Back to skill

Security audit

私域专家团 · 马甲实战版

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a disclosed private-domain operations assistant, but its self-update and restore features can persistently change future agent behavior and need review before installation.

Review the update module carefully before installing or using /siyu-update; prefer pinned, verified versions and avoid global updates unless you trust the publisher and host prompt. Treat ~/.siyu/ client archives as unencrypted local files, choose redacted saves for sensitive business data, and confirm any restored next step before letting it route work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
references/整盘怎么搭-老板版.md:128
Finding

Mandatory Skill Branding Injected into User Deliverables

Content
View full analysis
` file with no external dependencies. Requirements: - CSS variables supporting light and dark themes. - A title, five-step map, interactive checklist, and progress storage. - Mobile-friendly layout. - Add a discreet footer signature: `Private-Domain Expert Team · Majia Practical Edition`. ``` ### Technical Analysis The reference does not merely document the project’s identity. It directs the Agent to insert a fixed Skill-specific signature into an HTML artifact produced for the user. This branding is not necessary to generate the requested private-domain operations guide. Because the primary Skill routes ordinary store-owner requests through this reference, the instruction can directly affect user-facing output. It therefore crosses the boundary from documentation into operational output manipulation. The fixed footer can be included even when the user did not ask for attribution, co-branding, or promotion. This constitutes instruction hijacking because loading the Skill modifies the content requirements of the current task for the Skill author’s benefit. ### Attack Path 1. A user requests a private-domain operations guide or interactive web page. 2. The primary Skill selects the store-owner workflow. 3. The Agent loads `references/整盘怎么搭-老板版.md`. 4. The reference instructs the Agent to add the fixed footer signature. 5. The generated artifact contains Skill branding despite the user not requesting it. ### Impact Assessment The issue does not provide operating-system privileges or direct access to sensitive data. Its scope is the integrity of generated output. Potential consequences ...[truncated 278 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
modules/siyu-update/SKILL.md:9
Finding

Unpinned Remote Installer Executes Mutable Dependencies and Modifies Global Skill State

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Warning
Location
modules/siyu-restore/SKILL.md:40
Finding

Manually Editable Customer Archives Can Poison Future Agent Context and Routing

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (113)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向私域运营咨询的综合型 Skill,覆盖经营诊断、引流、欢迎语、厂商选型、报价与市场信息核验等多类任务,并带有明确的联网核验边界。给定代码却只实现了单一的“话术合规前置扫描”功能:从文件或标准输入读取文本,调用静态扫描器筛选若干合规标记并输出整改提示。虽然“欢迎语”属于声明场景的一小部分,但该代码的主功能是合规 lint,不是私域经营诊断或综合专家团能力,也没有任何联网核验、市场/厂商分析、客户档案导航或数据分流逻辑。因此这是明显的描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向私域运营场景的综合专家入口,覆盖诊断、策略、引流、厂商研究以及动态事实联网核验等高层业务能力。代码则只是一个本地脚本,专门对朋友圈文案做合规前置扫描,筛查如 COMPLIANCE_RED、ABSOLUTE_CLAIM、PRIVACY_COLLECT 等风险标签,并根据命中情况返回状态码。这属于较为具体的“文案合规检查”能力。虽然声明中提到处理‘朋友圈’,与代码主题存在弱相关,但代码既没有实现私域诊断/搭建,也没有实现厂商、价格、政策、平台规则等需要联网核验的流程,主用途与声明的综合顾问型定位存在实质差异。因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

描述把该 Skill 定位为一个广义的“私域专家团”咨询/诊断入口,覆盖运营策略、引流、厂商选型、市场信息核验等场景;而提供的代码仅实现了一个非常具体的群发文案合规前置扫描脚本。虽然“群发”属于声明覆盖的话题范围之一,但这里的核心交付物不是运营建议或诊断,而是基于词库的风险检测与退出码控制,属于明显更窄且不同的主要功能。此外,声明中强调对厂商/价格/规则等动态信息要实时联网核验并附证据,但代码没有任何联网、证据收集或事实核验逻辑。综合来看,代码行为与声明的主要用途并不一致,存在能力与目的层面的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个面向业务场景的“私域专家团”技能入口,核心价值在于回答和诊断私域经营问题,并在涉及厂商、价格、政策、平台规则等动态事实上进行实时联网核验;还包含对数据分析类问题的边界判断与转交。相比之下,给出的代码只是一个底层语料查询 CLI 工具,作用是从本地 corpus/manifest/JSONL 中筛选并打印知识原子。代码没有任何联网、证据附加、私域策略分析、厂商比较、客户档案处理、任务后导航,或问题分流判断的实现。虽然该工具可能是上层 Skill 的支撑组件之一,但就这段代码本身而言,其实际行为与声明的主要用途明显不一致,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向私域运营业务问题的专家型 Skill,核心能力应是提供运营策略诊断、话术/引流/选型建议,以及必要时联网核验动态商业信息。实际代码则完全是开发/内容治理侧的离线校验脚本,用于校验知识原子 JSONL 数据是否符合既定结构规范,与私域运营咨询场景无直接关系。代码没有实现任何朋友圈、群发、欢迎语、企微引流、私域诊断、厂商选型、市场地图、客户档案导航或联网事实核验能力,反而实现了未声明的本地文件解析、schema 校验、目录扫描和 CLI 返回码控制。因此其主要用途与声明严重不符,属于明显的描述-行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向私域运营咨询与诊断的综合业务 skill,重点在私域运营场景处理、厂商选型、市场信息核验以及根据问题类型路由到其他 skill。代码却并未实现这些核心能力,也没有联网核验、厂商/产品分析、客户档案、任务导航或路由逻辑。相反,它实现的是一个底层的合规词法规则库,服务于静态扫描和 lint,用于检查文本中的广告法、平台风险和隐私采集合规问题。虽然声明中提到朋友圈、群发、欢迎语等场景,代码中的“诱导分享”“隐私索取”等规则与这些场景存在弱相关,但其主要目的明显是合规检测组件,而非所声明的私域经营专家入口。因此属于明显的描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向私域运营业务问答与诊断的技能入口,重点在营销运营场景、厂商/价格/案例等信息核验,以及与会员数据类问题的路由边界。实际代码却完全没有实现任何私域运营分析、联网核验、厂商查询、内容生成、路由判断或数据口径识别逻辑。相反,它是一个内部评测/合规系统的数据契约层:定义 ScanHit、ScanResult、JudgeReport 等模型,并校验评分状态、维度、理由、元数据和独立评审要求。这属于 materially different primary purpose,且体现了未声明的能力(合规扫描/评审建模)。因此应判定为描述与代码行为明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个面向私域运营业务的专家型 Skill,核心能力应是诊断、策划、搭建、厂商选型与动态事实联网核验;而提供的代码片段完全聚焦于文本合规扫描与红线拦截,是独立且不同的主要功能。虽然合规检查可能作为某些业务流程的辅助环节存在,但该代码的主用途明显不是私域专家咨询,也没有实现声明中特别强调的联网核验、行业信息查询、私域经营诊断或数据路由能力。因此属于描述与实际行为的明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

这段代码的核心职责非常明确:它是公开批准知识库的严格加载契约实现,主要围绕本地知识文件的发现、读取、完整性校验、schema 校验、去重、过滤与社区语料装配展开。它处理的资源是本地路径、manifest、approved.jsonl、community 目录及 revoked/rejected 列表,而不是私域经营问题本身。声明描述的是一个面向最终用户的私域专家 Skill,强调业务咨询范围、联网核验要求以及与另一个数据类 Skill 的分流边界;但代码并未实现这些对话层/业务层能力,也没有任何联网、厂商核验、价格查询、规则抓取或路由判断逻辑。因此这不是“支持性实现细节”程度的差异,而是代码主功能与声明主功能明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个面向私域运营专家咨询的业务 Skill,核心应表现为对运营问题的诊断、建议输出、厂商/政策/价格等动态信息联网核验,以及根据问题类型决定是否转交 majia-huiyuan。相比之下,代码仅是底层知识数据结构定义与校验模块,主要职责是数据契约、序列化、ID 生成、隐私和审核约束、以及旧数据迁移。两者的主目的明显不同:一个是业务咨询与路由,另一个是知识资产建模与治理。此外,声明中特别强调的联网核验、证据附带、以及边界路由,在代码中完全不存在。因此这是明显的描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

该代码块的功能非常明确:对已加载的 Corpus 中知识条目做条件过滤与返回,是一个底层公共知识查询工具。它只使用本地 CorpusLoader/Corpus 数据结构,不显示任何联网访问、外部证据抓取、厂商信息核验或私域业务决策逻辑。相比声明描述,这不是“支持私域专家团业务并带实时联网核验约束”的实现,而是一个与具体业务领域弱相关的通用检索组件。虽然它可能作为该 Skill 的支撑基础设施之一,但就这段代码本身而言,其主要目的与声明的用户可见能力存在显著差异,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · modules/_expert-team/siyu-onboard.md (reported line 3)May include surrounding context.

md
---
description: "私域专家团团长:调研诊断客户私域现状 → 按行业/阶段路由 → 并行派公关/产品/广告/合规四官 → 团长主持收口出可落地 playbook"
argument-hint: "<客户名/品类> [--industry catering|retail|edu] [--stage cold|growth|mature] [--model direct|franchise|mixed] [--stores N]"
---

# 私域专家团 · 团长编排(siyu-onboard)

> 如只需单个动作(写朋友圈 / 出群发 / 给话术),直接调用 siyu-execution 对应 skill,无需全盘诊断。

> **讲人话**:这是后台编排文档,但**最终交付给用户的话**遵循讲人话铁律——别对店老板暴露"团长/四官/升舱/playbook"这些词,产物就叫「搭建清单 / 怎么做」。面对普通店老板(问得泛、没运营黑话),优先走零依赖的 [`../../references/整盘怎么搭-老板版.md`](../../references/整

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file explicitly allows direct BI-platform retrieval for funnel validation, which conflicts with the stated boundary that data verification/calculation belongs to a different skill. This creates a scope-break vulnerability: the agent may access or process analytics data under the wrong trust boundary, leading to excessive privilege use, policy bypass, or mishandling of sensitive operational metrics.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/siyu_team/eval/static.py (reported line 156)May include surrounding context.

python
def _effective_rule_id(rule: LexiconRule, token: str) -> str:
    if rule.flag != "COMPLIANCE_RED":
        return rule.rule
    return {
        "guarantee": "deceptive_guarantee",
        "restricted_tool": "restricted_tool",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/siyu_team/eval/static.py (reported line 197)May include surrounding context.

python
def _effective_rule_id(rule: LexiconRule, token: str) -> str:
    if rule.flag != "COMPLIANCE_RED":
        return rule.rule
    return {
        "guarantee": "deceptive_guarantee",
        "restricted_tool": "restricted_tool",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/siyu_team/eval/static.py (reported line 236)May include surrounding context.

python
def _effective_rule_id(rule: LexiconRule, token: str) -> str:
    if rule.flag != "COMPLIANCE_RED":
        return rule.rule
    return {
        "guarantee": "deceptive_guarantee",
        "restricted_tool": "restricted_tool",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/siyu_team/eval/static.py (reported line 240)May include surrounding context.

python
def _effective_rule_id(rule: LexiconRule, token: str) -> str:
    if rule.flag != "COMPLIANCE_RED":
        return rule.rule
    return {
        "guarantee": "deceptive_guarantee",
        "restricted_tool": "restricted_tool",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/siyu_team/eval/static.py (reported line 247)May include surrounding context.

python
def _effective_rule_id(rule: LexiconRule, token: str) -> str:
    if rule.flag != "COMPLIANCE_RED":
        return rule.rule
    return {
        "guarantee": "deceptive_guarantee",
        "restricted_tool": "restricted_tool",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/siyu_team/eval/static.py (reported line 252)May include surrounding context.

python
def _effective_rule_id(rule: LexiconRule, token: str) -> str:
    if rule.flag != "COMPLIANCE_RED":
        return rule.rule
    return {
        "guarantee": "deceptive_guarantee",
        "restricted_tool": "restricted_tool",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/siyu_team/eval/static.py (reported line 274)May include surrounding context.

python
def _effective_rule_id(rule: LexiconRule, token: str) -> str:
    if rule.flag != "COMPLIANCE_RED":
        return rule.rule
    return {
        "guarantee": "deceptive_guarantee",
        "restricted_tool": "restricted_tool",

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · tools/siyu_team/eval/static.py (reported line 276)May include surrounding context.

python
def _effective_rule_id(rule: LexiconRule, token: str) -> str:
    if rule.flag != "COMPLIANCE_RED":
        return rule.rule
    return {
        "guarantee": "deceptive_guarantee",
        "restricted_tool": "restricted_tool",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description states "中文私域经营工具箱," which presents the skill as Chinese-only. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified or alternatives are offered.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill instructs the agent to read many local files and conditionally invoke a CLI, but it declares no explicit tool scope such as allowed file paths, shell commands, or environment access. That creates an implicit privilege boundary: a host may expose broader file or shell capabilities than the skill actually needs, increasing the chance of unintended file access or command execution if routing logic or downstream module content is abused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction '面向用户一律中文' requires all user-facing communication to be in Chinese, which is a language policy constraint. The file does not offer the user a language choice or explain a region-specific compliance reason for forcing this locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is written as a mixed Chinese/English instruction centered on Chinese-language usage, and the file provides no option for users to choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.