Back to skill

Security audit

paged-report

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed local report-generation skill; it writes HTML/PDF report files and uses localhost browser preview tooling, with no hidden exfiltration or persistence found.

Before installing, treat it as a development/review-pending report tool: verify generated client content before sharing, do not include secrets or unreviewed customer facts, use WebBridge only if you trust the local daemon/browser context, and stop any temporary localhost server after previewing.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (21)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · README.md (reported line 145)May include surrounding context.

md
## Print and pagination guidance

- `@page { size: A4; margin: 18mm 16mm; }` — requests A4 paper and margins; the browser/PDF adapter must be checked
- `.report-page { min-height: 880px; }` — screen-space minimum only; print rules override it
- `.flex-col` + `.content-area { flex: 1 }` + `.footer-area { margin-top: auto }` — can push a footer after content when that logical page has spare space
- `page-break-inside: avoid` and `thead { display: table-header-group }` — print hints, not unconditional layout guarantees
- `page-break-after: always` — requests a break after each logical `.report-page`; it does not make one logical page equal one physical page when content overflows

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The code clearly does generate HTML reports, which partially aligns with the description. It supports report families such as proposal, progress, and confirmation, which also aligns with several stated use cases. However, the declared description specifically mentions 'A4 print via WebBridge,' and this code chunk contains neither WebBridge-related integration nor any trigger-handling logic. It is a standalone Python renderer/CLI that reads JSON and writes HTML. While CSS may enable print styling elsewhere, this chunk does not itself implement explicit A4 print behavior beyond embedding CSS. Therefore the description overstates or misstates important aspects of how the skill operates, making this a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a skill for generating client HTML reports with A4 printing through WebBridge. However, the supplied code chunk is only a Python package initializer with a docstring describing QA checks for paged-report artifacts. Based on the visible code, its purpose is aligned with validation/testing of report artifacts, not generating reports or handling the declared client-facing triggers. This is a material purpose mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says the skill generates client HTML reports with A4 print via WebBridge. The supplied code does not generate reports, render via WebBridge, or perform client-report creation. Its primary purpose is deterministic QA of already-produced paged-report HTML/PDF artifacts: checking doctype, lang, self-containment, logical .report-page counts, optional PDF page size/count/blank-page properties, and recording overflow evidence. This is a materially different primary function from report generation, so the description does not accurately represent the code's behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill generates client HTML reports with A4 print via WebBridge. The supplied code does not generate reports or interact with WebBridge. It is a self-check/test file for a paged-report QA gate, using unittest and temporary files to verify expected PASS/FAIL/WARN outcomes for HTML and PDF validation logic. Its primary purpose is testing and validation, not report creation. That is a material purpose mismatch.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/component-catalog.html (reported line 262)May include surrounding context.

html
<body>
<div class="page">

<!-- ============================================================
     DEMO: All 14 components in realistic contexts
     ============================================================ -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/component-catalog.html (reported line 327)May include surrounding context.

html
</tbody>
    </table>
  </div>
  <!-- Footer placement example; verify in the target browser/PDF -->
  <div class="footer-area">
    <p>Example Client · 数据质量报告 · 2026-08-31</p>
  </div>

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The example trigger phrase is broad enough to match ordinary user requests like sending confirmations or customer updates, which can cause the agent to load this skill outside a clearly intended reporting context. In an agentic environment, overbroad activation increases the chance of unintended skill execution and downstream actions such as document generation or publication workflows being invoked on unrelated user data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 164)May include surrounding context.

md
python3 -m http.server 8765 --bind 127.0.0.1 --directory /tmp

# Navigate to the served file (reuses same tab)
curl -s -X POST http://127.0.0.1:10086/command \
  -H 'Content-Type: application/json' \
  -d '{"action":"navigate","args":{"url":"http://127.0.0.1:8765/report.html"},"session":"report-gen"}'

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly instructs reading templates/base.css, writing HTML/PDF outputs, and serving files, but it declares no tool restrictions or permission scope. In an agent setting, missing scope boundaries can let the skill invoke broader file capabilities than intended, increasing the blast radius if the skill is misused or if prompt-triggering occurs unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad phrases like 'make a report for', '生成报告', and generic business terms that can match ordinary user requests outside the intended workflow. Over-broad activation can cause the skill to engage unexpectedly, read local assets, generate files, or initiate WebBridge-related actions in contexts where the user did not explicitly request this capability.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill instructs sending commands and locally served report content to an HTTP service on localhost, which is still an external process boundary from the agent's perspective. If the rendered report contains sensitive client information, this creates a data-exposure path to the WebBridge daemon/browser context, and an unsafe or misconfigured local service could capture or further transmit that data.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

md
python3 -m http.server 8765 --bind 127.0.0.1 --directory /tmp

# Navigate to the served file (reuses same tab)
curl -s -X POST http://127.0.0.1:10086/command \
  -H 'Content-Type: application/json' \
  -d '{"action":"navigate","args":{"url":"http://127.0.0.1:8765/report.html"},"session":"report-gen"}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JSON manifest specifies a fixed language value of "zh-CN", which is a natural-language locale constraint. Because the file does not show any user opt-in, alternative locale support, or justification that the skill is region-specific, it may violate the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML document declares lang="zh-CN" and all visible user-facing text is in Simplified Chinese, which imposes a specific language/locale on users. There is no indication that the user can choose another language, nor any documented reason that the skill is intentionally limited to a China-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code defaults meta.language to zh-CN whenever the caller does not provide a language. That creates a locale policy issue because the skill imposes a specific language by default rather than offering a user choice or documenting why the renderer is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document sets lang="zh-CN", which hard-codes a specific language/locale for the skill output. Under the policy, locale-specific behavior should either be optional for the user or clearly justified as region-specific; this file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The example HTML skeleton sets <html lang="zh-CN"> directly, which can imply a default locale choice in core usage guidance. Although the README mentions bilingual support elsewhere, this specific primary template example does not present language selection or explain when Chinese should be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown specification presents core instructional content in Chinese while other sections are in English, but it does not state that the document is intentionally region-specific or provide a user opt-in for language/locale. That can violate the language/locale policy criterion because readers are forced into a mixed-language experience without documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document declares lang="zh-CN", which fixes the content to a specific language/locale. Under the policy criteria, locale-specific behavior should either be user-selectable or clearly justified as region-specific; this file does not provide such an explanation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The HTML root sets lang="zh-CN", and the visible content is written in Simplified Chinese, indicating a fixed language/locale choice. The file does not offer any user opt-in or explain that the document is intentionally region-specific, which can conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This schema defines a meta.language field constrained to language-tag syntax, which introduces a locale-setting mechanism but does not include any accompanying natural-language guidance that the language should be user-selected or optional. Under the policy rule for language/locale handling, a file that enforces or steers locale behavior without explicit opt-in or justification can be considered a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.