Back to skill

Security audit

明日Dmp人群同步

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate DMP audience-sync purpose, but it asks for sensitive API secrets in chat and can execute spoofable local helper code from broad skill directories.

Review carefully before installing. Do not paste AK/SK secrets into chat; use a secure secret manager or a tightly permissioned local credential file instead. Only install the auth and logger dependencies after verifying publisher, version, and integrity, and avoid using this skill in an environment where untrusted skills can exist in searched directories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:244
Finding

Mandatory Workflow Redirection and Suppression of Task Results

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/create_sync_task.py:34
Finding

Arbitrary Python Execution Through Spoofable Authentication Skill Discovery

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:87
Finding

Installation of Unpinned Security-Sensitive Third-Party Skills

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:139
Finding

Long-Lived API Credentials Requested Through the Agent Conversation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (24)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill’s stated purpose is audience synchronization, yet it also orchestrates task-logger installation checks and AI-facing control instructions unrelated to the core API operation. That expands behavior into local modification and persistence features that users may not reasonably expect from the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill’s stated purpose is audience synchronization, yet it also orchestrates task-logger installation checks and AI-facing control instructions unrelated to the core API operation. That expands behavior into local modification and persistence features that users may not reasonably expect from the description.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly instructs users to paste Access Key and Secret Key directly into chat, creating a direct natural-language collection path for highly sensitive credentials. Chat channels are often logged, retained, or visible to intermediaries, so this practice can lead to credential disclosure and downstream API compromise.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes shell execution and local file/path inspection but does not declare any tool scope or allowed-tools restrictions. That creates an authority gap where an agent may be induced to use filesystem and terminal capabilities without explicit least-privilege boundaries, increasing the chance of unintended local actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to install an additional skill via terminal command, effectively granting package-management and environment-modification behavior beyond normal audience synchronization. Installing external components increases supply-chain and local compromise risk, especially if the source or integrity of the installed skill is not strongly verified.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The logging flow similarly instructs installation of a separate task-logging skill, modifying the local environment for a non-core feature. Even if optional, this broadens the attack surface and creates persistence/storage behavior that may surprise users.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The task-logging flow mandates automatic recording of task parameters, which may include sensitive account identifiers, audience metadata, or other user-supplied information. Persisting such data locally without prior granular consent or minimization increases exposure through local file access, retention, and secondary use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Broad trigger phrases can cause the skill to activate on ordinary conversation, which is risky because this skill can lead to credential handling, local checks, and shell-based installation flows. Overbroad activation increases the chance of unintended execution of sensitive workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The query triggers are underspecified and could match vague user requests without sufficient scope or parameter constraints. In a skill that can inspect local state and process task identifiers, ambiguity raises the risk of accidental data access or unintended workflow entry.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing documentation and printed instructions entirely in Chinese, including required assistant behaviors and user prompts. Because the file does not offer any language/locale opt-in or alternative, it creates a language-policy concern under the rule for forced locale or language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all user-facing messaging are written only in Chinese, and the instructions presented to the AI assistant are framed as mandatory behavior without any opt-in or language-selection mechanism. Under the policy, forcing a specific language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script scans multiple local skill directories, enumerates candidate skills, and opens their files to inspect content in order to discover an auth helper. This exceeds the minimum access needed for audience-sync task creation and creates an unnecessary local-discovery capability that could expose filesystem structure, interact with unintended scripts, or execute a malicious lookalike auth skill if one is planted in a searched location.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code launches another script via subprocess to perform a POST request, passing advertiser/account identifiers and audience data derived from user input. Although the module docstring states the functional purpose, there is no runtime warning, confirmation prompt, or explicit disclosure near the network operation itself before transmitting potentially sensitive business data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language docstrings and CLI output entirely in Chinese, including the skill description and usage/help text. The policy scope includes all file types, and there is no indication that the language restriction is optional, user-selected, or justified as a region-specific tool.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/get_ad_accounts.py (reported line 66)May include surrounding context.

python
sys.exit(3)
    
    try:
        result = subprocess.run(
            ["python3", str(auth_skill_path), method, endpoint, json.dumps(request_body, ensure_ascii=False)],
            capture_output=True,
            text=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script searches multiple user-writable directories, dynamically enumerates skill folders, and selects any minri_dmp_api.py whose first 500 bytes contain matching strings. This creates a trust-boundary violation: an attacker who can place a crafted script in one of those locations can cause this skill to execute arbitrary code under the user's account when query_sync_task.py runs.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/create_sync_task.py (reported line 66)May include surrounding context.

python
sys.exit(3)
    
    try:
        result = subprocess.run(
            ["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body, ensure_ascii=False)],
            capture_output=True,
            text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/query_sync_task.py (reported line 57)May include surrounding context.

python
sys.exit(3)
    
    try:
        result = subprocess.run(
            ["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body, ensure_ascii=False)],
            capture_output=True,
            text=True,

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code invokes another script to perform a POST request and passes user-supplied query parameters in the request body, but there is no confirmation prompt, warning message, or explanatory comment disclosing that data will be sent to an external API. The top-level docstring only says the script queries sync tasks and does not explicitly warn about network transmission.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

文档中多处把用户回复和系统提示固定为中文用语,例如 L81 要求回复“是/否”,后续也反复要求回复“确认”“修改”“取消”等中文词汇。这会将交互语言默认锁定为单一语言,但未说明可接受其他语言或允许用户自行选择语言。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script inspects local filesystem paths to determine whether an unrelated 'skill-logger' component is installed, which exceeds the stated DMP audience synchronization purpose and creates unnecessary environment awareness. While it does not execute the logger or exfiltrate data by itself, this kind of host probing can reveal local setup details and can be used to pressure downstream behavior ('must execute') based on the result.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file's natural-language descriptions and runtime messages are written entirely in Chinese, and the skill does not offer any language selection or indicate that it is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when users are not given a choice or prior opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The natural-language descriptions and all user-facing messages are written only in Chinese, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in can be a language/locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.