Back to skill

Security audit

生意数据分析助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local business-data dashboard generator with expected handling of user-provided reports and optional branding images.

Install only if you want a Chinese business analytics workflow that reads local operating data and creates an offline HTML dashboard. Before sharing any generated HTML, review it for embedded business summaries or personal data; use the optional logo color script only on images you intend to process locally.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明的技能核心是经营数据分析与看板/report 生成,而提供的代码片段核心功能是读取品牌图片并提取颜色,用于生成视觉主题配置。两者在主要目的上明显不同:声明聚焦业务数据处理与分析,代码聚焦 UI/品牌配色。虽然品牌化 HTML 报告可能会需要主题配色,这段代码可被视为报告美化的辅助组件,但就单独代码行为而言,它既不读取表格/数据库经营数据,也不执行任何分析或看板生成。因此该代码与声明描述存在明显不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description and title explicitly position the skill as producing Chinese interactive dashboards, which imposes a language choice in the skill's natural-language behavior. The file does not state that users may choose another language or opt into Chinese output, so this conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as producing Chinese interactive output by default, but it does not indicate that language should be selected based on user preference or locale. This can lead to unexpected language forcing, usability issues, and possible misunderstanding of analytical conclusions if the user expected another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L49 explicitly instructs authors to avoid one Chinese phrase and instead use other Chinese business labels, which imposes a specific language/locale in the skill guidance. The file does not indicate that the dashboard is intentionally region-specific or that users may opt into another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language descriptions and console output exclusively in Chinese, including the module docstring and CLI help text. The policy scope applies to all file types, and there is no indication that the user can choose another language or that the tool is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The argparse description, argument help strings, and printed status/output labels are all fixed to Chinese. This constitutes a language/locale constraint in natural-language content without any explicit user choice or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The primary skill description is presented entirely in Chinese, which can impose a language constraint on users without any documented opt-in or alternative locale. The policy for this audit flags language or locale requirements when the skill does not explicitly offer a choice or justify the restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill metadata is broadly phrased around analyzing business data and generating dashboards, without clear activation boundaries such as accepted file types, business-use scope, or explicit user intent requirements. This can cause overbroad invocation and unintended handling of requests that only loosely resemble analytics tasks, increasing the chance of misrouting sensitive or irrelevant data into the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.