Back to skill

Security audit

Contract Renewal

Security checks for vulnerabilities and agentic risk

Overview

The skill supports contract-renewal work, but it handles real tenant/business records and can send identifiable data to an externally configurable WeCom webhook without strong controls.

Review before installing. Use only with an approved production workbook, restrict and validate the WeCom webhook to the intended corporate endpoint, disable or gate outbound notifications until recipients and fields are approved, and treat workbook writes as business-record mutations that need backup, audit, and input validation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/wecom_sender.py:17
Finding

Unvalidated WeCom Webhook Destination Can Expose Customer Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/data_manager.py:52
Finding

Spreadsheet Formula Injection in Renewal Plan Exports

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
84% confidence
Finding

Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill performs sensitive capabilities—reading a real local Excel file and sending data to an external WeCom webhook—without declaring any explicit tool scope or permission boundary. In an agent environment, this can lead to overbroad file/network access and unreviewed exfiltration of business data, especially because the workbook contains real tenant and contract information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill accesses a real local Excel workbook containing business/customer data, but the description does not warn users that sensitive local records will be read and processed. In agent systems, lack of a clear data-access warning undermines informed consent and increases the chance of accidental exposure of contract, payment, and tenant information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill can automatically deliver alerts through an external WeCom webhook, but no warning is provided that data may be transmitted outside the local environment. Because the messages may include tenant names, unit numbers, contract dates, and risk markers, undisclosed outbound delivery materially raises confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Line L028 states that the '客户画像' source is the customer-management skill, while nearby documentation says the skill is self-contained and no longer depends on that external skill. The actual code confirms local inlined logic by reading workbook sheets directly in query_customer_profile and build_customer_portrait, so the documentation actively contradicts the implementation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes identifying expiring contracts from the Excel ledger, analyzing enterprise portraits, and generating renewal plans, with sheet mapping focused on customer management, fee collection, and C+ service records. The inlined portrait builder additionally pulls from 能耗收缴 and 报修情况汇总 sheets to compute risk tags, expanding the behavioral basis of profiling beyond what the skill claims.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON configuration contains user-facing category names and template descriptions entirely in Chinese, which effectively imposes a specific language/locale in the skill's behavior. Under the policy, locale-specific language is only acceptable when the constraint is clearly documented and justified or when users are given a choice, neither of which is evident in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module description and all user-facing CLI text indicate the skill is designed to operate in Chinese only. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

技能清单描述的范围集中在基于 Excel 台账进行到期识别、提前3个月预警,以及手动触发续租检查。main.py 还暴露了报告生成和每月任务执行入口,这些属于更广泛的运营管理功能,超出了清单中明确声明的能力范围。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes two concrete trigger behaviors: a daily 09:00 scheduled check and a 3-month '续租预警'. In this file, the implemented scheduling entrypoint is run_monthly_task rather than a daily scheduler, and the warning logic includes 黄色预警 at 4 months and 绿色预警 at 6 months in addition to the 3-month red warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill sends customer renewal warning data to an external sender component without any visible consent, disclosure, minimization, or destination validation in this file. Because the warning payload includes customer identifiers, room numbers, contract expiry dates, and business-profile attributes, this can expose sensitive business data to external systems or chat channels unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest states the skill is for contract renewal warning and scheme generation based on the Excel ledger. This module goes beyond that by saving renewal plans, updating plan progress, sending progress update notifications, and creating JSON reports on disk, which are additional workflow-management capabilities not described in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Progress updates are forwarded externally through the notification sender with no apparent transparency or safeguards in this file. Renewal progress can contain operationally sensitive negotiations or customer status details, so silent transmission increases privacy and confidentiality risk, especially in a property-management context handling real tenant data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code’s user-facing natural-language strings, docstrings, and generated reminders are all fixed to Chinese, which can force a specific language experience on users without opt-in. The file does not indicate that the skill is region-specific or that users can select another language/locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation description and operational wording are written as Chinese-only commands and scenarios, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The method docstring and log message explicitly label the scheduled workflow as a monthly task. That directly conflicts with the manifest's declared trigger of a daily 09:00 contract expiry check, indicating intent/documentation divergence within the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains natural-language docstrings and messages entirely in Chinese, including the module description and class initialization text. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.