Back to skill

Security audit

库存监控与补货提醒

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned, but it can persistently change a real business inventory workbook and send inventory alerts externally without enough authorization, validation, or confirmation safeguards.

Install only in the intended inventory environment after an administrator configures the workbook path and WeCom destination. Require role-based authorization, explicit confirmation for intake/withdrawal commands, strict quantity and stock validation, backups, and an audit log before allowing the skill to modify the ledger.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:184
Finding

Unauthenticated and Unvalidated Inventory Ledger Modification

Content
View full analysis
0: available_months = new_stock / monthly_usage ws_env.cell(row=row_idx, column=4).value = available_months wb.save('/Users/mac/美兰中心C+服务.xlsx') return True return False ``` The two Unicode escape sequences above represent the original source transaction literals for stock intake and stock withdrawal, respectively. ### Technical Analysis The function accepts `item_name`, `transaction_type`, `quantity`, and `department` as parameters and performs a privileged write without checking the requesting actor or requiring approval. The documented manua ...[truncated 2708 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description specifies a concrete inventory monitoring and replenishment reminder skill operating on a real Excel workbook and supporting multiple trigger modes. The actual code does none of this: it is a minimal example script whose only behavior is printing a fixed string. This is a material purpose mismatch rather than a minor implementation gap, because the core advertised functionality is entirely absent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill supports write operations that directly modify a real Excel ledger on disk, including stock increases/decreases and saving the workbook, but the documentation does not prominently warn that these actions persist changes. In practice, ambiguous or accidental user commands could alter inventory records, damaging data integrity and creating an audit gap for business operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill automatically pushes inventory status and replenishment details to a WeCom webhook without documenting privacy, integrity, or recipient-scope risks. If misconfigured, this can disclose sensitive operational data, enable spoofed or unauthorized notifications, or send incorrect procurement instructions to downstream staff.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The description, trigger phrases, commands, templates, and examples are all specified in Chinese, and no alternative language or user choice is described. Under the policy, forcing a specific language without opt-in can be a natural-language policy issue unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.