Back to skill

Security audit

Enterprise Service Assistant

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly an enterprise Excel workflow assistant, but it has under-disclosed external messaging, hard-coded webhook credentials, broad scheduled automation, and unrelated/high-impact modules that need human review before installation.

Review this skill before installing in any real enterprise workspace. Rotate or remove the embedded WeCom webhook, disable scheduled tasks and legal-proceeding automation by default, verify every outbound channel and cloud document integration, and only use redacted test data until an admin has approved file paths, retention, recipients, and per-feature permissions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (76)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill declares itself as self-contained and local-Excel based, yet the documented behavior includes file read/write and outbound network use without an explicit permission model. That creates hidden capability risk: a user may invoke what appears to be a local reporting skill, while it can also write local artifacts and transmit operational data externally.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding
The public description frames the skill as an Excel-driven enterprise-service assistant, but the embedded logic also performs external webhook messaging, local report persistence, automated escalation, and bulk reminder workflows. This mismatch undermines informed consent and can cause sensitive tenant, billing, complaint, and renewal data to be handled in ways users did not reasonably expect.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The README makes a strong privacy claim that all data remains local and is never uploaded, while the documented capabilities include network-enabled tools and optional webhook-based message delivery. This can mislead operators into enabling the skill with sensitive tenant, billing, contract, or complaint data under false assumptions about data flow, increasing the risk of unintended disclosure.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
Saying the agent 'only reads the file you specify' is inaccurate given the documented use of additional workspace files, knowledge files, user memory, and integrations that may access or process other resources. This kind of overbroad assurance can cause users to place sensitive operational data into the system without understanding its true access scope.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
The skill claims local, self-contained processing but explicitly instructs pushing results to an Enterprise WeChat webhook. That contradiction is dangerous because operators may treat the skill as offline/local-only while it actually exfiltrates potentially sensitive business and customer data to an external service endpoint.

Context-Inappropriate Capability

Medium
Confidence
99% confidence
Finding
A hard-coded Enterprise WeChat webhook key is embedded directly in the skill documentation. Anyone with access to the skill can reuse that endpoint to send spoofed messages, abuse the organization's bot integration, or route sensitive operational data to a channel outside normal secret-management controls.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The skill explicitly states that Excel contains sensitive customer information that must not leak to external systems, yet elsewhere instructs sending generated reports through an external Enterprise WeChat webhook. In this context, the data includes tenant identities, billing arrears, complaints, and contract risks, making unauthorized external transmission a direct confidentiality and compliance issue.

Description-Behavior Mismatch

High
Confidence
99% confidence
Finding
The skill content materially conflicts with the declared metadata: instead of an enterprise service assistant operating on园区企业-service Excel ledgers, it defines a separate agent-efficiency optimizer that scans agent configs, discovers skills, tracks metrics, and pushes notifications. This kind of identity/purpose mismatch is dangerous because it can cause a host agent to load and execute capabilities outside the user's expected scope, potentially exposing configuration data, enabling unintended automation, and bypassing policy or review tied to the advertised skill purpose.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill labeled as a contract-renewal assistant aggregates additional datasets including fees, energy payments, repair records, and service history to build broad customer portraits. This expands data use beyond the narrowly declared renewal-warning purpose, increasing privacy exposure and enabling secondary profiling without clear minimization, consent, or purpose limitation.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The later sections implement customer value scoring and differentiated retention strategy generation, which goes beyond simple expiry detection into business decision automation and tenant profiling. Such hidden scope expansion can cause unauthorized use of customer data for pricing, benefits, and treatment decisions without governance, review, or transparency.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill includes an active WeCom webhook endpoint and describes pushing customer risk reports to group chats, which expands a local Excel analysis skill into external data exfiltration capability. Because the workbook contains real customer records and sensitive business information, this creates an unnecessary outbound disclosure path if triggered automatically or by prompt misuse.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill writes customer onboarding reports containing contract numbers, tenant names, contact details, inspection data, and workflow status to fixed local filesystem paths under /Users/mac without any consent, access-control, retention, or sanitization safeguards. In an agent environment, this can create unauthorized persistence of sensitive business and personal data and expose it to other local users, processes, backups, or later exfiltration.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill additionally generates handover and inspection documents on disk that are not clearly disclosed in the manifest summary, increasing hidden data persistence and expanding the number of sensitive artifacts created. Because these files contain customer, contract, staffing, and operational details, undisclosed generation raises privacy and compliance risk and makes accidental exposure more likely.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The embedded WeCom webhook configuration enables outbound transmission of customer and contract information to an external enterprise messaging endpoint, despite the skill being presented as a self-contained Excel-based workflow. If enabled or misconfigured, this creates a direct exfiltration channel for sensitive operational and personal data and could leak information outside approved systems.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as an internal Excel-based monitoring/reporting workflow, but the code also transmits operational task content to external WeCom webhook endpoints. Those messages include department names, unit numbers, and risk descriptions, so this creates undisclosed outbound data flow and potential leakage of tenant operational information.

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill advertises and operationalizes actions that go beyond ordinary enterprise-service assistance by automatically escalating to lawyer letters, lawsuit initiation, and legal document generation. In context, this creates a high-risk authority expansion problem: a scheduled or casual trigger can cause legally consequential actions without robust approval gates, making accidental or unauthorized escalation plausible.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The code contains automation for indictment generation, simulated court submission, and legal proceeding record creation, which are sensitive actions not justified by the parent skill's stated business-assistant purpose. Embedding this capability in a general enterprise service assistant increases the risk of misuse, privilege overreach, and accidental legal action from routine operational triggers.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill aggregates broad customer portrait data—services, energy, repairs, satisfaction, and other records—beyond the minimum data needed to detect payment-related performance exceptions. This violates data-minimization principles and increases the blast radius if the skill is misused, exposing unrelated tenant information during sensitive enforcement workflows.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The document makes a strong privacy/safety claim that data 'will not be sent to any server' while elsewhere recommending remote Tencent Docs and IMA knowledge-base integrations. This mismatch can mislead users into sharing sensitive tenant, contract, billing, and complaint data under false assumptions about where data is stored or processed.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The embedded manifest metadata does not align with the actual documented function of the skill, which creates scope confusion and can cause the agent or operators to invoke the skill under the wrong trust assumptions. In a multi-skill enterprise environment, this kind of identity/purpose mismatch can lead to unintended access to operational data, incorrect routing, or misuse of the skill in contexts it was not reviewed for.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The script produces hardcoded mock alerts while the skill metadata promises Excel-based enterprise analysis and automated risk reporting. In an enterprise operations context, presenting simulated results as real checks can mislead staff into acting on false status, missing actual overdue contracts or payment risks, and making operational decisions on fabricated data.

Intent-Code Divergence

Low
Confidence
88% confidence
Finding
Although the docstring mentions this is a simplified workflow check, the runtime output states that the check is completed and writes plausible-looking alert records without indicating they are simulated. This can create false assurance and confusion, especially if downstream users or automation consume the JSON as an authentic daily check result.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented primarily as generating service recommendations for manager confirmation, but the documented logic also mutates the underlying Excel workbook and triggers follow-up notifications. This hidden state-changing behavior can cause unauthorized record updates and secondary message dispatches, especially in an enterprise workflow handling tenant data.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The documentation describes a self-contained Excel-based matching skill, but it also includes outbound WeCom webhook behavior that is not clearly declared in the main description. Undisclosed external communication is dangerous because tenant-related recommendation data may be transmitted outside the local environment without informed consent or proper review.

Description-Behavior Mismatch

Medium
Confidence
82% confidence
Finding
The skill is presented as visit-plan management, but it explicitly inlines customer profiling, timeline generation, and risk-tag computation across multiple business domains. This expands the data-processing scope beyond the narrowly described task, increasing privacy exposure and the chance of unauthorized secondary use of tenant data.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.