Back to skill

Security audit

明日Dmp人群投放

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its RTQ ad-order purpose, but it needs Review because it handles live credentials unsafely and can execute loosely discovered local helper scripts.

Install only after reviewing the credential risk. Do not paste production keys into chat; use a scoped test key or an out-of-band secret mechanism, verify the exact auth/logger dependencies before installation, and remove or rotate any RTQ keys that may have been printed or stored in ~/workspace/.order_cache.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create_rtq_deal.py:339
Finding

RTQ Access Key Exposed in Console and Agent Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/create_rtq_deal.py:117
Finding

RTQ Access Key Persisted in Insecure Order Cache Files

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/create_rtq_deal.py:283
Finding

Authentication Tool Can Be Spoofed Through Untrusted Dynamic Discovery

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:124
Finding

Executable Skill Dependencies Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The finding indicates the skill may primarily initialize configuration and persist credentials rather than perform the declared order-management functions. Undeclared secret collection and persistence are particularly risky because they expand the threat surface beyond the stated business function and can lead to credential leakage or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The finding indicates the skill may primarily initialize configuration and persist credentials rather than perform the declared order-management functions. Undeclared secret collection and persistence are particularly risky because they expand the threat surface beyond the stated business function and can lead to credential leakage or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The finding indicates the skill may primarily initialize configuration and persist credentials rather than perform the declared order-management functions. Undeclared secret collection and persistence are particularly risky because they expand the threat surface beyond the stated business function and can lead to credential leakage or misuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The finding indicates the skill may primarily initialize configuration and persist credentials rather than perform the declared order-management functions. Undeclared secret collection and persistence are particularly risky because they expand the threat surface beyond the stated business function and can lead to credential leakage or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs users to paste full AK/SK and RTQ credentials directly into the conversation, but does not provide strong warnings about exposure in chat transcripts or safer input channels. Collecting long-lived secrets in plain conversational context is dangerous because they may be logged, retained, surfaced to other tools, or exposed through host compromise.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly directs users to provide secret API credentials in plaintext conversation and says those credentials will be saved locally. This creates a direct secret-handling vulnerability: sensitive credentials can be exposed through chat logs, local file compromise, backup systems, or insufficient filesystem protections, enabling unauthorized API access and business impact.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

On successful order creation, the script stores rtqCluster and rtqAccessKey in a local JSON cache file. Persisting live access credentials in plaintext outside a dedicated secret store creates a direct secret exposure risk: any local user, malware, backup system, or later process that can read the file can reuse the credentials to access or manipulate RTQ resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Sensitive RTQ credentials are written to local storage with no warning, consent, encryption, or permission hardening. This is dangerous because users may be unaware that long-lived secrets are being persisted, increasing the likelihood of accidental leakage through shared machines, logs, backups, or support bundles.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script scans local skill directories, heuristically selects any script containing identifying text, and then executes it via Python. An attacker who can place or modify a matching file in those searched directories can hijack execution and run arbitrary code in the agent context, potentially stealing credentials or altering RTQ operations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises shell, file read/write, and environment-dependent behavior but does not declare any explicit tool scope or permission boundaries. That creates unnecessary ambiguity about what resources the skill may access and increases the chance that the runtime grants broader capabilities than users expect, especially given the documented installation commands and local credential storage.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The create-request trigger words are broad enough that ordinary conversation mentioning '投放', '订单', or 'RTQ' could be misclassified as an action request. In a skill capable of credential checks, dependency installation, and API-side order changes, weak intent detection can cause unintended state-changing workflows to start.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Keyword-only request recognition without boundary constraints or negative cases is brittle and can route users into the wrong workflow. Given that the skill can prompt for secrets, inspect local state, and potentially install dependencies, accidental activation materially increases the risk of over-collection and unintended operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes automatic installation flows for auxiliary skills, which extends its effective capabilities beyond RTQ order management. Installing additional components via shell commands increases supply-chain and privilege risk, especially when the user may not understand that approving one skill causes execution and trust expansion to another.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow adds local task-history recording that is not necessary to create or modify ad orders and may capture sensitive business and targeting information. Expanding into local recordkeeping without strong minimization and disclosure increases the blast radius of any compromise or accidental exposure of the host filesystem.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The task-recording flow encourages saving full order parameters and operational history to a local JSON file, likely including targeting attributes, audience identifiers, and other commercially sensitive data. Even if not always personal data, this unnecessary persistence creates confidentiality and compliance risk if the host or logs are accessed by other users, tools, or malware.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module description and all user-facing strings are written exclusively in Chinese, indicating an implicit fixed locale for the skill experience. There is no natural-language indication that users may choose another language or opt in to Chinese, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest describes RTQ order creation/query/update with a standardized interaction flow, but does not state that this skill will directly inspect host environment variables or scan local credential files in the current directory and home directory. Accessing local secrets is a broader host-access capability than the advertised business function itself and relies on undeclared local credential discovery behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The cache helper writes order data to a persistent local file under the user's home workspace without any access-control hardening or sensitivity filtering. In context, this becomes a security issue because order details may include audience targeting metadata and, elsewhere in the script, the same cache mechanism is later used to store RTQ credentials.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
78% confidence
Finding

The script executes another local Python script discovered from the filesystem via subprocess, creating a trust boundary issue: if the resolved auth_skill_path points to a tampered or malicious file, this code will run it with inherited privileges and sensitive request data. Although arguments are passed as a list rather than through a shell, the danger is arbitrary code execution through unsafe dependency/script discovery, not shell injection.

Content

Scanner excerpt · scripts/create_rtq_deal.py (reported line 153)May include surrounding context.

python
# 调用人群任务状态查询接口
        request_body = {"audienceId": audience_ids[0], "pageNum": 1, "pageSize": 10}
        
        result = subprocess.run(
            ["python3", auth_skill_path, "POST", "/audience/manage/taskList", 
             json.dumps(request_body, ensure_ascii=False)],
            capture_output=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script scans multiple local directories, inspects other skills' files, and selects a candidate script based on loose content matching before executing it. This broad filesystem discovery exceeds the stated function and materially increases the risk of executing a malicious planted script or interacting with unrelated files in a multi-skill environment.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
85% confidence
Finding

This subprocess invocation sends RTQ credentials and order parameters to an external script selected earlier via dynamic path discovery. If that script is replaced or a malicious lookalike is found first, the call can exfiltrate credentials or execute arbitrary code, making this more severe because sensitive secrets are included in the payload.

Content

Scanner excerpt · scripts/create_rtq_deal.py (reported line 379)May include surrounding context.

python
# 调用鉴权技能的API模块
    try:
        result = subprocess.run(
            ["python3", auth_skill_path, "POST", "/rtq/deal/create", 
             json.dumps(params, ensure_ascii=False)],
            capture_output=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill reads RTQ credentials from multiple local files and environment variables, and also persists order data locally under ~/workspace/.order_cache. This broad local data access and persistence exceeds the narrow action of modifying an RTQ order and creates unnecessary exposure of sensitive operational data on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

When cache is missing, final_params is built with rtqCluster and rtqAccessKey included, and on successful modification the entire structure is written to the local cache file. This stores live access credentials in plaintext without explicit disclosure, increasing the risk of credential theft from the workspace or subsequent processes/users.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/modify_rtq_deal.py (reported line 380)May include surrounding context.

python
if api_params['flowType'] == 'pc' and 'cookieType' in final_params:
            api_params['cookieType'] = final_params['cookieType']
        
        result = subprocess.run(
            ['python3', auth_skill_path, 'POST', '/rtq/deal/modify', 
             json.dumps(api_params, ensure_ascii=False)],
            capture_output=True,

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/create_rtq_deal.py:267

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/modify_rtq_deal.py:292