Back to skill

Security audit

Kingdee

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about operating Kingdee, but it can change or delete ERP data and includes an unsafe remote CLI installer path, so it should be reviewed before use.

Install only if you are comfortable granting an agent mediated access to Kingdee business data. Install the oo CLI through a verified, user-controlled process rather than letting an agent run the pipe-to-shell commands, connect a least-privilege Kingdee account, and require explicit review of every write, delete, or proxy payload before execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
3. Read [references/proxy-reference.md](references/proxy-reference.md). Fetch the selected operation's official detail first, then only the request fields, resp

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
3. Read [references/proxy-reference.md](references/proxy-reference.md). Fetch the selected operation's official detail first, then only the request fields, resp

External Script Fetching

High
Category
Supply Chain
Confidence
96% confidence
Finding

The skill includes a one-line installer that downloads a remote script and pipes it directly to a shell, which creates a classic supply-chain and remote code execution risk. If the remote host, transport, or script content is compromised, an agent or user following this instruction could execute arbitrary code with local privileges.

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger text instructs the agent to use this skill for any Kingdee-related request, including reads, writes, and deletions, without meaningful scoping or preconditions. That broad routing increases the chance the skill is invoked in contexts where a narrower, safer workflow should apply, amplifying the risk of unintended state-changing operations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/proxy-reference.md (reported line 16)May include surrounding context.

md
| Response fields | `/apiinfoparam/apiinfo/{apiInfoId}/paramfield/res` | Interpret an unfamiliar result                                           |
| Examples        | `/apiinfoparam/apiinfo/{apiInfoId}/paramjson`      | Inspect request/response shapes when needed                              |

These are documentation endpoints, not enterprise execution endpoints. Read them with a public HTTP tool or curl without Cookie, Authorization or application credentials. Check both HTTP status and the JSON `result` flag. Fields are in `dataList`; examples are in `data.requestJson` and `data.responseJson` and may themselves be JSON strings.

Walk parameter-tree `children` recursively, keeping full paths and case. Interpret `isMust`, `fieldType`, `defaultValue` and `description` together: conditional requirements and example strings such as `"false"` are not unconditional defaults. An empty response-field tree does not prove an empty business response; consult the example.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/proxy-reference.md (reported line 65)May include surrounding context.

md
The CLI proxy envelope is `{ "data": { "status": ..., "headers": ..., "data": ... }, "meta": { "executionId": ... } }`. Read HTTP status from `response.data.status`, the Kingdee payload from `response.data.data`, and the trace ID from `response.meta.executionId`. This envelope is based on the connector/CLI contract; no real enterprise request was used during skill authoring.

| Kingdee payload                  | Interpretation                                                                                                     |
| -------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| Ordinary business result         | Check `Result.ResponseStatus.IsSuccess`; inspect `Errors`, error codes and messages                                |
| Report result                    | Check its documented status, commonly `Result.IsSuccess`; preserve Rows/RowCount only if returned                  |

Static analysis

No suspicious patterns detected.