Back to skill

Security audit

工单分派与SLA监控

Security checks for vulnerabilities and agentic risk

Overview

The skill matches a work-order automation purpose, but it would read and modify a real business workbook and broadcast detailed repair information broadly without clear guardrails.

Install only for a clearly authorized facilities-management environment. Before use, replace @all escalation with scoped recipients, require confirmation or policy checks for broad messages, validate the Excel schema before writes, and ensure the hardcoded workbook path and WeCom webhook are configured by the user rather than assumed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

代码与声明的主要用途严重不一致。声明描述的是一个完整的工单分派与SLA监控技能,但实际代码只是示例/占位脚本,只有打印输出,没有访问Excel、没有处理报修输入、没有定时任务、没有状态跟踪或升级能力。未发现额外的未声明高风险能力,但当前实现明显不能支撑声明的功能,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 6)May include surrounding context.

md
description: 工单分派与SLA监控技能。基于真实Excel台账(美兰中心C+服务.xlsx)自动分派报修工单,跟踪处理进度,超时自动升级。触发场景:(1) 企业报修(企微、电话、邮件),(2) 管家上报维修需求,(3) 定时监控工单状态(每小时),(4) 超时未处理自动升级。
---

# 工单分派与SLA监控技能 (Workorder Dispatch Skill)

## 功能概述

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is designed to automatically escalate work-order details through enterprise messaging, including broad notifications, but it does not define any privacy guardrails, minimization rules, or approval checks. In this context, repair descriptions, locations, reporter names, and status details may be disclosed more broadly than necessary, creating privacy and operational information exposure risks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file declares the final defined column as '月份', but later logic assumes columns 13 and 14 contain customer feedback fields. This schema inconsistency increases the chance of writing ratings/comments into the wrong cells, causing data tampering by logic error and undermining the integrity of the source-of-truth Excel ledger.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented workbook schema defines 13 columns, but the feedback function writes to additional columns that are not part of the declared ledger structure. On a real workbook this can corrupt adjacent data, overwrite unintended fields, or create silent integrity issues that affect routing, reporting, or downstream business processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The urgent escalation template uses '@all' and includes location, urgency, and description fields pulled from work-order content. Because these fields may contain sensitive tenant, facility, or incident details, broadcasting them to all recipients can cause unnecessary data exposure and may amplify social engineering or reputational risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The activation description and all user-facing instructions are presented in Chinese, and the manual trigger phrases are also Chinese-specific. There is no statement that the skill is region-specific by design or that users may choose another language, which can violate a language-choice policy if such opt-in is required organizationally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.