Back to skill

Security audit

私域专家团 · 马甲实战版

Security checks across malware telemetry and agentic risk

Overview

This is a coherent private-domain operations skill with disclosed local archive, reporting, update, and web-verification behavior, though users should be careful with its unencrypted customer records and broad restore/report triggers.

Install only if you are comfortable with this skill keeping unencrypted local customer archives and reports under ~/.siyu. Use explicit /siyu-save, /siyu-restore, /siyu-report, and /siyu-update commands when handling sensitive customer work, prefer redacted saves, and independently verify any vendor, pricing, platform-rule, or policy facts before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Lp3

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding
The skill instructs the host to read local files and optionally invoke a CLI (`siyu-plan`) while declaring no permissions. That creates a capability transparency gap: users and platform policy engines may not realize the skill can access filesystem, environment, or shell-adjacent functionality, increasing the risk of unauthorized file access or command execution through the runtime.

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding
The published description presents the skill as a private-domain operations advisor, but the behavior described reaches into runtime contract loading, module dispatch, local knowledge-pack validation, and compliance/scoring frameworks. This mismatch is dangerous because it obscures the true attack surface; a user may invoke what looks like a content-consulting skill while it actually directs broader local file reads and execution-flow decisions.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The module binds `skills/conversion-caliber/SKILL.md`, which expands into metrics/caliber analysis even though the parent skill metadata explicitly says metric definitions, formulas, SQL, dashboards, and data-quality work must be routed to `majia-huiyuan`. This creates boundary confusion that can cause the wrong agent to answer data-sensitive questions, producing unauthorized or unreliable analytical output and undermining routing safeguards.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill’s completion section explicitly recommends BI instrumentation as a next step, which conflicts with the stated boundary that metric definitions, BI, SQL, and dashboard work should be routed to a different skill. This boundary drift can cause the agent to collect or act on analytics/data tasks under the wrong authorization and review context, increasing the chance of overreach into sensitive data workflows.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill authorizes use of internal note and BI connectors during intake, even though the skill is framed as onboarding/diagnosis and elsewhere emphasizes strict boundaries and minimal data use. This creates unnecessary access to internal data sources and could expose sensitive business data or expand scope without a clear need-to-know justification.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill metadata explicitly requires real-time online verification with evidence for claims about vendor/product/price/policy/platform rules, but this file hardcodes such facts as static knowledge. If the agent relies on these values without live verification, it can provide outdated or false operational guidance on Enterprise WeCom limits, pricing, and platform constraints, leading to compliance mistakes or bad business decisions.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The file declares and documents a different skill (`content-as-product`) while it is being evaluated in the `majia-siyu` context. This creates scope confusion and can cause the agent to invoke instructions outside the parent skill’s intended boundary, leading to misrouting, policy bypass, or use of the wrong operating constraints.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill instructs users to route to `/siyu` as a general navigation fallback, but `majia-siyu` has explicit boundary and transfer rules, especially around data/metrics topics that must be handed to another skill. Conflicting routing guidance can make the agent ignore stricter dispatch rules and keep processing requests in the wrong skill path.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill explicitly defines conversion-caliber metrics such as numerators, denominators, and time windows, which overlaps with the parent skill's stated boundary that data-caliber, formulas, SQL, tables, and dashboard-related work must be routed to majia-huiyuan. This can cause the agent to invoke the wrong skill for metric-definition tasks, leading to inconsistent business logic, incorrect analytics outputs, and policy-boundary bypass within the skill system.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The parent skill explicitly says metric-caliber definitions, formulas, SQL, dashboards, and data-validation deliverables must be routed to a different skill, but this child playbook embeds concrete metric formulas and conversion-caliber definitions anyway. That creates a routing-boundary violation: users may receive analytics guidance from the wrong skill, causing inconsistent KPIs, governance drift, or unsafe downstream business decisions based on unvalidated definitions.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The archive signal and save/restore trigger patterns are broad conversational phrases such as '记下来', '上次聊', and '恢复', which can match ordinary user dialogue rather than explicit persistence intent. In this skill, those routes lead to reading or writing local customer archives, so misrouting can cause unintended memory access, accidental storage of sensitive business context, or leakage of prior session data into the current interaction.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The update trigger accepts broad terms like '更新', '升级', '同步', or '安装' near common product references, which can be invoked during ordinary discussion rather than a deliberate maintenance request. Because this route initiates version checking and installation workflow, accidental activation could cause unplanned state changes, supply-chain exposure, or interruption of the intended business task.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The invocation description covers broad, everyday tasks like topic selection, hook design, and follow-up copy without tightly defining exclusions or required preconditions. Overbroad triggers increase the chance of accidental invocation for adjacent domains, which can expose users to unsupported guidance or bypass safer specialized skills.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The invocation text is broad enough to catch generic planning and reactivation requests without clearly enforcing the parent boundary on data-heavy or adjacent operational topics. In a skill-routing system, ambiguous scope is dangerous because it can cause the wrong skill to answer, bypassing specialized controls or real-time verification requirements defined at the parent level.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation description includes broad trigger phrases such as writing welcome messages, icebreakers, Q&A scripts, and account persona setup without strong boundary checks at activation time. This can cause the skill to be invoked for loosely related or ambiguous requests, increasing the chance of inappropriate routing, policy bypass through mis-scoping, or generation of persuasive messaging in contexts the user did not intend.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The invocation description is broad enough to trigger on common writing and private-domain operations requests, which can cause the skill to activate when the user did not explicitly intend to use it. In a multi-skill agent, this increases the risk of misrouting, unnecessary tool usage, and the generation of business/marketing content in contexts where another specialized or safer skill should have handled the request.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases include broad everyday terms like '打包' and '整理一份', which can cause the skill to activate during ordinary conversation without clear user intent. In this skill, accidental activation can aggregate customer archives and create a deliverable report, increasing the chance of unintended sensitive-data exposure or file creation.

Missing User Warnings

Low
Confidence
78% confidence
Finding
The workflow writes the report file before the compliance scan, so potentially noncompliant or sensitive content is persisted to disk even if delivery is later blocked. This creates a residual data-exposure risk because the unsafe artifact already exists locally and may be accessed, synced, or mishandled.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger set includes very broad natural-language phrases such as “上次”, “接着”, and “之前聊到哪了”, which can cause the skill to activate during ordinary conversation without clear user intent. In this skill’s context, accidental activation is more dangerous because it restores and summarizes local customer archives, potentially exposing sensitive prior-client information into the current chat.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill reads from `~/.siyu/clients/` and restores customer archive contents, but it does not require a user-facing notice or confirmation that local customer data will be accessed and summarized. Because the content involves customer dossiers and prior consultation state, silent access can violate user expectations, leak sensitive business or personal data, and worsen the impact of any accidental or misrouted restore.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger list includes very common phrases such as “保存”“记下来”“这个结论留着”, which can be said in normal conversation without an explicit intent to invoke a file-writing skill. In this skill, unintended invocation is more risky because the action persists structured customer conclusions to local plaintext storage, potentially causing accidental retention of sensitive business or personal data.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes very broad phrases such as “我有个私域问题”, and the slash commands may be invoked in contexts where a user is only casually mentioning a problem rather than explicitly requesting this skill. Overly broad routing can cause unintended activation, leading the agent to apply this skill’s workflow, constraints, and transfer behavior to queries that should have been handled by another skill or general assistant logic.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The instruction “面向用户一律中文” forces Chinese output regardless of the user’s language preference. This can degrade safety and usability by preventing the system from responding in the user’s preferred language, and in multilingual environments it may interfere with accessibility, policy delivery, or correct interpretation of important advice.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The activation guidance is intentionally broad and uses generic user phrases like '私域从哪开始' and '帮我把私域搭起来', which can cause this skill to trigger for loosely related requests. Because the skill also contains boundary logic that relies on nuanced interpretation, overbroad activation can misroute users away from more appropriate skills or cause the agent to answer outside its intended scope.

Ssd 3

Medium
Confidence
92% confidence
Finding
The skill explicitly allows original local archive content to be merged into a client-facing deliverable after only a reminder and optional confirmation for desensitization. Because the archives are cross-conversation customer records, verbatim inclusion can leak private or sensitive data, and the report-generation context makes that risk more acute than in a purely internal summarization tool.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.