work should be handled by another skill. This can cause misrouting of users into the wrong skill, leading to inconsistent KPI definitions, broken governance, and incorrect business decisions based on conflicting metric logic.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The documentation tells users to route back to /siyu for next-step selection, even though the parent manifest says explicit metric-definition questions should bypass this path and go to another skill. In practice, this can trap users in the wrong routing loop or cause the navigation layer to select a skill that violates the declared safety and ownership boundaries for data definitions.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill explicitly instructs writing a file to `.siyu-team/02x-*.md` without any user-facing warning, confirmation, or permission boundary. In an agent environment, silent file modification can create integrity and auditability issues, especially if the caller did not expect persistent side effects or if filenames are influenced by upstream tasking.

Missing User Warnings

Low
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to write output into a project-local '.siyu-team/02x-*.md' path without any disclosure, consent, or safety checks. Hidden filesystem writes can create integrity and privacy risks, especially if user inputs or sensitive client information are persisted unexpectedly or to attacker-influenced filenames/locations.

Vague Triggers

Low
Confidence
86% confidence
Finding
The manifest exposes many broadly named sub-skills without any machine-readable activation constraints, precedence rules, or exclusion metadata. In a routing system, this can cause overbroad or incorrect skill invocation, especially where the top-level skill description already contains nuanced boundary conditions that are not enforced in the manifest itself.

Natural-Language Policy Violations

Medium
Confidence
80% confidence
Finding
The identifiers are tightly coupled to Chinese private-domain marketing and WeChat-specific workflows, but the manifest does not record any user opt-in, region gating, or locale justification. This can lead to the wrong skill being selected for users in other jurisdictions or contexts, increasing the chance of non-compliant advice, privacy missteps, or platform-inappropriate guidance.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger text is broad enough that the skill may activate for a wide range of loosely related '运营/漏斗/埋点' requests without explicit exclusion criteria. In a multi-skill routing context, this can cause misrouting, inappropriate handling of requests that need other specialized skills, and lower-quality or unsafe guidance if the wrong workflow is applied.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill description is broad enough to activate on generic planning or copywriting requests related to community operations, which can cause incorrect routing and overshadow more appropriate specialized skills. In this repository, misrouting matters because the parent skill explicitly says data-heavy topics should be handed off elsewhere; over-broad triggering can bypass those boundaries and lead to lower-quality or policy-inconsistent outputs.

Natural-Language Policy Violations

Medium
Confidence
87% confidence
Finding
The description is written to operate in Chinese without indicating that language should follow user preference, which can force an unexpected language switch during invocation. This is primarily a safety and usability issue: it can degrade transparency, cause misunderstanding, and make downstream instructions or compliance notices less clear for users who did not request Chinese.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The skill description contains broad trigger phrases such as multiple open-ended examples of when to use the skill, but the boundary conditions are only partially constrained later in the file. In an agentic routing system, this can cause over-selection of this skill for adjacent tasks, leading to incorrect handling of requests, bypass of more appropriate specialized skills, or generation of content outside intended controls.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill description contains broad trigger phrases such as '写社群群发、群发通知、社群栏目推送、做群活动文案、私域群运营发消息、救群发打开率时', which can cause the router to invoke this skill for a wide range of loosely related requests. Because the skill can generate outbound mass-messaging copy and operational guidance, overbroad routing increases the chance of misapplication, bypass of more specialized skills, and unsafe or non-compliant outputs in contexts the skill is not designed to handle.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases include broad everyday terms like '打包', '整理一份', and '给老板或客户看', which can cause the skill to activate in situations where the user did not intend to generate a client report. Because this skill reads and merges local client archives into a new file, accidental invocation can expose sensitive client information or create unauthorized report artifacts.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill writes a merged report file from local client archives, but it does not present an upfront warning that the output may contain sensitive or personally identifiable information copied from prior archives. In a cross-conversation archive context, users may not realize the report is persisted to disk and may be suitable for sharing, increasing the risk of unintended disclosure.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill defines trigger phrases including very broad everyday expressions such as “上次”“接着”“之前聊到哪了”, which can cause unintended invocation during normal conversation. Because this skill restores local customer archives and cross-dialog state, accidental activation may expose prior client context or steer the session based on stale private data without explicit user intent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger list includes broad natural-language phrases such as '保存', '记下来', and '这个结论留着', which are common conversational utterances rather than narrowly scoped commands. In an agent environment, this can cause unintended activation and local file writes based on ordinary dialogue, creating a risk of accidental persistence of sensitive customer information.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list includes broad everyday phrases such as “转化差怎么办”, “群不活跃”, and “我有个私域问题”, which are common in ordinary conversation and can cause the skill to activate when the user did not explicitly intend to invoke it. Unintended routing is dangerous here because this skill enforces a rigid diagnostic flow and may divert users away from better-matched skills or inject domain-specific guidance into unrelated contexts.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
Mandating Chinese output for all users without checking user preference can cause accessibility and usability failures, especially in multilingual environments or when the surrounding system expects another language. While not directly a security exploit in isolation, it can contribute to unsafe misunderstandings, incorrect task routing, or failed handoff if users cannot reliably understand the output.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill description mixes many distinct business functions and only partially defines routing boundaries, which can cause the agent to invoke this skill for requests better handled by other skills or with different safety requirements. In a multi-skill system, ambiguous invocation scope increases the chance of incorrect tool selection, stale or unsupported guidance, and bypass of specialized controls described elsewhere.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger condition '模式 C 触发后' is underspecified, so the system may invoke this tutorial in unintended contexts. In an agent skill that can route into other skills and continue execution automatically, ambiguous activation increases the chance of misrouting, unwanted task execution, or bypassing user intent boundaries.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The tutorial language is very broad and overlaps with ordinary private-domain operations discussion, which can cause over-triggering from normal user messages. Because the skill is designed to infer the 'most needed next step' and immediately hand off to another skill, this broad framing raises the risk of unsolicited routing and actions beyond what the user explicitly asked for.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.