Back to skill

Security audit

ContractAI Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese contract review and template tool with overstated marketing claims but no hidden network, persistence, credential access, or unsafe execution behavior.

Install only if you want a Chinese-language, local, rule-based contract checker/template generator. Do not rely on its marketing claims as proof of AI legal analysis, current law coverage, OCR/PDF support, or lawyer-grade review, and avoid feeding confidential contracts unless local processing and explicit report files are acceptable for your workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

描述强调的是“AI合同审查”与“合规检查”类能力,核心应包括分析现有合同、识别风险、检查法律合规、自动修改条款等。但该代码并不读取或审查已有合同文本,也没有任何AI分析、规则校验、风险评分、条款比对、合规审查或管理功能。它仅基于内置模板生成买卖合同、劳动合同、房屋租赁合同和保密协议,属于合同起草/模板生成工具。虽然描述中提到“模板生成”,这一点与代码部分吻合,但这只是描述中的一个子项,代码缺失其余主要宣称能力,因此描述与实际行为存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

该描述与代码部分匹配,因为代码确实执行合同风险识别、一定程度的合规/完整性检查,并生成审查报告。但描述明显夸大了能力范围。代码没有自动修改合同条款,只是在报告中输出建议;没有任何模板生成功能;也没有企业级合同管理相关实现。并且“AI合同审查专家”这一表述与实际代码行为不一致,代码仅使用预定义规则和关键词/正则匹配进行检测,没有体现模型推理、学习或智能生成能力。因此属于描述与实际行为存在实质性不一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill title and core value proposition are presented entirely in Chinese, and the examples and templates throughout the document assume Chinese-language usage. For an all-users skill README, this creates an implicit language constraint without opt-in or explanation of why the skill is limited to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
81% confidence
Finding

The skill advertises command usage that reads user-supplied contract files and writes generated reports, but it does not declare any tool scope such as permissions or allowed-tools. This creates an undeclared capability boundary, increasing the risk that sensitive legal documents are processed or exported without clear platform-level constraint or user expectation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill encourages users to submit contracts and export reports but does not warn that contract text may contain highly sensitive legal, commercial, and personal information. In a contract-review context, this omission is more dangerous because users may upload confidential agreements, assume privacy protections, and inadvertently expose or persist sensitive data in generated outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown report presents all user-facing content in Chinese, including headings, risks, recommendations, and closing guidance, with no indication that the language is optional or limited to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language descriptions and all user-facing messaging in Chinese, indicating a fixed language/locale behavior. The file does not offer any user opt-in, alternate locale selection, or documentation that the tool is intentionally limited to a Chinese-only jurisdiction or audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language content of the skill, including its description, headings, and usage guidance, is entirely Chinese. This effectively forces a specific language/locale experience without indicating user opt-in or explaining that the skill is intended only for a Chinese-speaking or China-specific legal context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This plain-text skill file contains natural-language content only in Chinese, and there is no accompanying statement that the language is optional, user-selected, or required for a specific regional/legal workflow. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This Python file contains natural-language descriptions and all built-in templates entirely in Chinese, indicating the skill is designed to operate in a specific language/locale. The file does not provide any opt-in, alternative locale selection, or justification that it is restricted to a China-specific compliance context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.