Back to skill

Security audit

Complaint Handling

Security checks for vulnerabilities and agentic risk

Overview

This complaint-handling skill is purpose-aligned, but it handles sensitive customer records with under-scoped local storage and external notification behaviors that users should review before installing.

Install only in an authorized complaint-management environment. Before use, configure paths and WeCom destinations deliberately, restrict access to generated reports/backups, avoid unnecessary personal data, and add spreadsheet formula neutralization plus clear retention and notification policies.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/data_manager.py:116
Finding

Spreadsheet Formula Injection Through Unsanitized Complaint Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wecom_sender.py:32
Finding

Unrestricted Webhook URL Enables Server-Side Request Forgery

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly processes and records customer personal data such as names, phone numbers, complaint details, and satisfaction records, but the user-facing content does not provide clear privacy warnings, handling constraints, retention limits, or consent guidance. In this context, the skill normalizes collecting and storing personally identifiable information in spreadsheets and platforms, which increases the risk of unnecessary disclosure, over-collection, or improper downstream use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module docstring and all user-facing CLI help text are written only in Chinese, which effectively imposes a specific language on users. The file does not indicate that the skill is region-specific or provide any opt-in or alternative locale, so this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module title and governing-process description are written only in Chinese, and the file exposes no indication that users may choose another language or locale. Under the policy, language constraints should be opt-in or clearly justified as region-specific; this file provides neither in its natural-language text.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code overwrites the '投诉记录' sheet in the configured Excel workbook, which contains customer complaint data and related identifiers. Although there is a success print after saving, there is no confirmation prompt or prior disclosure warning before performing the write operation on potentially sensitive user data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code implements a hard-coded backup routine that duplicates a complaint Excel file containing personal and complaint data into a fixed directory under the user's home path. This increases data exposure and retention risk because sensitive records are copied to an additional location without access controls, configurability, encryption, or any visible consent/justification in the module.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The backup function silently creates another on-disk copy of sensitive complaint data, expanding the attack surface and persistence of personal information. Even if intended for recovery, undisclosed duplication of regulated or private records can worsen the consequences of endpoint compromise, over-retention, or accidental disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module sends complaint data including customer name, room number, complaint content, and timing to an external WeCom webhook without any consent check, minimization, masking, or user-facing notice. In a complaint-handling context this is potentially sensitive business and personal information, so exfiltration or over-sharing to a third-party messaging platform creates a real confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The only natural-language description in this file is written entirely in Chinese, which may reflect a language-specific constraint without any indication that users can choose another language. Under the policy rule for language/locale constraints, this can be a violation when a specific language is imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file's docstrings and operational messages are written only in Chinese, which effectively fixes the skill's language for users and operators. Under the policy, forcing a specific language without opt-in or documented locale justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file contains natural-language descriptions and generated reminder content exclusively in Chinese, including module docstrings and all user-facing message templates. Under the policy rule, forcing a specific language without opt-in can be a locale-policy violation when no user choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language content in docstrings and outbound notification templates is entirely fixed in Chinese, and the file provides no indication that users can choose another language or locale. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.