T09 · Insecure Skill Coding Practices
- Location
scripts/visit_manager.py:201- Finding
Spreadsheet Formula Injection Through Unsanitized Visit Results
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is not malicious, but it handles and persists sensitive customer/business data with broad, fixed local access and insufficient controls.
Install only in a controlled Chinese-language deployment where the workbook path, output directories, WeCom destination, and operators are trusted. Before production use, require explicit approval for reading the workbook, sending notifications, updating visit records, and retaining backups; also add private file permissions, retention limits, and formula neutralization for Excel writes.
scripts/visit_manager.py:201Spreadsheet Formula Injection Through Unsanitized Visit Results
scripts/visit_manager.py:67Sensitive Customer and Operational Data Written Without Explicit Access Controls
声明描述的是一个完整的走访计划管理与提醒技能,核心能力应包括读取指定Excel台账、生成走访计划,并在特定时间或手动触发时发送提醒。但实际代码只是一个示例/占位脚本,仅输出固定文本,没有任何与声明目标相关的实质功能。因此代码实际行为与声明用途存在明显且重大的不一致。
声明描述的核心能力是‘计划管理与提醒’,包括读取指定Excel台账、生成走访计划、发送提醒,以及对应的定时/手动触发场景。但提供的代码仅包含一个 VisitScoring 类,用于按权重计算走访质量分、统计分布、生成质量报告和改进建议。代码中虽然导入了 pandas 和 datetime,但没有读取任何Excel文件,没有任务计划生成、没有提醒发送、没有调度逻辑、没有外部触发处理。其主要目的与声明明显不同,因此构成实质性描述-行为不一致。
The skill processes a real local Excel ledger and is configured to push generated outputs to an external WeCom webhook, but it declares no explicit tool scope or permissions. This creates an authorization gap where file access and outbound transmission capabilities are effectively hidden from policy review and user consent, increasing the risk of unintended data exposure.
The skill is presented as a visit-plan/reminder tool, but it embeds broad customer profiling, payment-risk analysis, repair history aggregation, and timeline construction across multiple datasets. This expands access to sensitive business and tenant information beyond what a user would reasonably expect, violating least privilege and increasing privacy and insider-risk exposure.
The skill reads a real local Excel ledger containing customer data, but the description does not provide a clear user-facing warning about that access. Lack of disclosure undermines informed consent and can cause operators to trigger processing of sensitive local business data without understanding the privacy implications.
Building full customer dossiers and timelines from multiple worksheets introduces broad surveillance-style visibility into tenant information without a clear need for simple visit management. Because the skill operates on a real local workbook, compromise or misuse could reveal a consolidated view of contract dates, payments, repairs, and service interactions that is more sensitive than any single sheet alone.
The documented logic accesses and correlates payment status, repair records, customer history, and timelines that exceed the manifest's narrow scheduling/reminder purpose. In this context, the extra data processing is more dangerous because the workbook is described as a real production ledger, so overcollection could expose sensitive operational and financial details to operators or downstream systems.
The function claims to fetch visit details by unit number but actually compares tenant_name to unit_no, which can cause mis-association or failure to retrieve the correct record. In a workflow that drives reminders and external notifications, such identity-matching bugs can leak one tenant's data into another tenant's plan or produce inaccurate customer actions.
The configuration includes a WeCom webhook destination for pushing generated visit plans, but the skill description does not warn that customer-related data may be transmitted externally. This is especially dangerous because the same skill aggregates financial risk, repair, and service information, so outbound messages could disclose sensitive business data to external systems or unintended recipients.
This file contains natural-language content in comments, docstrings, and print strings that assumes Chinese as the only operating language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.
This Python file contains natural-language documentation and all generated reminder content exclusively in Chinese, with no mechanism for user language selection or any documented justification for a fixed locale. Under the policy rule for language/locale constraints, forcing a specific language without opt-in is a natural-language policy violation.
The code writes visit plans and reminders containing customer identifiers, names, room numbers, and visit purposes to local JSON files under a fixed user path without any access controls, encryption, or disclosure. If the host is shared, backed up, synced, or otherwise accessible, sensitive customer operational data may be exposed or retained longer than intended.
The manifest describes the skill as generating visit plans from an Excel ledger and reminding visit tasks. This code additionally implements workflow-state mutation for existing visit records, including marking visits in progress, completed, or cancelled and saving those changes back through the data manager, which goes beyond plan/reminder generation as stated.
The function persistently modifies visit-history records, including status, timestamps, results, and cancellation reasons, without any visible user consent, change review, or authorization checks in this file. Unauthorized or accidental invocation could tamper with business records and expose sensitive customer interaction outcomes.
The function claims to load today's visit plan but instead returns hard-coded sample customer data and a fixed group ID. This can cause reminders to be generated for the wrong customer or wrong destination, creating integrity and privacy risks by sending operational messages based on fake data rather than actual plans.
The manifest describes a skill for managing visit plans and reminders based on an Excel ledger, with scheduled plan/reminder generation. This file instead defines a scoring algorithm, computes satisfaction/deal-rate-based quality scores, and generates analytical reports and recommendations; those analytics capabilities are not described as part of the skill's purpose.
In track_visit_followup, the inline comment says '租户名匹配', yet the code tests row[0] == unit_no. This is an active contradiction in the documentation and can mislead maintainers about what identifier the function uses.
The scheduled task configuration hard-codes the timezone to Asia/Shanghai, and the document does not indicate that this locale setting is configurable or limited to a region-specific deployment. Under the policy, fixed locale behavior without user opt-in or clear justification is a natural-language policy concern.
The module docstring presents the skill description exclusively in Chinese, which can amount to a language policy issue when no user opt-in or locale justification is provided. The file contains no indication that the skill is intentionally limited to Chinese-speaking users or a China-specific deployment context.
The manifest scope is limited to generating weekly visit plans, daily reminders, and manual visit management triggering. The daily task also compiles a daily report summary and writes it to a reports directory, which is an additional reporting behavior not described in the manifest.
This Python file contains natural-language documentation and output strings entirely in Chinese, including the module docstring and later recommendation/report text, with no indication that the user can choose another language. The policy for this audit flags language/locale constraints when a specific language is effectively forced without opt-in or justification.
No suspicious patterns detected.