Back to skill

Security audit

明日Dmp人群洞察

Security checks for vulnerabilities and agentic risk

Overview

The skill’s core audience-insight purpose is legitimate, but it asks for sensitive credentials, installs and executes other skills, and persists audience-task data with weak scoping.

Review before installing. Use only in a trusted workspace, verify the auth and logger skill publishers and versions manually, avoid letting it scan untrusted .skills directories, and treat the local credential, task-history, JSON, and Excel files as sensitive business data. Decline or remove the logger workflow unless you specifically need persistent task history.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/create_insight_task.py:42
Finding

Untrusted Skill Discovery Can Execute an Attacker-Controlled Authentication Script

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:72
Finding

External Skills Are Installed by Mutable Name Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:420
Finding

Skill Instructions Force Promotion and Installation of an Unrelated Logging Skill Before Returning Results

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:533
Finding

Complete Audience Task Parameters Are Persisted Without Defined Storage Protections or Retention Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is audience insight analysis, but the document also instructs local filesystem probing, skill discovery, script validation, shell-based installation, and path/status handling. This mismatch hides materially broader behavior than advertised, increasing the risk that users authorize sensitive host actions they did not meaningfully consent to.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill describes capabilities that include reading and writing local files and invoking shell commands, yet it declares no explicit tool scope or permissions boundary. This creates an overprivileged, ambiguous execution model where an assistant could perform sensitive local or system actions beyond what users would reasonably expect from a crowd-insight skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill interface, prompts, examples, and required user replies are written exclusively in Chinese, including expected confirmations such as “是/否” and “确认”. There is no indication that users may choose another language or that the Chinese-only constraint is region-specific and justified, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation directs the assistant to automatically install additional skills, including authentication and logging components, via shell commands. Auto-installing dependencies from within a skill expands the trust boundary and can lead to unauthorized code introduction or supply-chain risk on the host environment.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the assistant to collect API credentials from chat and save them into a local credentials file. Storing secrets received through conversational input increases the chance of exposure through logs, local compromise, accidental reuse, or weak file protections, especially when combined with broad file and shell capabilities.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill extends beyond insight generation by mandating post-task checking, installation, and use of a task-logging component that writes task history and parameters to local storage. This broadens data handling and persistence without being necessary for the core analytic function, increasing privacy and security exposure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The logging workflow saves complete task parameters and history to a local file, potentially including sensitive business identifiers, audience IDs, analysis selections, and other user-provided configuration. Persistent local logs increase the blast radius of compromise and may violate data minimization expectations for an analytics skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This skill's stated purpose is audience-insight task creation, but it delegates execution to a separately discovered Python file outside its own package boundary. That creates an unnecessary execution primitive: anyone able to influence the discovered auth-skill path or contents can run arbitrary code, and the broad directory scan increases the attack surface in shared or untrusted workspaces.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

The code executes a Python script discovered at runtime from user-accessible skill/workspace directories. Because the path is selected by scanning multiple locations and only lightly validated by checking for marker strings in the file content, an attacker who can place or replace a matching script could achieve arbitrary code execution under the current user's privileges when this skill runs.

Content

Scanner excerpt · scripts/create_insight_task.py (reported line 85)May include surrounding context.

python
# 调用鉴权技能的API脚本
    try:
        result = subprocess.run(
            ["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body)],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This Python file’s natural-language interface elements, including the module docstring and function docstring/comments, are entirely in Chinese. Under the stated policy, forcing a specific language without user opt-in or documented locale justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script scans local skill and workspace directories, inspects candidate files, and then later executes a discovered auth script based on loose content matching. In an adversarial local environment, an attacker could plant a malicious minri_dmp_api.py in one of the searched paths and have this skill execute it, resulting in arbitrary code execution under the user's account.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest limits the skill to audience insight analysis across specified insight dimensions, but this function transforms data into formatted spreadsheets with summaries and high-TGI sheets. That is a substantive reporting/export capability rather than just performing insight analysis.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/get_insight_result.py (reported line 253)May include surrounding context.

python
# 调用鉴权技能的API脚本(正确的endpoint路径,不包含/api/open-api前缀)
    try:
        result = subprocess.run(
            [
                "python3", 
                str(auth_skill_path),

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script persists the full API response and derived Excel report to local disk automatically, which can expose sensitive audience-insight data to other local users, backup systems, or later processes without explicit user consent. Because the skill handles potentially sensitive marketing/audience profiling data, unnecessary persistence increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code writes API response data and generated reports to disk without any warning, consent, or confirmation, creating silent local data retention. Since audience-insight outputs may contain commercially sensitive segmentation information, this hidden persistence can lead to unintended disclosure and policy violations.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

The script executes another local Python script discovered at runtime from user/home/workspace directories, which creates a trust-boundary violation. An attacker who can place or replace a matching minri_dmp_api.py in one of the scanned paths can achieve arbitrary code execution when this skill runs, and the dynamic discovery logic makes that easier than a fixed trusted path would.

Content

Scanner excerpt · scripts/query_insight_task.py (reported line 157)May include surrounding context.

python
# 调用鉴权技能的API脚本
    try:
        result = subprocess.run(
            [
                "python3", 
                str(auth_skill_path),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This skill silently invokes external code from another skill without disclosing that behavior to the user. While the core risk comes from the subprocess execution itself, the lack of transparency removes an opportunity for users to detect unexpected code execution and increases the chance that a poisoned dependency is run unnoticed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

该技能的描述聚焦于洞察分析,但文档多处将“下载人群投放技能/创建投放任务”作为内置后续操作建议。推荐关联技能本身未必有问题,但把投放能力作为流程化延伸,会将分析技能引向广告执行场景,超出当前声明的核心目的。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

All human-facing descriptions and argument help strings in this file are presented exclusively in Chinese, which can amount to forcing a specific language without offering user choice. The file does not indicate that the language restriction is optional, configurable, or justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code sends user-supplied values such as task name, audience ID, insight type, and dimensions to an external API by invoking another script, but the visible disclosure is limited to internal comments/docstrings rather than a user-facing warning. There is no confirmation prompt or runtime notice that these inputs will be transmitted off-process to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring, CLI description, and runtime messages are all presented in Chinese, which imposes a fixed language on users. Under the policy, locale or language constraints should either be optional, user-selectable, or clearly documented as justified for a region-specific tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The script iterates through local skill directories and opens candidate files to inspect their contents in order to locate the auth helper. This is a file-access behavior, and while it is functionally related to the skill, there is no visible warning, prompt, or disclosure in this file that it will scan and read local files under user home and workspace skill directories.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.