Back to skill

Security audit

明日Dmp人群圈选

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a real Mingdata DMP audience tool, but it uses risky local helper discovery, credential storage, and mandatory logging/install flows that users should review before installing.

Install only if you trust this publisher, the Mingdata DMP service, and the separate auth/logger skills. Prefer manually installing reviewed, pinned versions of dependencies, avoid entering long-lived AK/SK in chat or command-line arguments, rotate credentials after testing, and skip task logging unless you are comfortable storing full audience-targeting parameters locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:1071
Finding

Mandatory Promotional Content Hijacks Agent Output

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/create_app_crowd.py:25
Finding

Weak Authentication-Script Discovery Allows Execution of Spoofed Sibling Skills

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:224
Finding

External Skills Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup_credentials.py:13
Finding

API Credentials Are Accepted Through Process Command-Line Arguments

Content
View full analysis
``` ### Technical Analysis Command-line arguments are an unsafe channel for secrets. Depending on the operating system and execution environment, process arguments can be exposed through: - Process-inspection tools. - `/proc` process metadata. - Shell history. - Terminal session recording. - Agent tool-call logs. - Job-runner or orchestration telemetry. - Diagnostic and crash records. The script later stores the credential file with mode `0600`, which appropriately limits ordinary file access after creation. However, that permission does not protect the credentials while they are being transmitted through the command line. The exploitability depends on local process-inspection restrictions and whether command invocations are logged. On systems where users can inspect one another's process arguments, another local user may capture the Secret Key while the setup process is active. In managed agent environments, retained execution logs may preserve it for substantially longer. ### Attack Path 1. A user provides an Access Key and Secret Key for configuration. 2. The agent or operator invokes the script with both secrets as positional command-line arguments. 3. The operating system, shell, agent runtime, or orchestration layer exposes or records the complete command line. 4. A local user, log reader, support operator, or compromised monitoring component retrieves the arguments. 5. The attacker obtains the DMP credentials. 6. The attacker uses the creden ...[truncated 709 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (73)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly tells the agent to collect Access Key and Secret Key from the user and persist them locally in ~/.mingdata_dmp_credentials. Collecting long-lived secrets inside a skill and storing them on disk creates a direct credential-compromise risk, especially because the same document also encourages automated dependency installation and local environment interaction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger logic uses broad natural-language phrases such as common requests about users, conditions, or demographics, which can collide with ordinary conversation. That increases the chance the skill activates or steers into operational flows when the user may only be asking exploratory questions, leading to unintended credential prompts or downstream actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The LBS trigger list includes very broad everyday terms like '定位', '区域', '附近', '经过', and '广场', which are likely to match benign conversation unrelated to audience targeting. In this skill's context, false activation is more dangerous because it can funnel users into location-based profiling flows and subsequent sensitive data handling.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to inspect local filesystem paths and automatically install another skill (mingdata-dmp-auth) as part of normal operation. This expands the skill's authority beyond audience selection into environment discovery and software supply-chain modification, creating unnecessary risk if the dependency is compromised or if the installation flow is abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that API credentials will be automatically saved to a local configuration file for future use, but it does not present a clear, prominent consent step describing persistence, storage location, retention, and protection measures at the time of collection. Silent or assumed persistence of AK/SK materially increases the chance of credential exposure on shared or compromised systems.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The task-history flow introduces installation of an unrelated logger skill and additional filesystem checks solely to persist task history. This is not necessary for core audience creation and increases attack surface by adding a secondary component that can access sensitive task metadata and modify the local environment.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The logger flow requires saving task ID, audience name, creation time, and full parameter configuration, then revealing the storage path. Full parameter capture may include sensitive targeting criteria, IDs, or business context, and exposing the path makes discovery easier for local attackers or other components on the same system.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill repeatedly mandates automatic retention of complete historical task records and parameter configurations for every audience operation. Persistent storage of comprehensive targeting history creates a data-minimization failure and raises privacy, confidentiality, and compliance risks if the host environment is shared, compromised, or insufficiently protected.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents itself as a generic API response wrapper, but it conditionally injects an unrelated mandatory workflow directive that alters downstream agent behavior. This is dangerous because it hides policy-changing logic behind innocuous framing, increasing the chance that reviewers or integrators will trust and deploy code that manipulates user-facing workflow without clear disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language strings and docstrings entirely in Chinese, including the described behavior and user-facing instruction content. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

On successful API responses, the wrapper injects a 'CRITICAL_NEXT_STEP' block that forbids showing final results until the agent checks for and potentially prompts the user to download an additional component ('skill-logger'). This creates coercive, hidden control flow that can be used to steer users toward installing extra software unrelated to the original request, a strong supply-chain and social-engineering risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and all printed user-facing instructions are written in Chinese, and the script mandates specific messages the AI assistant must show. There is no indication that the user can choose another language or that the skill is limited to a Chinese-only context, which violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill scans multiple filesystem locations for other skills and selects any script matching loose content heuristics, then later executes it. That creates cross-skill trust abuse: any attacker able to place or modify a matching file in scanned directories can gain code execution under the current user's privileges.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file invokes another API client script and sends the full request body, including audience definition parameters, to a remote endpoint. Although network transmission is central to the script's function, there is no explicit user-facing disclosure, confirmation, or warning in this file that user-provided data will be transmitted externally.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script delegates core behavior to external Python scripts, including a post-operation checker, without strong trust controls or clear necessity from the advertised audience-creation function. This expands the execution surface and allows compromised local helper scripts to influence behavior, exfiltrate data, or execute arbitrary code.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The script executes another Python file discovered by scanning local skill directories and trusts the first matching minri_dmp_api.py containing simple marker text. Because the path is selected dynamically and then executed, a malicious or trojanized sibling skill can hijack this flow and run arbitrary code whenever this skill is used.

Content

Scanner excerpt · scripts/create_ad_behavior_crowd.py (reported line 58)May include surrounding context.

python
sys.exit(3)
    
    try:
        result = subprocess.run(
            ["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body)],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains its primary docstring and operational descriptions entirely in Chinese, and the CLI messages later in the file follow the same pattern. Under the natural-language policy rule, forcing a specific language without user opt-in or clear justification is a policy concern for any file type.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented design principle says the function only searches the standard path and does not rely on platform-specific locations, implying tightly limited discovery behavior. In reality, the implementation checks several additional locations including .openclaw paths and then scans skill directories for matching scripts, which materially contradicts the stated intent.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
92% confidence
Finding

This subprocess invocation executes a Python script discovered via dynamic path search and directory scanning, rather than a pinned trusted dependency. An attacker who can place or replace a matching minri_dmp_api.py in one of the searched locations could achieve arbitrary code execution under the current user's privileges when this skill runs.

Content

Scanner excerpt · scripts/create_app_crowd.py (reported line 79)May include surrounding context.

python
# 调用鉴权技能的API脚本
    try:
        result = subprocess.run(
            ["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body)],
            capture_output=True,
            text=True,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage and parameter guidance printed to users is only available in Chinese, so users are required to operate in that language to understand the skill's behavior. The file does not provide any alternative language option or explicit locale limitation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill scans multiple local skills/workspace directories, inspects unrelated files, and selects one to execute based on a weak string check. This broad filesystem discovery creates a trust-boundary violation: an attacker who can place a crafted file in any scanned location can hijack execution and potentially access API credentials or manipulate requests. In a skill environment, searching across user/workspace directories makes the behavior more dangerous than a normal fixed dependency lookup.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
88% confidence
Finding

The script dynamically discovers and executes another Python file from local skills/workspace directories. Even though subprocess.run is invoked without shell=True, the danger is arbitrary code execution via a spoofed or trojanized minri_dmp_api.py placed in one of the scanned paths; this skill effectively trusts and runs code based on weak content matching. The skill context increases risk because it handles authentication/API access, so executing the wrong helper can expose credentials or perform unauthorized actions.

Content

Scanner excerpt · scripts/create_combined_crowd.py (reported line 57)May include surrounding context.

python
sys.exit(3)
    
    try:
        result = subprocess.run(
            ["python3", str(auth_skill_path), "POST", endpoint, json.dumps(request_body)],
            capture_output=True,
            text=True,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Executing another Python script as a subprocess is dangerous here because the executed script path is the result of prior dynamic discovery rather than a strongly authenticated dependency. This creates an execution chain where a malicious local skill can be run with the same user privileges and can access request contents and potentially secrets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This script invokes another Python script via subprocess to perform a POST request and transmits the provided audience definition in request_body, but the code offers no confirmation prompt and no explicit user-facing disclosure about the external API call. The surrounding docstring only states the feature purpose and does not warn that data will be sent to a remote service through another skill.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/create_ad_behavior_crowd.py (reported line 84)May include surrounding context.

python
# 调用任务记录检查模块
                check_script = Path(__file__).parent / "check_task_logger.py"
                if check_script.exists():
                    subprocess.run(
                        ["python3", str(check_script), str(task_id) if task_id else "", task_name or ""],
                        check=False
                    )

Static analysis

No suspicious patterns detected.