Back to skill

Security audit

Visit Management

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malicious, but it handles and persists sensitive customer/business data with broad, fixed local access and insufficient controls.

Install only in a controlled Chinese-language deployment where the workbook path, output directories, WeCom destination, and operators are trusted. Before production use, require explicit approval for reading the workbook, sending notifications, updating visit records, and retaining backups; also add private file permissions, retention limits, and formula neutralization for Excel writes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/visit_manager.py:201
Finding

Spreadsheet Formula Injection Through Unsanitized Visit Results

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/visit_manager.py:67
Finding

Sensitive Customer and Operational Data Written Without Explicit Access Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

声明描述的是一个完整的走访计划管理与提醒技能,核心能力应包括读取指定Excel台账、生成走访计划,并在特定时间或手动触发时发送提醒。但实际代码只是一个示例/占位脚本,仅输出固定文本,没有任何与声明目标相关的实质功能。因此代码实际行为与声明用途存在明显且重大的不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心能力是‘计划管理与提醒’,包括读取指定Excel台账、生成走访计划、发送提醒,以及对应的定时/手动触发场景。但提供的代码仅包含一个 VisitScoring 类,用于按权重计算走访质量分、统计分布、生成质量报告和改进建议。代码中虽然导入了 pandas 和 datetime,但没有读取任何Excel文件,没有任务计划生成、没有提醒发送、没有调度逻辑、没有外部触发处理。其主要目的与声明明显不同,因此构成实质性描述-行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill processes a real local Excel ledger and is configured to push generated outputs to an external WeCom webhook, but it declares no explicit tool scope or permissions. This creates an authorization gap where file access and outbound transmission capabilities are effectively hidden from policy review and user consent, increasing the risk of unintended data exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a visit-plan/reminder tool, but it embeds broad customer profiling, payment-risk analysis, repair history aggregation, and timeline construction across multiple datasets. This expands access to sensitive business and tenant information beyond what a user would reasonably expect, violating least privilege and increasing privacy and insider-risk exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill reads a real local Excel ledger containing customer data, but the description does not provide a clear user-facing warning about that access. Lack of disclosure undermines informed consent and can cause operators to trigger processing of sensitive local business data without understanding the privacy implications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Building full customer dossiers and timelines from multiple worksheets introduces broad surveillance-style visibility into tenant information without a clear need for simple visit management. Because the skill operates on a real local workbook, compromise or misuse could reveal a consolidated view of contract dates, payments, repairs, and service interactions that is more sensitive than any single sheet alone.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented logic accesses and correlates payment status, repair records, customer history, and timelines that exceed the manifest's narrow scheduling/reminder purpose. In this context, the extra data processing is more dangerous because the workbook is described as a real production ledger, so overcollection could expose sensitive operational and financial details to operators or downstream systems.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function claims to fetch visit details by unit number but actually compares tenant_name to unit_no, which can cause mis-association or failure to retrieve the correct record. In a workflow that drives reminders and external notifications, such identity-matching bugs can leak one tenant's data into another tenant's plan or produce inaccurate customer actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration includes a WeCom webhook destination for pushing generated visit plans, but the skill description does not warn that customer-related data may be transmitted externally. This is especially dangerous because the same skill aggregates financial risk, repair, and service information, so outbound messages could disclose sensitive business data to external systems or unintended recipients.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file contains natural-language content in comments, docstrings, and print strings that assumes Chinese as the only operating language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This Python file contains natural-language documentation and all generated reminder content exclusively in Chinese, with no mechanism for user language selection or any documented justification for a fixed locale. Under the policy rule for language/locale constraints, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code writes visit plans and reminders containing customer identifiers, names, room numbers, and visit purposes to local JSON files under a fixed user path without any access controls, encryption, or disclosure. If the host is shared, backed up, synced, or otherwise accessible, sensitive customer operational data may be exposed or retained longer than intended.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes the skill as generating visit plans from an Excel ledger and reminding visit tasks. This code additionally implements workflow-state mutation for existing visit records, including marking visits in progress, completed, or cancelled and saving those changes back through the data manager, which goes beyond plan/reminder generation as stated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function persistently modifies visit-history records, including status, timestamps, results, and cancellation reasons, without any visible user consent, change review, or authorization checks in this file. Unauthorized or accidental invocation could tamper with business records and expose sensitive customer interaction outcomes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function claims to load today's visit plan but instead returns hard-coded sample customer data and a fixed group ID. This can cause reminders to be generated for the wrong customer or wrong destination, creating integrity and privacy risks by sending operational messages based on fake data rather than actual plans.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a skill for managing visit plans and reminders based on an Excel ledger, with scheduled plan/reminder generation. This file instead defines a scoring algorithm, computes satisfaction/deal-rate-based quality scores, and generates analytical reports and recommendations; those analytics capabilities are not described as part of the skill's purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

In track_visit_followup, the inline comment says '租户名匹配', yet the code tests row[0] == unit_no. This is an active contradiction in the documentation and can mislead maintainers about what identifier the function uses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The scheduled task configuration hard-codes the timezone to Asia/Shanghai, and the document does not indicate that this locale setting is configurable or limited to a region-specific deployment. Under the policy, fixed locale behavior without user opt-in or clear justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module docstring presents the skill description exclusively in Chinese, which can amount to a language policy issue when no user opt-in or locale justification is provided. The file contains no indication that the skill is intentionally limited to Chinese-speaking users or a China-specific deployment context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest scope is limited to generating weekly visit plans, daily reminders, and manual visit management triggering. The daily task also compiles a daily report summary and writes it to a reports directory, which is an additional reporting behavior not described in the manifest.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This Python file contains natural-language documentation and output strings entirely in Chinese, including the module docstring and later recommendation/report text, with no indication that the user can choose another language. The policy for this audit flags language/locale constraints when a specific language is effectively forced without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.