Back to skill

Security audit

债权公告查询助手

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent read-only debt-notice search skill that uses a disclosed external service and short-lived guest-token cache.

Install this if you are comfortable sending debt-notice search terms to agent.debtop.com. Treat the local guest-token cache as sensitive, avoid using it on shared machines without cleanup, and do not override the documented service endpoint unless you trust the alternate deployment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是面向金融不良资产/债权公告的数据查询技能;但提供的代码完全没有网络请求、数据库查询、公告解析或任何与债权公告相关的业务逻辑。代码仅围绕“客户端名称 -> 标识符”映射展开:加载 references/client-source-ids.md 表、规范化名称、生成 slug、返回来源(table/derived/fallback)、支持 --json 和 --check。其主要目的、输入输出、能力边界都与债权公告查询明显不符,因此属于明确的描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

该代码块的核心职责是认证引导与游客令牌管理,而不是债权公告搜索。它与声明中的业务目标(公告检索与结果展示)没有直接对应关系。虽然令牌获取可能是上层查询功能的支撑步骤,但当前提供的代码本身只完成认证准备,不包含任何查询公告、解析公告结果或处理用户搜索关键词的实现。因此,这属于明显的描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向债权公告与不良资产线索的检索/汇总技能,应当体现搜索、筛选、结果整理等行为。但实际代码仅包含 SHA-256 哈希计算与 nonce 暴力枚举逻辑,用于解决游客通道的 PoW 挑战,没有任何网络请求、数据源访问、关键词检索、公告解析或金融字段提取功能。其主要目的与声明用途完全不同,属于明显的不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向终端用户的债权公告搜索与汇总能力,而实际代码只是一个独立的URL处理脚本:解析输入链接,移除已有 source 参数并追加新的 source 值,然后输出修改后的URL。代码没有网络请求、没有查询公告数据源、没有搜索逻辑、没有任何与债权公告、不良资产、公告比对或信息抽取相关的实现。因此其主要目的与声明严重不符,属于明显的描述与行为不匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
| `@scripts/guest_token.sh` | 取游客令牌:`bash scripts/guest_token.sh [输出文件] [BASE]`(失败非 0 退出并在 stderr 给出错误码) |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 116)May include surrounding context.

sh
if [ -s "$OUT" ]; then
  RT="$(read_refresh "$OUT")"
  if [ -n "$RT" ]; then
    if curl -sS --max-time 20 -X POST -H 'Content-Type: application/json' \
         -d "{\"refreshToken\":\"$RT\"}" -o "$TMP" \
         "$BASE/bff/v1/guest-access/refresh" \
       && TOKEN="$(emit_token "$TMP" 2>/dev/null)"; then

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest says to use the skill when the user '要求搜索、比对、汇总公告' and that '一个关键词即可', which broadens activation beyond the explicitly listed debt-notice phrases. Without clearer constraints or negative examples, this could overlap with common requests to search or summarize notices and cause unintended invocation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The skill instructs the runtime to make outbound requests to an external service and to create guest-access tokens, which can transmit user queries, metadata, and runtime identifiers outside the host environment. Even though the destination is declared, external transmission is security-relevant because it may expose sensitive user-entered company/debt-search terms or create externally usable session artifacts if the platform executes these instructions without strong egress controls.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
curl -s $BASE/.well-known/oauth-protected-resource | grep -qE '"public_create"[[:space:]]*:[[:space:]]*true' \
  && echo "元数据 OK (公开通道已开启)"     # 注意: 响应是紧凑 JSON, 冒号后可能无空格
# 2) PoW 挑战端点应可达
curl -s -o /dev/null -w "challenge=%{http_code}\n" $BASE/bff/v1/guest-access/challenge
# 期望: 200;若为 404 说明 GUEST_PUBLIC_CREATE_ENABLED=false
# 3) 免凭据创建必须被要求 PoW(准入校验生效)
curl -s -X POST $BASE/bff/v1/guest-access -H 'Content-Type: application/json' -d '{"source":"web"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/guest-access.md (reported line 94)May include surrounding context.

md
# ④ MCP 三步握手
# ④a initialize —— 从响应头取 Mcp-Session-Id,后续请求都要带
curl -s -D "$CACHE/h.txt" -o "$CACHE/init.txt" -X POST "$BASE/mcp/debt/stream" \
  -H "Authorization: Bearer $GUEST_TOKEN" -H 'Content-Type: application/json' \
  -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"debtop-skill","version":"1.0"}}}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/guest-access.md (reported line 100)May include surrounding context.

md
-d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"debtop-skill","version":"1.0"}}}'
SID=$(grep -i '^mcp-session-id:' "$CACHE/h.txt" | awk '{print $2}' | tr -d '\r')
# ④b notifications/initialized(200/202 即成功)
curl -s -o /dev/null -w "initialized=%{http_code}\n" -X POST "$BASE/mcp/debt/stream" \
  -H "Authorization: Bearer $GUEST_TOKEN" -H "Mcp-Session-Id: $SID" \
  -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' \
  -d '{"jsonrpc":"2.0","method":"notifications/initialized"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The document instructs operators to persist guest access and refresh tokens in a local cache file and actively reuse them across sessions. Although it briefly says tokens should be masked in logs, it does not provide clear end-user guidance on secure storage, file permissions, secret handling, or cleanup, which increases the chance of token leakage and unauthorized reuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire document, including the title and all operational instructions, is written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file’s natural-language interface—including the module docstring and user-facing usage instructions—is written only in Chinese. That effectively forces a specific language for users without opt-in, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI description and argument help messages are part of the skill’s natural-language user interface, and they require Chinese comprehension to use effectively. Because no alternative language option or documented locale scope is provided, this is a policy-relevant language constraint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 116)May include surrounding context.

sh
if [ -s "$OUT" ]; then
  RT="$(read_refresh "$OUT")"
  if [ -n "$RT" ]; then
    if curl -sS --max-time 20 -X POST -H 'Content-Type: application/json' \
         -d "{\"refreshToken\":\"$RT\"}" -o "$TMP" \
         "$BASE/bff/v1/guest-access/refresh" \
       && TOKEN="$(emit_token "$TMP" 2>/dev/null)"; then

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/guest_token.sh (reported line 152)May include surrounding context.

sh
NONCE="$(python3 "$DIR/pow_solve.py" "$CH" "$DIFF")"

# ⑤ 创建游客(source 固定 "web" 是公开通道的要求;挑战一次性,重复提交会被拒)
curl -sS --max-time 20 -X POST "$BASE/bff/v1/guest-access" \
  -H 'Content-Type: application/json' \
  -d "{\"source\":\"web\",\"skillId\":\"$SKILL_ID\",\"skillCode\":\"$SKILL_CODE\",\"deviceFingerprint\":\"$FP\",\"pow\":{\"challenge\":\"$CH\",\"nonce\":\"$NONCE\"}}" \
  -o "$TMP"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The skill content is written as prescriptive operating instructions in Chinese and the provided output template is Chinese-only, while the manifest also exposes an English name and English trigger phrases. There is no explicit statement offering the user a language choice, which can conflict with language/locale flexibility expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all operational guidance exclusively in Chinese, and there is no indication that users can choose another language or that the skill is intentionally restricted to a Chinese-speaking context. That creates a natural-language policy concern under the language/locale rule because the file effectively forces one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file presents all operational instructions and warnings only in Chinese, which effectively forces a specific language on users. The document does not provide an opt-in language choice or explain that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language interface is written in Chinese in the module docstring and user-facing usage text, which effectively forces a specific language for users. The policy allows locale constraints when they are explicitly justified or optional, but this file does not provide an opt-in, alternative language, or justification for being Chinese-only.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown template forces a specific language/locale for the generated report through all headings, labels, and instructions. Under the policy criteria, a fixed language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.