Back to skill

Security audit

债权人债权处置清单

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only public debt-notice lookup skill, with a guest-login helper that should be reviewed but fits its stated purpose.

Install only if you are comfortable with the skill contacting agent.debtop.com, creating or refreshing a read-only guest token, and storing a guest token plus device identifier in ~/.cache/debtop. Treat the token cache as sensitive and avoid running the guest helper repeatedly or concurrently.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to aggregate disposal announcements but also references PoW challenge solving and SHA-256 nonce brute-force via helper scripts, which is unrelated operational behavior with compute and shell-execution implications. Hidden compute tasks can be abused for unauthorized resource consumption and indicate that the skill does more than its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to aggregate disposal announcements but also references PoW challenge solving and SHA-256 nonce brute-force via helper scripts, which is unrelated operational behavior with compute and shell-execution implications. Hidden compute tasks can be abused for unauthorized resource consumption and indicate that the skill does more than its declared business function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to aggregate disposal announcements but also references PoW challenge solving and SHA-256 nonce brute-force via helper scripts, which is unrelated operational behavior with compute and shell-execution implications. Hidden compute tasks can be abused for unauthorized resource consumption and indicate that the skill does more than its declared business function.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
| `@scripts/guest_token.sh` | 取游客令牌:`bash scripts/guest_token.sh [输出文件] [BASE]`(失败非 0 退出并在 stderr 给出错误码) |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 116)May include surrounding context.

sh
if [ -s "$OUT" ]; then
  RT="$(read_refresh "$OUT")"
  if [ -n "$RT" ]; then
    if curl -sS --max-time 20 -X POST -H 'Content-Type: application/json' \
         -d "{\"refreshToken\":\"$RT\"}" -o "$TMP" \
         "$BASE/bff/v1/guest-access/refresh" \
       && TOKEN="$(emit_token "$TMP" 2>/dev/null)"; then

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly instructs the agent to read internal package files and execute shell/Python scripts, yet it declares no tool restrictions or allowed-tools boundary. That broadens the effective capability surface and can let an agent with permissive runtime access perform file reads and command execution beyond what a simple read-only announcement lookup skill should need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill is primarily framed in Chinese and its required output template, warnings, and reporting conventions are specified only in Chinese-language sections. Although the manifest contains an English description, the operational instructions do not state that users may choose another language, which can violate a language/locale choice policy.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to create and refresh guest access tokens through direct HTTP/curl flows, expanding from content retrieval into account/session bootstrapping. This is risky because it enables outbound authentication actions and token lifecycle management that may bypass normal platform guardrails and expose tokens in logs, shell history, or local storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest says this skill is for summarizing one creditor's public disposal notices and explicitly redirects users seeking an enterprise debt profile to another skill. The code guidance nevertheless instructs the agent to look up each debtor enterprise and fetch its debt summary, adding debtor debt-profile capability that is only tangentially related and overlaps the neighboring enterprise-profile skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The skill includes explicit curl commands to contact external endpoints for metadata discovery, challenge retrieval, and guest-access creation. In a skill that is supposed to summarize public notices, these outbound requests increase the attack surface for unintended data transmission, token exposure, and policy bypass, especially when paired with shell execution instructions.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
curl -s $BASE/.well-known/oauth-protected-resource | grep -qE '"public_create"[[:space:]]*:[[:space:]]*true' \
  && echo "元数据 OK (公开通道已开启)"     # 注意: 响应是紧凑 JSON, 冒号后可能无空格
# 2) PoW 挑战端点应可达
curl -s -o /dev/null -w "challenge=%{http_code}\n" $BASE/bff/v1/guest-access/challenge
# 期望: 200;若为 404 说明 GUEST_PUBLIC_CREATE_ENABLED=false
# 3) 免凭据创建必须被要求 PoW(准入校验生效)
curl -s -X POST $BASE/bff/v1/guest-access -H 'Content-Type: application/json' -d '{"source":"web"}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill reference is written in Chinese and provides operational instructions without indicating that language is optional or limited to a justified region-specific context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational guidance in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guest-access guide states that a guest token with notice:read and enterprise:read can use all 4 tools, which exceeds the creditor-disposal skill's narrowly described purpose. This creates a scope-expansion risk: a caller entering through this skill may gain access to broader data retrieval functions than users or platform operators expect, undermining least-privilege boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document provides concrete handling instructions for guest access tokens and refresh tokens, including caching and shell examples, but lacks strong user-facing secrecy guidance beyond a brief note about masking logs. In practice, such examples can lead operators or downstream agents to store tokens insecurely, print them in logs, or mishandle rotating refresh tokens, enabling token theft and unauthorized reuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/guest-access.md (reported line 93)May include surrounding context.

md
# ④ MCP 三步握手
# ④a initialize —— 从响应头取 Mcp-Session-Id,后续请求都要带
curl -s -D "$CACHE/h.txt" -o "$CACHE/init.txt" -X POST "$BASE/mcp/debt/stream" \
  -H "Authorization: Bearer $GUEST_TOKEN" -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"debtop-skill","version":"1.0"}}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/guest-access.md (reported line 99)May include surrounding context.

md
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"debtop-skill","version":"1.0"}}}'
SID=$(grep -i '^mcp-session-id:' "$CACHE/h.txt" | awk '{print $2}' | tr -d '\r')
# ④b notifications/initialized(200/202 即成功)
curl -s -o /dev/null -w "initialized=%{http_code}\n" -X POST "$BASE/mcp/debt/stream" \
  -H "Authorization: Bearer $GUEST_TOKEN" -H "Mcp-Session-Id: $SID" \
  -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","method":"notifications/initialized"}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The entire skill reference is written as a Chinese-only instruction/specification, and it does not indicate that language choice is optional or limited to a justified region-specific context. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 116)May include surrounding context.

sh
if [ -s "$OUT" ]; then
  RT="$(read_refresh "$OUT")"
  if [ -n "$RT" ]; then
    if curl -sS --max-time 20 -X POST -H 'Content-Type: application/json' \
         -d "{\"refreshToken\":\"$RT\"}" -o "$TMP" \
         "$BASE/bff/v1/guest-access/refresh" \
       && TOKEN="$(emit_token "$TMP" 2>/dev/null)"; then

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The script sends refresh tokens to the remote service and later transmits client, skill, and device-fingerprint data in HTTP requests. While the code comments document the behavior for maintainers, there is no user-facing warning or runtime notice that local identifiers and authentication material are being sent over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script generates and persists a stable device fingerprint in a local file for reuse across guest-token requests. Although comments explain the behavior for developers, there is no user-facing prompt or warning that a persistent identifier affecting privacy/tracking semantics will be stored on disk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 152)May include surrounding context.

sh
NONCE="$(python3 "$DIR/pow_solve.py" "$CH" "$DIFF")"

# ⑤ 创建游客(source 固定 "web" 是公开通道的要求;挑战一次性,重复提交会被拒)
curl -sS --max-time 20 -X POST "$BASE/bff/v1/guest-access" \
  -H 'Content-Type: application/json' \
  -d "{\"source\":\"web\",\"skillId\":\"$SKILL_ID\",\"skillCode\":\"$SKILL_CODE\",\"deviceFingerprint\":\"$FP\",\"pow\":{\"challenge\":\"$CH\",\"nonce\":\"$NONCE\"}}" \
  -o "$TMP"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire skill file presents operational instructions exclusively in Chinese, including safety-critical setup and token-handling guidance. Under the policy, forcing a specific language without user opt-in or documented justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The example tools/call uses a generic keyword notice search (search_debt_notice) instead of a creditor-disposal-specific flow. While not a direct exploit by itself, it normalizes use of this skill as a general search entry point and can encourage cross-skill capability drift that weakens intended access boundaries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file's user-facing natural language is entirely in Chinese, including the module docstring and usage guidance. The policy specifically calls for flagging language or locale constraints when the skill forces a specific language without user opt-in, and this file provides no alternative or opt-in mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The argparse description and help strings are all presented only in Chinese, which constrains the skill's interactive interface to a single language. Because no user choice or documented locale justification is provided, this matches the natural-language policy concern for forced language usage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.