Back to skill

Security audit

企业AI应用诊断工具

Security checks for vulnerabilities and agentic risk

Overview

This is a mostly coherent enterprise AI assessment skill, but it under-discloses sensitive business data handling and has unsafe report-generation behavior.

Review before installing. Use only with non-confidential business information unless you are comfortable with how reports and questionnaires will be shared. Avoid generating or hosting HTML reports from untrusted input, and do not pass custom filenames to the save function until path validation and HTML escaping are added. The hardcoded contact details should be removed or made explicitly configurable before using reports with clients or customers.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
scripts/diagnosis_tool.py:531
Finding

Forced Promotional Content Embedded in Generated Reports

Content
View full analysis

📞 后续支持

如需进一步咨询或定制方案,请联系:

📧 邮箱:87287416@qq.com

💬 飞书:@胡大大

报告生成:企业AI应用诊断工具 v1.0
小龙虾协助制作 🦞

``` ### Technical Analysis Both report-generation paths unconditionally append fixed contact information and branding to the final user-facing document. The content is unrelated to the calculations required for enterprise diagnosis and is not supplied or approved by the user. Because this behavior is implemented directly in the report templates, every generated Markdown or HTML report becomes a distribution channel for third-party promotional information. There is no configuration flag, consent prompt, or supported option to replace or disable the content. This is classified as skill instruction hijacking because the skill alters the expected output objective: instead of generating only the requested diagnosis report, it also injects fixed promotional material into the agent-produced artifact. ### Attack Path 1. A user asks the skill to create an enterprise AI diagnosis report. 2. The skill collects business information and calculates suitability and ROI values. 3. `generate_report()` or `generate_html_report()` constructs the requested report. 4. The hardcoded contact details and branding are appended automatically. 5. The user downloads or shares the report, unknowingly distributing the embedded promotional content. ### Impact Assessment The issue does not grant ...[truncated 526 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/html_generator.py:130
Finding

Stored HTML Injection in Generated Diagnosis Reports

Content
View full analysis

🏢 企业AI应用诊断报告

企业名称:{enterprise_info['basic_info']['company_name']}
生成时间:{datetime.now().strftime('%Y-%m-%d %H:%M:%S')}
``` ```python for name, data in process_analysis.items(): score_color = '#00b894' if data['ai_score'] >= 80 else ('#fdcb6e' if data['ai_score'] >= 60 else '#e17055') html += f"""
{data['ai_score']}

{name}

AI适用性评分:{data['ai_score']}/100

当前成本

⏱️ 时间成本:{data['time_cost']}小时/月

💵 人力成本:{data['labor_cost']}元/月

⚠️ 痛点级别:{data['pain_level']}

""" ``` ```python for scenario in data['ai_scenarios']: html += f"""
🎯 {scenario['name']}
预估节省:{scenario['savings']}
实施难度:{scenario['difficulty']}
""" ``` ```python for process in phase_data['processes']: html += f"
  • {process}
  • \n" if phase_data.get('tools'): for tool in phase_data['tools']: html += f"
  • {tool}
  • \n" ``` ### Technical Analysis The generator inserts enterprise names, process names, ...[truncated 2062 chars]
    Remediation
    View remediation

    T09 · Insecure Skill Coding Practices

    Warning
    Location
    scripts/diagnosis_tool.py:557
    Finding

    Path Traversal and Arbitrary File Overwrite Through Report Filename

    Content
    View full analysis
    str: """ 保存Markdown报告 Args: report: 报告内容 filename: 文件名(可选) Returns: 文件路径 """ if filename is None: filename = f"ai_diagnosis_{datetime.now().strftime('%Y%m%d_%H%M%S')}.md" filepath = os.path.join(self.output_dir, filename) with open(filepath, 'w', encoding='utf-8') as f: f.write(report) return filepath ``` ### Technical Analysis The public `save_report()` method accepts an optional filename and joins it to the report output directory without validation. `os.path.join()` does not guarantee that the resulting path remains beneath `self.output_dir`. A filename containing parent-directory components can traverse outside the directory. An absolute filename can also cause the base output directory to be discarded entirely. Examples of dangerous values include: ```text ../../target-file /home/user/.config/application/config ``` The file is opened in write mode, which creates a missing file or truncates an existing file. Consequently, any file writable by the current process may be replaced with attacker-influenced report content. The separately calculated filename in `save_html_report()` is not passed to `generate_and_save_html_report()`, so this specific caller-controlled filename issue is confirmed in `save_report()`. ### Attack Path 1. An attacker gains control over the `filename` argument passed to `save_report()`. 2. The attacker supplies an absolute path or a relative path containing `../`. 3. `os.path.join(self.output_dir, filename)` resolves to a location outside the intended report directory. 4. `open(filepath, 'w')` creates or truncates the target. 5. The report content overwrites the chosen file wit ...[truncated 895 chars]
    Remediation
    View remediation
    Vulnerability Patterns
    • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
    • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
    • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
    • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
    • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
    Findings (14)

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The trigger phrases are broad enough to overlap with ordinary business-AI questions, which can cause the skill to activate unexpectedly. In an agent environment, overbroad auto-invocation can expose user context to the skill, cause unintended tool/script execution, or steer conversations into workflow paths the user did not explicitly request.

    Content

    No source excerpt is available for this finding.

    Undeclared Tool Scope

    Medium
    Category
    MCP Least Privilege
    Confidence
    87% confidence
    Finding

    The skill advertises report export and the analyzer detected file_write capability, but the manifest does not declare any explicit tool scope or permissions boundary. This can lead to unintended file creation or broader write behavior without reviewer or user visibility, increasing the chance of misuse or unsafe execution paths.

    Content

    No source excerpt is available for this finding.

    Vague Triggers

    Medium
    Category
    Not specified by scanner
    Confidence
    90% confidence
    Finding

    The trigger phrases are very broad and overlap with ordinary business-AI questions, so the skill may activate in situations where the user did not intend a full diagnostic workflow. In context, that can cause unnecessary data collection, external form sharing, or report generation beyond the user's expectation.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    91% confidence
    Finding

    The workflow sends an assessment questionnaire through a Feishu form without disclosing that an external service will receive enterprise information. Because the skill is designed to collect business status, budgets, and expectations, the privacy and data-handling risk is higher than in a purely local advisory workflow.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    95% confidence
    Finding

    The module title and all user-facing docstrings/report content are written exclusively in Chinese, indicating the skill is designed to operate in a single language. There is no natural-language indication that users may choose another language or that the Chinese-only behavior is a documented regional requirement.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    96% confidence
    Finding

    The file’s natural-language strings and generated HTML are consistently fixed to Chinese, including the document title, headings, labels, and the HTML lang attribute. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified, which is not present here.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The generated report sets <html lang="zh-CN">, which enforces a Chinese locale in user-facing output. Because the file does not present this as an opt-in or clearly justified regional constraint, it conflicts with the language/locale policy for all file types.

    Content

    No source excerpt is available for this finding.

    Description-Behavior Mismatch

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The code writes generated reports to an arbitrary local filesystem path supplied via output_dir, which expands the skill from analysis into persistent file creation. In an agent setting, this can create unauthorized files, overwrite data if the path is attacker-influenced, and persist sensitive enterprise assessment data on disk without clear user consent or storage controls.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    This Python file contains user-facing natural-language strings exclusively in Chinese, including the title, prompts, and status messages. Under the policy rule for language/locale constraints, this is a violation because the skill imposes a specific language on users without any opt-in or alternative selection.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Medium
    Category
    Not specified by scanner
    Confidence
    94% confidence
    Finding

    The questionnaire solicits potentially sensitive business information, including company identity, operational costs, process pain points, budgets, and current tool usage, but provides no privacy notice, data handling statement, minimization guidance, or secure submission instructions. In the context of an enterprise AI diagnosis skill, users are likely to treat the form as authoritative and may overshare commercially sensitive information that could be exposed, mishandled, or forwarded insecurely.

    Content

    No source excerpt is available for this finding.

    Intent-Code Divergence

    Low
    Category
    Not specified by scanner
    Confidence
    93% confidence
    Finding

    The example presents itself as a complete diagnosis workflow, but generate_report(enterprise_info, processes, roi, plan) uses plan without ever defining or computing it in the preceding steps. This documentation contradicts the implied runnable flow and can mislead users about what the skill actually does or requires.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    72% confidence
    Finding

    All user-facing descriptions, examples, and instructions are written exclusively in Chinese, which can amount to a language/locale restriction if the organization expects language choice or opt-in. The file does not indicate that Chinese is optional, configurable, or required for a justified region-specific purpose.

    Content

    No source excerpt is available for this finding.

    Missing User Warnings

    Low
    Category
    Not specified by scanner
    Confidence
    89% confidence
    Finding

    The skill offers to generate and export a shareable report file but does not clearly warn the user that a file will be created. Even if the content is business-focused, silent file generation can surprise users, create sensitive artifacts, or store enterprise information in unintended locations.

    Content

    No source excerpt is available for this finding.

    Natural-Language Policy Violations

    Low
    Category
    Not specified by scanner
    Confidence
    82% confidence
    Finding

    The file presents all user-facing instructions and fields exclusively in Chinese, which can amount to a language policy issue when no user choice or documented locale limitation is provided. There is no indication that this questionnaire is intentionally limited to a Chinese-speaking or region-specific audience.

    Content

    No source excerpt is available for this finding.

    Static analysis

    No suspicious patterns detected.