Back to skill

Security audit

企业债务查询与画像

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent read-only public-debt lookup, but it automatically creates and caches guest session material and client/device identifiers that users should review before installing.

Install only if you are comfortable with the skill contacting agent.debtop.com, creating a guest identity, adding client-source attribution to returned links, and storing guest session data plus a stable device identifier under ~/.cache/debtop. Prefer a platform-managed OAuth/MCP connector where available, restrict cache file permissions, and do not pass an untrusted BASE endpoint to the helper script.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to retrieve financial/debt information, but also directs URL rewriting and tracking-parameter insertion unrelated to core debt analysis. This creates undisclosed attribution/tracking behavior and further demonstrates that the published purpose does not match the implemented operational instructions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to retrieve financial/debt information, but also directs URL rewriting and tracking-parameter insertion unrelated to core debt analysis. This creates undisclosed attribution/tracking behavior and further demonstrates that the published purpose does not match the implemented operational instructions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to retrieve financial/debt information, but also directs URL rewriting and tracking-parameter insertion unrelated to core debt analysis. This creates undisclosed attribution/tracking behavior and further demonstrates that the published purpose does not match the implemented operational instructions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill claims to retrieve financial/debt information, but also directs URL rewriting and tracking-parameter insertion unrelated to core debt analysis. This creates undisclosed attribution/tracking behavior and further demonstrates that the published purpose does not match the implemented operational instructions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
| `@scripts/guest_token.sh` | 取游客令牌:`bash scripts/guest_token.sh [输出文件] [BASE]`(失败非 0 退出并在 stderr 给出错误码) |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 116)May include surrounding context.

sh
if [ -s "$OUT" ]; then
  RT="$(read_refresh "$OUT")"
  if [ -n "$RT" ]; then
    if curl -sS --max-time 20 -X POST -H 'Content-Type: application/json' \
         -d "{\"refreshToken\":\"$RT\"}" -o "$TMP" \
         "$BASE/bff/v1/guest-access/refresh" \
       && TOKEN="$(emit_token "$TMP" 2>/dev/null)"; then

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires broad capabilities including file reads, network access, and shell execution, but does not declare any tool scope or allowed-tools restrictions. In an agent environment this violates least privilege and increases the blast radius if the skill is misused, compromised, or triggered unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description lists English trigger phrases including "risk profile" without narrowing them to debt or public-notice contexts. That phrase is generic enough to match many common enterprise-risk requests outside this skill's intended scope, increasing the chance of unintended invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

These activation examples are broad natural-language requests that could cover general financial or compliance analysis, not just this skill's public debt-notice workflow. Although some examples are specific, the description does not provide negative examples or explicit boundaries for these broader phrases.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill markets itself as zero-configuration and enterprise-name-only, yet instructs the agent to perform guest-token creation, OAuth probing, PoW handling, refresh/upgrade, and self-check routines. This deceptive simplification hides significant authentication and control-plane complexity that can surprise users and bypass normal platform-mediated auth expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Requiring local curl, bash, and python3 execution to obtain access and validate service state materially increases execution risk for what is presented as a simple read-only lookup skill. Shelling out introduces command-execution surface, environment dependency, and opportunities for misuse or unexpected data exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The mandatory generation and propagation of a client-specific source parameter introduces cross-client attribution/tracking that is not necessary for the stated debt-profile functionality. Such tracking metadata can leak client identity, enable request correlation, and create privacy concerns without clear user awareness or consent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The skill instructs outbound network requests to external endpoints for metadata discovery, challenge retrieval, and guest-access creation. External transmission is expected for a data-query skill, but here it extends into auth/bootstrap and telemetry-related requests that are more sensitive than the user-facing debt lookup purpose suggests.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
curl -s $BASE/.well-known/oauth-protected-resource | grep -qE '"public_create"[[:space:]]*:[[:space:]]*true' \
  && echo "元数据 OK (公开通道已开启)"     # 注意: 响应是紧凑 JSON, 冒号后可能无空格
# 2) PoW 挑战端点应可达
curl -s -o /dev/null -w "challenge=%{http_code}\n" $BASE/bff/v1/guest-access/challenge
# 期望: 200;若为 404 说明 GUEST_PUBLIC_CREATE_ENABLED=false
# 3) 免凭据创建必须被要求 PoW(准入校验生效)
curl -s -X POST $BASE/bff/v1/guest-access -H 'Content-Type: application/json' -d '{"source":"web"}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document is written entirely in Chinese and uses imperative guidance for identifier handling, but it does not state that the skill is region-specific or provide any language/locale opt-in. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational guidance exclusively in Chinese, which can amount to a language/locale policy violation when no user opt-in or alternative language path is provided. The policy explicitly calls out forced language choices as reportable across all file types.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/guest-access.md (reported line 94)May include surrounding context.

md
# ④ MCP 三步握手
# ④a initialize —— 从响应头取 Mcp-Session-Id,后续请求都要带
curl -s -D "$CACHE/h.txt" -o "$CACHE/init.txt" -X POST "$BASE/mcp/debt/stream" \
  -H "Authorization: Bearer $GUEST_TOKEN" -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"debtop-skill","version":"1.0"}}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/guest-access.md (reported line 100)May include surrounding context.

md
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"debtop-skill","version":"1.0"}}}'
SID=$(grep -i '^mcp-session-id:' "$CACHE/h.txt" | awk '{print $2}' | tr -d '\r')
# ④b notifications/initialized(200/202 即成功)
curl -s -o /dev/null -w "initialized=%{http_code}\n" -X POST "$BASE/mcp/debt/stream" \
  -H "Authorization: Bearer $GUEST_TOKEN" -H "Mcp-Session-Id: $SID" \
  -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","method":"notifications/initialized"}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file's natural-language instructions and field descriptions are entirely Chinese, which can impose a fixed language on users or maintainers without opt-in. The policy allows locale constraints only when the skill offers a choice or clearly documents a justified regional restriction, neither of which appears here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persists guest access tokens and a stable device identifier under the user's home directory without setting restrictive permissions or warning the caller that authentication material and tracking identifiers will be stored locally. On multi-user systems, shared workspaces, backups, or permissive umask settings, these files could be read by other local users or processes and reused to impersonate the guest session or correlate activity.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
75% confidence
Finding

The script sends a refresh token to a remote endpoint derived from the configurable BASE argument, and the token is sufficient to obtain fresh access credentials. Because BASE can be overridden by the caller, a user or wrapper that passes an untrusted endpoint could exfiltrate the refresh token to an attacker-controlled server.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 116)May include surrounding context.

sh
if [ -s "$OUT" ]; then
  RT="$(read_refresh "$OUT")"
  if [ -n "$RT" ]; then
    if curl -sS --max-time 20 -X POST -H 'Content-Type: application/json' \
         -d "{\"refreshToken\":\"$RT\"}" -o "$TMP" \
         "$BASE/bff/v1/guest-access/refresh" \
       && TOKEN="$(emit_token "$TMP" 2>/dev/null)"; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 152)May include surrounding context.

sh
NONCE="$(python3 "$DIR/pow_solve.py" "$CH" "$DIFF")"

# ⑤ 创建游客(source 固定 "web" 是公开通道的要求;挑战一次性,重复提交会被拒)
curl -sS --max-time 20 -X POST "$BASE/bff/v1/guest-access" \
  -H 'Content-Type: application/json' \
  -d "{\"source\":\"web\",\"skillId\":\"$SKILL_ID\",\"skillCode\":\"$SKILL_CODE\",\"deviceFingerprint\":\"$FP\",\"pow\":{\"challenge\":\"$CH\",\"nonce\":\"$NONCE\"}}" \
  -o "$TMP"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill body, operating instructions, and output template are written entirely in Chinese, while the skill is user-invocable and also declares English metadata. There is no explicit statement that users may choose their preferred output language, which can violate language-choice policy for general-purpose skills.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing natural-language documentation entirely in Chinese, including the module docstring and usage guidance, without any indication that another language is available. Under the language/locale policy rule, this is a forced language choice rather than an opt-in or clearly justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring is entirely in Chinese and provides the usage and behavior description only in that language. This imposes a language choice on users without opt-in or any documented reason that the skill is region-specific, which matches the policy-violation criterion for language or locale constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.