T09 · Insecure Skill Coding Practices
- Location
scripts/wecom_sender.py:17- Finding
Unvalidated WeCom Webhook Destination Can Expose Customer Data
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill supports contract-renewal work, but it handles real tenant/business records and can send identifiable data to an externally configurable WeCom webhook without strong controls.
Review before installing. Use only with an approved production workbook, restrict and validate the WeCom webhook to the intended corporate endpoint, disable or gate outbound notifications until recipients and fields are approved, and treat workbook writes as business-record mutations that need backup, audit, and input validation.
scripts/wecom_sender.py:17Unvalidated WeCom Webhook Destination Can Expose Customer Data
scripts/data_manager.py:52Spreadsheet Formula Injection in Renewal Plan Exports
Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.
Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.
Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.
Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.
Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.
Although framed as a mismatch finding, this one points to a real risk: the skill is configured to send potentially sensitive contract and tenant information to an external WeCom webhook, yet that outbound data flow is not prominently disclosed in the top-level description. Hidden or under-disclosed external transmission is dangerous in a skill handling real local business records because reviewers and users may not realize data leaves the host environment.
The skill performs sensitive capabilities—reading a real local Excel file and sending data to an external WeCom webhook—without declaring any explicit tool scope or permission boundary. In an agent environment, this can lead to overbroad file/network access and unreviewed exfiltration of business data, especially because the workbook contains real tenant and contract information.
The skill accesses a real local Excel workbook containing business/customer data, but the description does not warn users that sensitive local records will be read and processed. In agent systems, lack of a clear data-access warning undermines informed consent and increases the chance of accidental exposure of contract, payment, and tenant information.
The skill can automatically deliver alerts through an external WeCom webhook, but no warning is provided that data may be transmitted outside the local environment. Because the messages may include tenant names, unit numbers, contract dates, and risk markers, undisclosed outbound delivery materially raises confidentiality and compliance risk.
Line L028 states that the '客户画像' source is the customer-management skill, while nearby documentation says the skill is self-contained and no longer depends on that external skill. The actual code confirms local inlined logic by reading workbook sheets directly in query_customer_profile and build_customer_portrait, so the documentation actively contradicts the implementation.
The manifest describes identifying expiring contracts from the Excel ledger, analyzing enterprise portraits, and generating renewal plans, with sheet mapping focused on customer management, fee collection, and C+ service records. The inlined portrait builder additionally pulls from 能耗收缴 and 报修情况汇总 sheets to compute risk tags, expanding the behavioral basis of profiling beyond what the skill claims.
This JSON configuration contains user-facing category names and template descriptions entirely in Chinese, which effectively imposes a specific language/locale in the skill's behavior. Under the policy, locale-specific language is only acceptable when the constraint is clearly documented and justified or when users are given a choice, neither of which is evident in this file.
The module description and all user-facing CLI text indicate the skill is designed to operate in Chinese only. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the locale restriction is explicitly documented and justified.
技能清单描述的范围集中在基于 Excel 台账进行到期识别、提前3个月预警,以及手动触发续租检查。main.py 还暴露了报告生成和每月任务执行入口,这些属于更广泛的运营管理功能,超出了清单中明确声明的能力范围。
The manifest describes two concrete trigger behaviors: a daily 09:00 scheduled check and a 3-month '续租预警'. In this file, the implemented scheduling entrypoint is run_monthly_task rather than a daily scheduler, and the warning logic includes 黄色预警 at 4 months and 绿色预警 at 6 months in addition to the 3-month red warning.
The skill sends customer renewal warning data to an external sender component without any visible consent, disclosure, minimization, or destination validation in this file. Because the warning payload includes customer identifiers, room numbers, contract expiry dates, and business-profile attributes, this can expose sensitive business data to external systems or chat channels unexpectedly.
The manifest states the skill is for contract renewal warning and scheme generation based on the Excel ledger. This module goes beyond that by saving renewal plans, updating plan progress, sending progress update notifications, and creating JSON reports on disk, which are additional workflow-management capabilities not described in the manifest.
Progress updates are forwarded externally through the notification sender with no apparent transparency or safeguards in this file. Renewal progress can contain operationally sensitive negotiations or customer status details, so silent transmission increases privacy and confidentiality risk, especially in a property-management context handling real tenant data.
This code’s user-facing natural-language strings, docstrings, and generated reminders are all fixed to Chinese, which can force a specific language experience on users without opt-in. The file does not indicate that the skill is region-specific or that users can select another language/locale.
The activation description and operational wording are written as Chinese-only commands and scenarios, with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is clearly documented and justified.
The method docstring and log message explicitly label the scheduled workflow as a monthly task. That directly conflicts with the manifest's declared trigger of a daily 09:00 contract expiry check, indicating intent/documentation divergence within the skill.
This code file contains natural-language docstrings and messages entirely in Chinese, including the module description and class initialization text. Under the stated policy, forcing a specific language without user opt-in can be a locale-policy violation when no choice or justification is provided.
No suspicious patterns detected.