Back to skill

Security audit

企服助手一键初始化

Security checks for vulnerabilities and agentic risk

Overview

This skill is an installer for enterprise-service helper skills, but it installs multiple mutable dependencies and asks users to store a webhook secret in a regular knowledge file.

Review the exact eight dependency skills before installing, prefer pinned versions and verified publishers, and do not place a real webhook URL in PROJECT_KB.md; use a secret manager, environment variable, or untracked local secret file instead. Treat the included shell scripts as untrusted until they are repaired and reviewed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned and Unverified Third-Party Skill Installation

Content
View full analysis
") ``` ### Technical Analysis The initialization instructions install eight third-party Skills using package names alone. They do not specify immutable versions, content hashes, verified publisher identities, trusted registry constraints, or an approval step that reviews the resolved package contents. Because these dependencies are not included in the audited project, their effective behavior cannot be assessed from this repository. Name-only resolution allows the content associated with a dependency to change after this Skill has been reviewed. This creates a supply-chain risk if a registry account is compromised, a package is transferred or replaced, dependency resolution reaches an unintended source, or a malicious package is published under a confusing identity. The shell installer repeats the same dependency names in `scripts/install_deps.sh:10-19`, confirming that the dependencies are treated as mutable named components rather than pinned artifacts. ### Attack Path 1. An attacker compromises the publisher or registry entry for one of the eight named Skills, or causes dependency resolution to select an attacker-controlled package. 2. A user triggers the enterprise-service initialization workflow. 3. The workflow calls `skillhub_install` with only the mutable Skill name. 4. The installation mechanism resolves and installs the attacker-controlled version without verifying an expected version, hash, or publisher identity. 5. The malicious dependency subsequently executes when invoked and operates with whatever filesystem, ...[truncated 752 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:61
Finding

Sensitive WeCom Webhook Stored in a Plaintext Workspace Document

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code broadly aligns with the stated domain and targets the same 8 dependency skills, creates the expected skills folder, and ends with guidance about setting up project knowledge. However, there is a material description/behavior mismatch: the description says it will automatically detect and install dependencies, while the script merely checks for directories and, when a skill is absent, prints instructions for the user to execute a separate install command. It only conditionally copies from ./skills if a local copy exists. Also, the declared trigger phrases are not implemented in this code chunk at all. Additionally, the script contains substantial syntax/corruption issues, so its actual executable behavior is likely broken, further weakening the match.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to place a sensitive Enterprise WeChat webhook URL into a local knowledge-base file, which may be synced, indexed, shared, or exposed through workspace tooling. Even though the text later says not to leak it, embedding secrets directly into general project documentation increases the chance of accidental disclosure and misuse of the webhook for spoofed notifications or information leakage.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
88% confidence
Finding

Whitespace-based obfuscation on the first line makes the file materially harder to inspect and can disguise multiple statements merged together. Because this script manages dependency installation, hidden behavior in this context increases supply-chain and integrity risk even if no direct exploit string is visible.

Content

Scanner excerpt · scripts/check_deps.sh (reported line 1)May include surrounding context.

sh
#!/bin/bash                                                                                                                                                                                                                                          #!/bin/bash#企服助手 - 依赖技能安装脚本                                                                                                                                              #由 enterprise-service-starter 元技能自动调用                                                                                                                                             set-e 
echo "🏢 企服助手 - 正在检查依赖技能..."                                                                                                                                echo "=================================================="                                                                                                                      
 
#定义8个核心依赖技能declare-a SKILLS=("contract-renewal""fee-collection""enterprise-customer-management""inventory-monitor""service-matching""workorder-dispatch""visit-management""enterprise-service-assistant"

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
88% confidence
Finding

Whitespace-based obfuscation on the first line makes the file materially harder to inspect and can disguise multiple statements merged together. Because this script manages dependency installation, hidden behavior in this context increases supply-chain and integrity risk even if no direct exploit string is visible.

Content

Scanner excerpt · scripts/check_deps.sh (reported line 1)May include surrounding context.

sh
#!/bin/bash                                                                                                                                                                                                                                          #!/bin/bash#企服助手 - 依赖技能安装脚本                                                                                                                                              #由 enterprise-service-starter 元技能自动调用                                                                                                                                             set-e 
echo "🏢 企服助手 - 正在检查依赖技能..."                                                                                                                                echo "=================================================="                                                                                                                      
 
#定义8个核心依赖技能declare-a SKILLS=("contract-renewal""fee-collection""enterprise-customer-management""inventory-monitor""service-matching""workorder-dispatch""visit-management""enterprise-service-assistant"

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
88% confidence
Finding

Whitespace-based obfuscation on the first line makes the file materially harder to inspect and can disguise multiple statements merged together. Because this script manages dependency installation, hidden behavior in this context increases supply-chain and integrity risk even if no direct exploit string is visible.

Content

Scanner excerpt · scripts/check_deps.sh (reported line 1)May include surrounding context.

sh
#!/bin/bash                                                                                                                                                                                                                                          #!/bin/bash#企服助手 - 依赖技能安装脚本                                                                                                                                              #由 enterprise-service-starter 元技能自动调用                                                                                                                                             set-e 
echo "🏢 企服助手 - 正在检查依赖技能..."                                                                                                                                echo "=================================================="                                                                                                                      
 
#定义8个核心依赖技能declare-a SKILLS=("contract-renewal""fee-collection""enterprise-customer-management""inventory-monitor""service-matching""workorder-dispatch""visit-management""enterprise-service-assistant"

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
84% confidence
Finding

Repeated padding anomalies in executable content are not harmless style issues here because they coincide with malformed shell syntax throughout the file. This combination can conceal execution semantics and prevent reliable review of what the installer will do on a user's system.

Content

Scanner excerpt · scripts/check_deps.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash                                                                                                                                                                                                                                          #!/bin/bash#企服助手 - 依赖技能安装脚本                                                                                                                                              #由 enterprise-service-starter 元技能自动调用                                                                                                                                             set-e 
echo "🏢 企服助手 - 正在检查依赖技能..."                                                                                                                                echo "=================================================="                                                                                                                      
 
#定义8个核心依赖技能declare-a SKILLS=("contract-renewal""fee-collection""enterprise-customer-management""inventory-monitor""service-matching""workorder-dispatch""visit-management""enterprise-service-assistant"
)

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
84% confidence
Finding

Repeated padding anomalies in executable content are not harmless style issues here because they coincide with malformed shell syntax throughout the file. This combination can conceal execution semantics and prevent reliable review of what the installer will do on a user's system.

Content

Scanner excerpt · scripts/check_deps.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash                                                                                                                                                                                                                                          #!/bin/bash#企服助手 - 依赖技能安装脚本                                                                                                                                              #由 enterprise-service-starter 元技能自动调用                                                                                                                                             set-e 
echo "🏢 企服助手 - 正在检查依赖技能..."                                                                                                                                echo "=================================================="                                                                                                                      
 
#定义8个核心依赖技能declare-a SKILLS=("contract-renewal""fee-collection""enterprise-customer-management""inventory-monitor""service-matching""workorder-dispatch""visit-management""enterprise-service-assistant"
)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script's natural-language output strings are in Chinese throughout, and there is no indication that the skill is China-specific or that users can opt into another language. This may violate language/locale policy when used in a broader environment where users are not given a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs a file-write operation by recursively copying directories into the target skills root, which can modify the user's filesystem. In this file there is no confirmation prompt and no clear explanatory comment warning the user that installation will copy files into another location.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script creates and writes to the user's ~/.qclaw/skills directory automatically via mkdir -p without any confirmation, dry-run mode, or clear consent step. In an installer skill that is triggered by simple user phrases, silent filesystem modification increases the risk of unexpected persistence and unwanted changes to the user's environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The local copy path copies skill content into the user's home-directory skill store (cp -r ./skills/... "$SKILL_ROOT/") without verifying provenance, presenting contents for review, or asking for confirmation. Because this skill is specifically designed to bootstrap multiple dependent skills automatically, an unsafe local copy can introduce untrusted or tampered files into a location from which future agent behavior may be influenced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and user-visible echo statements are written in Chinese, and there is no indication that the user can choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy concern unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.