Back to skill

Security audit

Service Matching

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-aligned for C+ service matching, but it reads identifiable tenant/business records, can push them to WeCom, runs on a schedule, and writes follow-up data back to the source Excel file without enough control detail.

Review before installing. Only use this skill if the Excel ledger path, tenant data fields, scheduled daily analysis, WeCom webhook recipients, and Excel write-back behavior are approved by the business owner. Configure the webhook carefully, minimize or mask tenant/contact details in notifications, and require explicit operator approval before updating source records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a concrete business function for analyzing real Excel-based records and performing C+ service matching under specific trigger conditions. The actual code chunk does none of this: it is an example placeholder script with a print statement and TODO comments. This is a material mismatch in primary purpose and capabilities, not just an incomplete supporting detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The configuration includes a WeCom webhook and the workflow states that recommendations are pushed externally, yet the skill description does not clearly warn that tenant-identifying and business-profile data may be transmitted to third-party recipients. External webhook delivery materially increases exposure because sensitive customer data can leave the local Excel environment and be disclosed to unintended audiences if the webhook is misconfigured, overshared, or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill reads tenant/customer information from a real Excel ledger, including contact and enterprise profile data, but the description does not clearly warn users that personal and business data will be processed to generate recommendations. This reduces transparency and increases the risk of unintended handling of sensitive tenant information in a production environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest and main description focus on mining needs from visit records and matching C+ service resources, with recommendations sent for confirmation. However, track_service_followup performs persistent write-back to the source Excel file by changing follow-up status, time, and notes, which is a broader record-management capability than the stated matching function.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes extracting enterprise needs from visit records and matching suitable C+ services. The check_followup_reminders and evaluate_service_effectiveness functions implement operational reminder management and post-service scoring/assessment, which extend the skill into workflow supervision and analytics not described in the stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.