Back to skill

Security audit

Internal Comms Midea

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only internal communications skill, but it gives broad instructions to collect and republish internal chat, email, calendar, and document content without enough permission and confidentiality guardrails.

Review this skill before installation if your agent has access to internal mail, chat, calendars, or document stores. Use it only with clearly approved sources and require human review before sending newsletters, FAQs, or reports broadly inside the company.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly directs the agent to gather information from email, calendar, documents, and team-update systems, all of which commonly contain sensitive personal, confidential, or business data. It does so without requiring user confirmation, least-privilege scoping, or a privacy warning, creating a real risk of over-collection and unintended disclosure in the generated report.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly encourages gathering content from internal chat, all-hands emails, calendars, and documents, but provides no guardrails around access control, need-to-know, confidential material, or user authorization. In a newsletter-generation context, this can cause the agent to aggregate and redistribute sensitive internal information at company-wide scale, increasing the risk of privacy breaches, confidential strategy leaks, and over-collection from enterprise systems.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The skill content is entirely written in Chinese and implicitly directs the interaction in Chinese without any mechanism to detect or honor the user's preferred language. In a general communications skill, this can cause unintended language switching, user confusion, and failure to meet business or compliance expectations for multilingual environments.

Static analysis

No suspicious patterns detected.