Back to skill

Security audit

企服客户管理

Security checks for vulnerabilities and agentic risk

Overview

The skill is broadly aligned with customer management, but it embeds a WeCom webhook credential and describes scheduled sharing of sensitive customer and financial-risk data without adequate controls.

Review this skill before installing. It should not ship with a real WeCom webhook key, and scheduled or group-chat reporting should require explicit configuration, approved recipients, redaction/minimization of customer data, and auditability. The placeholder implementation also means the actual runtime behavior is not fully represented by executable code in the package.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:645
Finding

Hardcoded WeCom Webhook Credential

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:645
Vulnerability Type: Hardcoded bearer-style webhook credential
Risk Level: High

Vulnerable Code

json
"wecom_webhook": "https://qyapi.weixin.qq.com/cgi-bin/webhook/send?key=14fb1170-2119-4f29-b400-67da770e3a3c"

Technical Analysis

The Skill configuration embeds a complete WeCom webhook URL, including its authentication key, in a distributable project file. The key functions as a bearer-style credential: possession of the URL may be sufficient to submit messages to the associated WeCom group webhook without separate user authentication.

The documentation also defines a scheduled risk-report workflow in SKILL.md:590-602 that is intended to send customer-risk reports to a WeCom group. Those reports may contain tenant identities, contract-expiration information, and financial delinquency data. Although the packaged Python script is only a placeholder and does not currently transmit this information, the exposed credential remains independently reusable if it is active.

Attack Path

  1. An attacker obtains a copy of the Skill package, repository, build artifact, log, or documentation containing SKILL.md.
  2. The attacker extracts the complete webhook URL and embedded key parameter from line 645.
  3. The attacker sends crafted requests directly to the WeCom webhook endpoint.
  4. If the key remains active, arbitrary supported messages can be posted to the webhook's associated group.
  5. The attacker may use the trusted integration identity for spam, phishing, misleading operational alerts, or impersonation. If the configuration is reused by the documented workflow, customer-risk reports may also be delivered to an unintended or insufficiently controlled destination.

Impact Assessment

Exploitation does not grant host-level code execution, filesystem access, administrative privileges, or general access to the WeCom tenant. Its scope is limit ...[truncated 653 chars]

Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the disclosed WeCom webhook key.
  2. Remove the complete webhook URL and all live credentials from SKILL.md, examples, source history, release artifacts, logs, and generated documentation.
  3. Load the webhook URL at runtime from a secret manager or a protected environment variable, such as WECOM_WEBHOOK_URL.
  4. Commit only a non-sensitive placeholder, for example:
    json
    "wecom_webhook_env": "WECOM_WEBHOOK_URL"
    
  5. Prevent recurrence with repository secret scanning, pre-commit checks, CI credential detection, and documented secret-rotation procedures.
  6. Review WeCom webhook access and delivery logs for unauthorized activity since the key was introduced.
  7. Limit the webhook's destination and capabilities where supported, and apply network or source restrictions if available.
  8. Require explicit authorization and destination validation before transmitting customer profiles, delinquency details, contact information, or contract-risk reports.
  9. Minimize notification contents so group messages contain only the information necessary for the intended operational purpose.
  10. Add fail-closed behavior so the workflow refuses to transmit reports when the secret is absent, malformed, or associated with an unapproved destination.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个面向真实业务数据的客户管理与分析技能,但实际代码仅为示例模板/占位文件,主功能与声明严重不符。虽然代码没有表现出额外的未声明高风险能力,但其实际行为与声明的核心用途存在实质性偏差,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly handles real Excel-based customer records and describes automatic daily risk-report generation plus group pushes, but does not provide clear safeguards, consent boundaries, or warning about external transmission. In this context, automated sharing can expose tenant names, contact details, financial arrears, and operational risk status to unintended recipients, causing privacy, compliance, and business confidentiality harm.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill embeds a live WeCom webhook URL and supports outbound pushes containing real customer risk data. In the context of a customer-management skill processing sensitive tenant records, this creates an exfiltration path and can leak PII/business-sensitive data to external systems without adequate access control, consent, or secret management.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation description and all example trigger phrases are written as Chinese-only commands, with no indication that another language can be used or that the locale restriction is intentional. Under the policy, a skill should not force a specific language without user opt-in or a documented justification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest limits the skill to customer profile management, portrait analysis, risk reminders, and timeline queries based on Excel ledgers. L579 states the skill can generate Tencent documents, which is an additional external publishing/export capability rather than an obvious requirement for local customer management and analysis.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest trigger scenarios mention a scheduled task only for generating a daily risk reminder report. L583 adds a separate daily 'customer anomaly summary' scheduled job, which broadens the skill's operational scope beyond the declared scenarios.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.