Back to skill

Security audit

费用催缴管理

Security checks for vulnerabilities and agentic risk

Overview

This fee-collection skill mostly matches its stated business purpose, but it can automatically send sensitive overdue-payment notices through a WeCom webhook without clear approval, scoping, or redaction controls.

Review this skill before installing in any real billing workflow. Configure the WeCom webhook only to an approved corporate destination, require an operator preview/approval step before sending reminders or @all escalations, restrict access to the intended Excel file, and treat generated reports/backups as sensitive financial records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个面向催缴业务流程的自动化技能,重点应包括定时或消息触发、逾期分级策略、催缴动作和相关计算逻辑。但提供的代码片段只是底层数据读写模块,功能集中在本地Excel文件的读取、更新、合并查询和备份。虽然这些数据操作可能是催缴系统的支撑实现之一,但从该片段本身看,其实际行为与声明的核心能力存在明显落差:没有任何触发器、规则引擎、催缴策略、消息发送或分级处理实现;同时包含了未声明的本地备份能力。因此应判定为描述与代码行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims a concrete催缴管理 skill with specific business logic and trigger scenarios. The actual code does not implement any of these behaviors; it is an example helper script whose only runtime action is printing a fixed string. This is a material description-behavior mismatch because the primary declared purpose is absent rather than merely partially implemented.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

声明描述的是一个完整的费用催缴管理技能,核心应包括催缴流程编排、触发响应、分级处理和沟通能力。但提供的代码块本质上只是一个费用计算模块,偏向财务计算辅助,而非催缴管理执行。虽然其中的逾期等级计算可作为催缴系统的支撑逻辑,但单独来看不足以覆盖声明的主要目的。因此描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill references local file access to a fixed Excel path and describes automated notification behavior, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, missing scope declarations can lead to over-broad file/network capabilities being available implicitly, increasing the risk of unintended access to customer financial data or unauthorized outbound messaging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill describes processing customer arrears data from a local Excel file and automatically generating or sending collection notices, but it lacks privacy, authorization, and human-review safeguards. Because the data includes customer identities, payment status, and amounts owed, misuse or accidental disclosure could expose sensitive financial information and trigger unauthorized or erroneous outbound messages.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code formats reminder content from overdue-fee records and sends it via wecom_sender.send_message(...), which transmits customer/payment-related information to an external messaging system. While there is a console print about starting reminder sends, there is no user confirmation, cautionary comment/docstring about external transmission, or other explicit disclosure near the operation itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language descriptions and reminder templates that assume Chinese as the required language, including all customer-facing output. Under the policy rule, forcing a specific language without user opt-in or a documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The function transmits message content, which may include customer names, overdue status, fee types, and amounts, to an external webhook with no validation, classification, redaction, or allowlist enforcement on the destination. In this skill context, the transmitted data is business-sensitive and potentially personal, so a misconfigured or malicious webhook could cause silent data leakage outside the intended boundary.

Content

Scanner excerpt · scripts/wecom_sender.py (reported line 49)May include surrounding context.

python
payload["text"]["mentioned_list"] = [chat_id]
        
        try:
            response = requests.post(
                self.webhook_url,
                json=payload,
                timeout=10

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code posts message payloads to a configured WeCom webhook, which transmits report, reminder, and customer-related content off-process to an external service. Although there is basic success/failure logging, there is no user-facing disclosure or warning that data such as customer names, overdue amounts, and report contents will be sent via network webhook.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This markdown-sending path also posts arbitrary report content to an external webhook without safeguards on destination or content sensitivity. Because this method is used for daily/monthly reports, it can expose aggregated fee and overdue data at scale if the webhook is wrongfully configured, intercepted operationally, or repointed to an untrusted endpoint.

Content

Scanner excerpt · scripts/wecom_sender.py (reported line 85)May include surrounding context.

python
}
        
        try:
            response = requests.post(
                self.webhook_url,
                json=payload,
                timeout=10

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This skill specifies all descriptions, trigger text, templates, and operating guidance only in Chinese, without indicating that users may choose another language or that the skill is restricted to a Chinese-speaking context. That creates a potential forced-language issue under the stated policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The module docstring and description fields present the skill entirely in Chinese, which can constitute a language/locale policy issue when no user opt-in or locale justification is provided. The file does not indicate that the skill is region-specific or that users may select another language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The monthly report is saved as a JSON file under a local reports directory and contains financial collection metrics. The code logs that the file was saved, but it does not provide any prior disclosure or caution that user/business data will be persisted to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The daily check writes a JSON report to a local path, creating directories as needed. Although the code prints the save location afterward, it does not clearly warn beforehand that operational collection data will be stored on disk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file’s natural-language documentation strings are entirely in Chinese, including the module description and class initialization text, with no indication that this skill is region-specific or that other languages are supported. Under the policy, language constraints should be justified or presented as an opt-in choice rather than implicitly forced.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file contains module docstrings, method docstrings, field names, and return messages entirely in Chinese, which imposes a specific language on downstream users and integrators. Under the policy, language constraints should either provide user choice or be explicitly documented as a justified region-specific limitation, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language text throughout the file, including logs, report labels, and alert content, is fixed to Chinese. This can violate language/locale policy when the skill does not offer user opt-in or document that it is intentionally limited to a Chinese-speaking or region-specific context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.