Back to skill

Security audit

企雀 AI 员工助手 · Qique Employee

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Qique employee assistant for local CRM access, with sensitive browser and CRM permissions called out and constrained by employee/admin controls.

Install only if you use Qique and understand that the separate official runtime and Chrome extension can access browser/CRM context. Verify the downloaded package hashes, inspect the extension manifest, avoid sharing cookies or tokens in chat, and keep high-impact operations limited to the documented human-confirmed flows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The README instructs users to run npx skills add Edmon/qique-employee without pinning a specific package version, which can cause execution of whatever version is current at install time. In a security-sensitive workflow involving local MCP setup and access to clinic CRM data, this increases supply-chain risk if the package is updated maliciously or unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The command npx skills add Edmon/qique-employee --list still relies on an unpinned npx skills package, so even a supposedly non-installing discovery step may execute an untrusted latest version. Because this skill is for employee use with local MCP and business/customer access, normalizing unpinned command execution raises avoidable supply-chain exposure.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 7)May include surrounding context.

text
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This plain-text file presents the licensing notice exclusively in Chinese. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The primary heading and most of the usage instructions are written in Chinese, with only limited English support. Under the policy criteria, a skill should not impose a language/locale without user opt-in unless the constraint is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This manifest is a JSON file, so SQP-3 applies. The only distribution URLs use the qique.cn domain, which may imply a region- or locale-specific distribution path, but the file provides no natural-language explanation of any regional limitation or user choice; line L18 discusses licensing and compatibility, not locale justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.