Back to skill

Security audit

industrial-park-investment-assistant

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real招商 assistant, but it can automatically store or modify customer, channel, and room records, and one speech feature can send briefing text to an online TTS service without a separate opt-in.

Review this carefully before installing. Use it only with a workspace where automatic CRM-style updates are acceptable, disable or remove online gTTS unless users explicitly approve external speech synthesis, require confirmation before customer/channel/room writes, and restrict project IDs and enterprise names to safe identifiers. Also review any scheduled WorkBuddy automation before enabling daily sync or push behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/text_to_speech.py:84
Finding

Customer briefing data may be transmitted to an external TTS service without explicit consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_enterprise_data.py:201
Finding

Unsanitized enterprise name allows file creation outside the intended workspace

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/init_project.py:18
Finding

Unsanitized project ID permits directory and configuration creation outside the workspace

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (130)

MCP Config Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · PERFORMANCE.md (reported line 369)May include surrounding context.

md
def test_parse_performance():
    """测试数据解析性能"""
    # 读取MCP原始格式
    with open("data/房源销控表_mcp.json", "r") as f:
        mcp_data = json.load(f)
    
    start = time.time()

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a comprehensive industrial-park招商 AI assistant spanning multiple business functions and a customer-centric four-step workflow, with AI-driven assistance, guardrails, scheduled pushes, and multi-project/knowledge-base support. The supplied code does something much narrower: it is a local CLI utility for channel follow-up management. It reads one SQLite table (渠道跟进记录), computes elapsed-contact-day thresholds, prints weekly/monthly reports, ranks channels by recommendation/deal conversion, lists all channels, and updates notes for a specified channel. While '渠道管理' is one capability mentioned in the description, the code does not substantiate the assistant’s primary declared scope or most of its headline features. This is therefore a material description-behavior mismatch, not just an incomplete snippet, because the actual code’s primary purpose is substantially narrower and different from the declared end-user assistant behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The supplied code is narrowly focused on dashboard/report generation from a local SQLite database. It computes overdue follow-up items for customers and channels, aggregates alerts, counts weekly new customers, and formats results as text or HTML/SVG. This aligns only with a small subset of the declared description: customer/channel management and timeliness checks. However, the declared purpose presents a much broader AI招商助手 with multiple operational scenarios, AI-driven guidance, approval guardrails, scheduled push behavior, and multi-project/knowledge-base architecture. None of those broader capabilities are implemented in this chunk. Because the actual code’s primary purpose is much narrower than the declared description, this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code does relate loosely to招商/customer analysis because it gathers enterprise background data and computes a park-industry match recommendation, which could support lead qualification. However, the declared description presents a broad end-to-end招商 personal assistant with specific workflow stages, operational scenarios, guardrails, scheduling, and knowledge-base architecture. This code chunk instead implements a narrow command-line enterprise intelligence fetcher and local saver. Its primary purpose is materially different from the described assistant experience, and several concrete behaviors—especially local file output and Qichacha-style enterprise enrichment—are not clearly declared. Therefore this chunk is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad招商 assistant covering customer workflow management, property lookup, reception, quote plans, site-selection advice, contract generation, channel management, time-validity checks, approval guardrails, and scheduled daily customer pushes. The supplied code does not implement that workflow. Instead, it has a much narrower and different primary purpose: generating a pre-meeting briefing for a single enterprise. It reads a local customer archive, populates mostly hardcoded/mock enterprise and competitor data, analyzes expansion signals, produces dialogue scripts for different executive roles, and saves a markdown briefing document. None of the declared features like four-step processing, housing/property search, quotation generation, contract generation, No Agency approval controls, 09:00 daily pushes, or multi-project/knowledge-base separation are present in this code chunk. While some relation exists to招商/customer preparation, the actual behavior is materially different and significantly narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The description promises a broad招商 personal assistant with multiple operational scenarios, workflow orchestration, safeguards, scheduled pushes, and knowledge-base/database integration. The supplied code instead performs one narrow task: generating a meeting briefing document for a named enterprise from a local JSON file plus many hardcoded template values. While this could loosely support招商人员, it does not materially implement the declared assistant behavior, triggers, or architecture. The code’s actual resource access is limited to local filesystem reads/writes under a workspace directory, not the stated SQLite + IMA separated knowledge setup. Therefore this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad招商 AI assistant for end-to-end customer and property management workflows. However, the supplied code chunk is only a chart-generation utility. It takes a chart type argument, builds Markdown tables/ASCII bars for area distribution, rent comparison, or support maps, and writes them to a local file. Most data is hardcoded mock data, and there is no evidence of customer management, workflow orchestration, approvals, scheduling, knowledge-base access, SQLite usage, or real property lookup. While rent and property-related visualization could be tangentially supportive of招商 work, this code’s primary purpose is materially narrower and different from the declared assistant functionality, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk is an initialization utility, not the招商 assistant described. It creates folders, writes project and global JSON config files, and defines knowledge sources as Tencent Docs or local files. There is no customer workflow handling,房源查询,报价,选址,合同生成,渠道管理,审批护栏,定时推送, or AI-driven recommendation logic. The code does support a multi-project structure, which partially aligns with the description, but the storage/integration details differ materially from the declared SQLite + IMA setup. Overall, the actual behavior is a narrow setup tool and does not accurately represent the declared product functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The supplied code does relate loosely to招商 sales support, but its actual purpose is much narrower and materially different from the declared description. It only handles one sub-task: retrieving canned objection-response talk tracks and cases from an in-memory dictionary, then saving the output to a markdown file. The broad declared assistant promises a full AI-driven招商 workflow with customer progression, prioritization, recommendations, property and contract functions, compliance guardrails, scheduling, and specific architecture. None of those are implemented in this chunk. This is therefore a description-behavior mismatch, because the code’s primary function is a limited objection-response utility rather than the declared comprehensive assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code chunk does not implement the declared skill’s primary behavior as an AI招商 personal assistant. Instead, it is a backend/import utility script for reading a structured Excel template and inserting records into a local SQLite database. While some imported data domains overlap with the declared business area (property, customers, channels, competitor info, project materials), the actual function is limited to ETL-style ingestion. The declared description emphasizes an interactive four-step workflow, AI-driven recommendations and analysis, guardrails such as approval for concessions, and automated daily notifications; none of these are present in the code. Therefore this is a material description-behavior mismatch rather than merely a supporting implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full招商业务 AI assistant with workflow management, recommendations, guardrails, scheduling, and multiple business functions. The supplied code does none of that. It is narrowly focused on importing and parsing Excel/CSV tabular data into JSON-like records, likely as a data ingestion utility. While the parsed table types (customer follow-up, room inventory, channel tracking) are adjacent to the business domain, this is only a supporting data-processing script, not the described assistant. Therefore the description materially overstates and misrepresents the actual behavior of the provided code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This code chunk is materially different from the declared skill purpose. Although the banner text mentions '产业园招商助手', the actual script only measures simulated system performance using sleep-based benchmarks and simple in-memory data structures. It contains no business-facing assistant logic, no customer or property operations, no scheduling, no approval controls, and no actual MCP/SQLite/knowledge-base integrations. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个功能较完整的产业园招商AI助手平台,具备多场景业务流程、自动推送、审批护栏和多数据源架构。实际代码只是一个单文件脚本,专注于生成客户推进建议,且主要依赖固定规则和模拟数据,没有看到客户列表处理、房源检索、报价/合同生成、审批护栏、定时任务、数据库或知识库访问等实现。代码行为属于声明中“客户推进”子能力的一小部分,但远不足以支撑所宣称的整体产品能力,因此描述与实际代码存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The supplied code chunk is narrowly focused on querying and formatting park reference data. It supports only four data types and operates from a hardcoded dictionary, despite the comment mentioning a simulated data source. This is at best a small supporting utility for the '房源查询' portion of the declared assistant, but it does not match the broader declared purpose as an AI-powered, workflow-centric招商 assistant. Key declared behaviors—customer workflow management, AI decision support, approvals/guardrails, scheduled pushes, knowledge-base separation, and other business functions—are absent. Additionally, the code saves output to a local file path, an undeclared operational behavior. Therefore the description materially overstates and misrepresents what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad招商 AI personal assistant with workflow orchestration, multiple business modules, governance controls, scheduled automation, and specific storage/knowledge-base architecture. The supplied code chunk is materially narrower: it is a single-purpose smart room recommendation script using mock data. While房源查询/推荐 is one sub-scenario mentioned in the description, the actual code does not substantiate the overall declared functionality and even misrepresents its own data source as real-time database-backed. This is a clear description-versus-behavior mismatch in primary scope and implemented capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full-featured招商 AI assistant covering end-to-end customer workflow, decision-support features, business guardrails, scheduling, and multiple operational scenarios. The supplied code chunk instead is a narrow data synchronization utility for '美兰中心知识库': it defines four remote table identifiers, a record-conversion helper, local output/cache paths, and emits messages that syncing requires an MCP environment. It neither performs the assistant behaviors nor exposes the stated triggers or business logic. While syncing knowledge-base data could be a supporting implementation detail for such a system, this chunk's actual purpose is materially different and far narrower than the declared skill behavior, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk does not implement the described招商 personal assistant workflow, customer guidance, prioritization, recommendations, approvals/guardrails, daily push, contract generation, or user-triggered assistant interactions. Instead, it performs backend data synchronization for several business tables into SQLite and reports database status. While this supports the declared architecture note about SQLite/local knowledge storage and multi-project separation, the actual code’s primary purpose is materially narrower and infrastructural. Therefore the description does not accurately represent what this specific code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code does not implement the declared招商 assistant workflow or user-facing capabilities such as client management, follow-up guidance, pricing/contract generation, approval guardrails, or daily customer push. Instead, it is a developer-oriented performance test for KnowledgeBase caching, focused on timing reads and reporting cache hit metrics. While it touches a knowledge base and a property-related table, that is only incidental and does not align with the declared primary purpose. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a business-facing industrial park招商 assistant with customer workflow management, property queries, pricing, site-selection advice, contract generation, approval guardrails, scheduled daily pushes, and multi-project knowledge-base separation. The supplied code instead is a developer/test utility focused on MCP performance evaluation. It prints example MCP calls, simulates data loading and cache hits, explains concurrent tool-call strategy, prompts the operator whether to run a real MCP latency test, and generates a performance report. There is no implementation of customer management,房源查询 logic,报价方案 generation,合同 generation, guardrails like No Agency approval, 09:00 pushes, SQLite/IMA knowledge separation, or the described four-step招商 workflow. This is a materially different primary purpose, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code chunk does not implement the declared招商 AI assistant workflow or its stated core scenarios such as customer management,房源查询,报价方案,选址建议,合同生成, guardrails, daily pushes, or knowledge-base separation. Instead, it is a utility script for converting a meeting/pre-briefing document into speech audio. This is a materially different primary purpose. It also introduces capabilities not described in the declaration: reading arbitrary local briefing files, generating audio output files, invoking system TTS/subprocesses, and potentially using the network through gTTS. The declared triggers are about招商 operations, while the code is a command-line TTS tool for briefings, so the behavior is unrelated rather than a mere supporting implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a comprehensive招商/customer-follow-up assistant with workflow guidance, customer and property management, pricing/site-selection/contract scenarios, approvals, timed daily pushes, and knowledge-base separation. The supplied code does none of that. Its primary purpose is converting a meeting/pre-briefing document into speech audio on macOS. This is a materially different function and introduces undeclared capabilities such as local file access and subprocess execution of the say command. The observed behavior is not a supporting implementation detail of the declared招商 assistant; it is an unrelated utility with different inputs, outputs, and usage patterns.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a broad招商/customer-follow-up AI assistant with workflow orchestration, customer/property/quotation/site-selection/contract functions, guardrails, daily pushes, and knowledge-base architecture. The supplied code does not implement those assistant capabilities. Instead, it performs a narrow utility function: reading a local briefing file, extracting certain lines, and invoking the macOS say command to generate or play speech. This is a materially different primary purpose and introduces undeclared capabilities such as text-to-speech generation, subprocess execution, and local audio file creation. While the script references招商人员 and briefing content, that context is incidental; the actual behavior is a TTS helper, not the declared招商 AI assistant.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

该代码片段的核心行为是后台数据同步/缓存预热,属于知识库维护组件,而不是用户可交互的招商AI个人助手。虽然声明中提到知识库分离和本地库,这能解释代码是整体系统的一个支撑模块,但就该代码片段本身而言,其主要目的与声明的主要用途明显不一致。尤其是声明强调完整招商工作流、客户推进辅助、自动推送和业务护栏,而代码仅做表数据拉取与本地保存,且定时说明还有08:00/09:00差异。因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a full招商 AI assistant with customer-follow-up workflow, operational safeguards, daily automation, and multiple business scenarios. The code chunk, however, is only a test file (test_intelligent_search.py) used to validate imports, configuration presence, knowledge base reads, and intelligent search routing. It does not implement the declared assistant features such as four-step workflow handling, customer推进/处理完成 logic, quote generation, site selection advice, contract generation, approval guardrails, or scheduled daily pushes. While the tested modules may support part of the described system, this specific code chunk’s primary purpose is diagnostic/testing, which is materially different from the declared skill behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill repeatedly instructs that natural customer-related conversation should automatically trigger data-entry actions. In this business context, casual mentions may include sensitive contact details, intentions, pricing, or competitive notes, so silent persistence creates a strong risk of unauthorized record creation, modification, and privacy violations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.