Back to skill

Security audit

数据自动分析

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent local spreadsheet analysis tool, but its generated HTML reports can run script from spreadsheet content and load a third-party chart script.

Install only if you are comfortable treating generated HTML reports as active content. Avoid running it on untrusted spreadsheets or sharing generated reports until the HTML escaping/script embedding issues are fixed, and prefer a local bundled ECharts copy plus pinned dependencies for sensitive business data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/analyze.py:583
Finding

Stored Cross-Site Scripting in Generic Analysis Reports

Content
View full analysis
`
${s.name}${s.is_pct?' (%)':''}
${s.is_pct?'均值':'合计'}${fmt(s.is_pct?s.mean:s.sum)}
均值${fmt(s.mean)}
最大值${fmt(s.max)}
最小值${fmt(s.min)}
`).join(''); ``` ```javascript function topRowHtml(r){ const gid=gidOf(r), sel=selected.has(gid), expanded=!!r.expanded; const hasCh = TREE_ON && r.childIdx && r.childIdx.length>0; const vis=visCols(); const chevIdx=(DATE_IDX>=0 && !hiddenCols.has(DATE_IDX)) ? DATE_IDX : (vis.length?vis[0]:0); let tds=vis.map(i=>{ const v=r.cells[i], numeric=META[i].type==='metric'; let inner=(numeric&&typeof v==='number')?fmt(v):v; if(i===chevIdx && hasCh) inner=`▸`+inner; return `${inner}`; }).join(''); let h=`${tds}`; if(hasCh && expanded) h+=r.childIdx.map(ix=>childRowHtml(REPORT.rows[ix])).join(''); return h; } ``` ```python repor ...[truncated 2101 chars]
Remediation
View remediation
... ``` Before insertion, encode at least `<`, `>`, `&`, U+2028, and U+2029. Parse the value from the element's `textContent`. 3. Prefer creating DOM elements and assigning workbook values through `textContent`. 4. Avoid using `innerHTML` for column names, cells, suggestions, summaries, or anomaly descriptions. 5. If HTML construction is unavoidable, use separate, context-aware encoders for HTML text and HTML attributes. 6. Remove the incomplete `esc()` function or replace it with a rigorously tested contextual encoding implementation. 7. Add regression tests containing payloads in cells and headers, including: ```html "> ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/diagnose.py:193
Finding

Stored Cross-Site Scripting in Diagnosis Reports

Content
View full analysis
tp)page=tp; document.getElementById('th').innerHTML=''+D.name_label+'状态${k}诊断 / 建议'+D.metric_keys.map(k=>``).join('')+''; const pr=rows.slice((page-1)*PS,page*PS); document.getElementById('tbd').innerHTML=pr.map(e=>`${e.name} ${e.level==='red'?'红':e.level==='yellow'?'黄':'绿'}${fmt(e.vals[k])}${e.reason}${e.action&&e.action!=='保持'?` → ${e.action}`:''} ${D.metric_keys.map(k=>``).join('')} `).join('') ||`无匹配`; ``` ### Technical Analysis `DATA` contains entity names and metric labels derived from the uploaded workbook. It is serialized and inserted directly into an executable inline script. A workbook value containing `` can break out of that script context. The report then inserts `D.name_label`, `D.metric_keys`, and `e.name` into `innerHTML` without HTML encoding. Entity names are also placed in a quoted `title` attribute, creating both HTML text and attribute-context injection paths. Although generated diagnostic reasons and actions are mostly application-controlled, the entity names, dimension labels, and metric labels are untrusted workbook content. ### Attack Path 1. An attacker places a script-breaking payload in a workbook dimension value or column name. 2. The victim ...[truncated 590 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ab_test.py:130
Finding

Stored Cross-Site Scripting in A/B Test Reports

Content
View full analysis
{html_escape(label)}
{val}
{html_escape(sub)}
' ``` ```python winner = result.get("winner") wname = a_name if winner == "A" else (b_name if winner == "B" else "持平") cards = card("p 值", f'{result["p_value"]:.4f}', "p<0.05 视为显著") cards += card("显著性", result["confidence"], f'置信度 {result["confidence_level"]}%' if result.get("confidence_level") else "未达显著") cards += card("胜出方", str(wname), f'相对提升 {result.get("relative_lift", 0):.2f}%' if winner != "tie" else "") ``` ```python chart = "const AB=" + json_dumps({"a": a_name, "b": b_name, "av": av, "bv": bv, "unit": unit, "metric": metric_name}) + ";" + r""" ``` ### Technical Analysis The `card()` helper escapes the label and subtitle but inserts `val` as raw HTML. The winning group name is supplied as `val`; it can originate from an uploaded workbook's group values or from the `--a-name` and `--b-name` command-line arguments. For example, a winning group named: ```html ``` is inserted directly into the report markup. The same group names and metric name are serialized into the `AB` object and inserted into an executable inline script. A `` payload can therefore escape the JavaScript block independently of the card injection path. ### Attack Path 1. An attacker controls one of the two group names in the input workbook, or persuades a user to run the command with a malicious label. 2. The malicious group wins the calculated comparison, causing its name to be inserted as the raw card value; alternatively, a `` payload reaches the inline chart data regardless of which group wins. 3. The ...[truncated 461 chars]
Remediation
View remediation
' f'
{html_escape(label)}
' f'
{html_escape(val)}
' f'
{html_escape(sub)}
' '' ) ``` - If some card values intentionally contain markup, separate trusted-markup and untrusted-text APIs rather than using one raw interpolation function. - Encode the `AB` object safely for HTML script context or place it in a non-executable JSON element. - Validate and test workbook group values and all user-controlled label arguments. - Apply a restrictive Content Security Policy after removing inline event handlers and inline executable data. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/daily_report.py:218
Finding

Stored Script Injection in Daily Report Trend Output

Content
View full analysis
'}) body = "const TR=" + json_dumps({"dates": trend["dates"], "values": trend["values"], "label": main_label}) + ";" + r""" ``` ### Technical Analysis `main_label` is derived from a workbook metric column name. When trend data is available, this value is serialized into `TR` and inserted directly into an executable script by the shared renderer. Ordinary JSON escaping protects JavaScript string syntax but does not protect the surrounding HTML script context. A metric column named with a `` sequence can terminate the generated script and inject arbitrary JavaScript. The visible rank, suggestion, and text-report fields are generally HTML-escaped; the confirmed issue is specifically the inline trend-data script. ### Attack Path 1. An attacker creates a multi-day workbook with a malicious metric column name. 2. The victim runs `scripts/daily_report.py` on that workbook. 3. Multi-day processing enables trend generation. 4. The malicious column name enters the inline `TR` object. 5. The victim opens the generated `daily_report.html`. 6. The browser executes the injected script. ### Impact Assessment The injected script can read and alter the daily report, including metrics, rankings, recommendations, and trend values. It may transmit that information to an external endpoint. The script executes for every recipient who opens the ...[truncated 27 chars]
Remediation
View remediation
` as `\u003e`, `&` as `\u0026`, and encode U+2028/U+2029 before embedding JSON in HTML. - Validate all workbook column names as untrusted data. - Add regression tests using malicious metric names in multi-day input files. - Consider bundling report data as a separate JSON file when deployment conditions allow it. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Python Dependencies and CDN Script Without Subresource Integrity

Content
View full analysis
``` ### Technical Analysis The Python installation instructions specify package names but no exact versions or hashes. Consequently, identical installations performed at different times can resolve different dependency versions. This weakens reproducibility and increases exposure to compromised or unexpectedly incompatible future releases. Generated reports also load ECharts from a remote CDN. The URL includes an exact ECharts version, but the script element has no Subresource Integrity `integrity` attribute. The browser therefore has no independent content hash against which to verify the downloaded script. No evidence was found that the listed package names are typosquatted, malicious, or retrieved from an intentionally unsafe custom repository. This finding concerns supply-chain hardening rather than confirmed malicious dependency content. ### Attack Path 1. A package release, package index account, CDN origin, or delivery path is compromised. 2. A user installs the unpinned dependencies or opens a generated report with network access. 3. The altered dependency or CDN script executes in the Python environment or browser. 4. The compromised component gains access to locally processed data or report contents within the privileges of the invoking process. ### Impact Assessment A compromised Python dependency would execute with the privileges of the user running the Skill and could access files available to that process. A compromised CDN script would execute in the generated report's browser con ...[truncated 235 chars]
Remediation
View remediation
``` 7. Add a restrictive Content Security Policy limiting scripts and network destinations. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (18)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

代码内容与描述存在明显的范围不一致。该脚本的核心与唯一明确功能是 A/B 测试显著性分析:读取两组数据,执行比例 Z 检验或均值 Welch T 检验,生成统计结论与 HTML 报告。这与描述中的第③项“A/B 测试分析”是吻合的。但描述把 Skill 定义为一个覆盖通用数据分析、广告账户诊断、日报生成、跨平台投放优化的一体化工具,而当前代码并未体现这些能力,也没有看到任何账户诊断逻辑、报表汇总逻辑、趋势分析逻辑、日报生成逻辑或对广告平台特定字段/规则的处理。因此其实际主用途比声明窄得多,属于“声明范围显著大于代码实际行为”的功能性不匹配。未发现额外越权、隐蔽资源访问或无关危险能力;问题主要是描述夸大了该代码块的能力范围。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

描述将该 Skill 定位为“数据自动分析 + 广告投放优化一体化”并明确覆盖账户诊断、A/B 测试显著性分析、日报生成等多个特定场景;但代码仅实现了通用表格读取、列类型识别、简单异常检测、基础汇总建议、热力图及 HTML 可视化报告生成。虽然这与“通用数据分析”部分一致,也确实支持 Excel/CSV 结构化数据分析,但并没有看到广告投放账户体检、暂停建议、投放诊断规则、A/B 显著性计算、置信区间/置信度分析、日报/周报文本生成或外部消息平台集成等能力。因此代码只覆盖了声明中的一部分,且缺失了若干核心承诺能力,属于描述与实际行为不完全一致的明显能力夸大。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

声明描述了一个覆盖多种分析场景的综合 Skill,但提供的代码块只实现了其中“账户诊断/投放诊断”的一个子集。代码没有看到 A/B 测试两组对比、显著性检验、置信度计算;也没有日报/周报文本生成、对比昨日;对“通用数据分析”仅提供基础汇总、筛选和可视化,不构成声明中所述的完整通用分析能力。虽然代码支持 Excel/CSV 输入、广告平台导出表格、可视化和结构化表格的通用异常诊断,这与声明部分吻合,但其主要用途明显比声明更狭窄,因此属于描述与实际行为不完全一致的能力范围夸大。

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill uses extremely broad trigger phrases such as '分析一下', '看看报表', and '生成日报', and even says it must trigger for many generic scenarios. In an agent system, this can cause over-triggering on ordinary conversation or unrelated files, leading to unnecessary access to uploaded spreadsheets, unintended processing, and execution of local scripts with file-write side effects.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
python3 scripts/analyze.py --file <输入文件> --out data_report.html

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

md
python3 scripts/diagnose.py --file <报表.xlsx> --out diagnose_report.html

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares capabilities that require environment setup, package installation, and file output, but it does not constrain tool scope with explicit permissions or allowed-tools. In an agent environment, this can lead to broader-than-necessary execution rights, increasing the chance of unintended file writes or shell/environment manipulation if the skill is triggered unexpectedly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill description and invocation examples are entirely framed in Chinese and position the skill around Chinese-language trigger phrases, without indicating that users may choose another language. This can violate language/locale policy when a skill implicitly requires a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is entirely written as a fixed Chinese-language skill reference and describes generated report text and recommendations only in Chinese. Under the policy rule for language/locale, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated page hard-codes lang="zh-CN", which imposes a specific language/locale on all rendered output. Under the policy, forcing a language or locale without user opt-in or a clearly documented regional justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated report HTML loads ECharts from a public CDN, which means opening the report triggers a third-party network request and executes remotely hosted JavaScript in the browser. For a skill marketed as local analysis of user-uploaded spreadsheets, this creates a supply-chain and data-disclosure risk: report access metadata and potentially sensitive contextual data can leak, and a compromised CDN asset could execute arbitrary code in the report context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The footer claims '数据本地处理' while the page depends on externally hosted JavaScript, which is misleading about the privacy boundary of the skill. In a workflow involving uploaded business reports and ad performance data, this can cause users to trust the output with sensitive datasets under false assumptions, increasing the likelihood of unintended data exposure and unsafe deployment decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code presents its description and generated user-facing conclusions in Chinese, and the CLI help/error/output strings throughout the file are also Chinese-only. The policy requires flagging language or locale constraints when the skill forces a specific language without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file’s natural-language interface and usage text are entirely in Chinese, and the generated report template is explicitly configured for Chinese locale/content without any user opt-in or alternative language path. Under the policy, forcing a specific language is a natural-language policy issue unless the locale restriction is clearly documented and justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level natural-language description is entirely in Chinese and presents the tool's interface/purpose in that language without offering a language choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

该 markdown 文件为完整的中文使用指南,未见提供其他语言选项、用户可切换语言的说明,或对仅支持中文的明确合理化说明。根据规则,强制特定语言而无用户 opt-in 可构成自然语言层面的语言/区域策略问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file states that the script outputs two files to the --out-dir directory, which is a file-writing operation affecting user data. The description provides usage details but does not include any warning or disclosure about potential overwriting or modification of files in the target directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The script writes a generated HTML report to a path on disk via open(out, "w", ...), which is a file-write operation. While the CLI has an --out argument and the module docstring mentions output usage, there is no explicit user-facing disclosure at the point of execution that the script will create or overwrite a local file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.