Back to skill

Security audit

流感数据周报

Security checks for vulnerabilities and agentic risk

Overview

This skill is a scoped China CDC report finder/downloader/extractor with clear limits, though users should be aware it installs an unpinned PDF parsing dependency for PDF extraction.

Install this skill only if you are comfortable letting it access official China CDC pages and write report artifacts locally. For PDF extraction, use an isolated environment and consider pinning or hash-verifying pdfplumber before running the install command.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Mutable and Unverified Third-Party Dependency Installation

Content
View full analysis
=0.11,<0.12 ``` ### Technical Analysis The Skill instructs the agent or user to install packages from the active Python package index before PDF extraction. The declared dependency uses a version range rather than an exact audited version, and the project does not provide package hashes or a lock file covering transitive dependencies. Consequently, installations performed at different times can resolve to different package artifacts. Pip will also use the environment's configured package indexes unless explicitly restricted. If an allowed release, one of its transitive dependencies, or a configured package index is compromised, attacker-controlled code could be installed. The installed dependency is subsequently imported by `scripts/fetch_report.py` during PDF extraction: ```python try: import pdfplumber except ImportError as exc: raise PipelineError( "tool_environment_error", "pdfplumber is required for PDF extraction", ) from exc ``` Importing a malicious Python package can execute attacker-controlled initialization code. This behavior exceeds the minimum supply-chain trust necessary because reproducible, hash-verified artifacts could be used instead. ### Attack Path 1. An attacker compromises a future package release accepted by `pdfplumber>=0.11,<0.12`, compromises a transitive dependency, or controls an active package index configured in the execution environment. 2. A user requests PDF extraction. 3. The agent or user follows the installation ...[truncated 1265 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code's actual function is limited to secure downloading and storage of one PDF from www.chinacdc.cn under a caller-supplied path prefix and referer. While this partially overlaps with the declared 'optionally download' and 'verify official PDF' aspects, it does not implement the broader advertised behavior: locating named report types, handling latest/date-based selection, or extracting and analyzing report contents. The primary implemented capability is a generic verified PDF downloader, which is materially narrower and different from the declared end-user skill behavior.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill directs use of file, network, and shell-capable operations but does not declare an explicit tool scope or permission boundary. That increases the risk of overbroad execution if the runtime grants default capabilities, making unintended downloads, file writes, or command execution harder to constrain or audit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document specifies Chinese-only pagination labels such as 下一页 and 尾页 and all title parsing examples are Chinese-language strings, which implies a fixed language/locale assumption. The file does not state that this schema is intentionally limited to a Chinese source or provide any user opt-in or locale selection, so it appears to enforce a specific language context.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/fetch_report.py (reported line 184)May include surrounding context.

python
def _run(self, *arguments: str) -> str:
        command = [self.executable, "--session", self.session, *arguments]
        try:
            result = subprocess.run(
                command,
                check=True,
                capture_output=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest-like markdown file contains natural-language metadata exclusively in Chinese, including the skill name and index marker, with no indication that language selection is optional or limited to users who requested Chinese output. Under the policy rule for language or locale constraints, this can be read as a fixed language choice without explicit opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest names the skill only in Chinese ("全国新型冠状病毒感染疫情情况"), which indicates a fixed language/locale choice in user-facing metadata. There is no accompanying note that this skill is region-specific or any indication that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The example output hard-codes a Chinese-language report title ("2026年第28周第917期中国流感监测周报") in a general output schema. Because this file does not indicate that the schema is region-specific or that language should follow user preference, it could be interpreted as prescribing a fixed locale in generated outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The alias column uses Chinese trigger phrases exclusively across the listed sources, which implies a language-specific interaction model. The file does not state that the skill is intentionally limited to Chinese-language use or offer any user opt-in or alternative locale handling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.