Back to skill

Security audit

OW Strategy 7 Step | 大恩营销策划七步法

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a real estate marketing framework, but its helper script can read or overwrite JSON files outside its own project folder if given a crafted project name.

Review this skill before installing if you plan to use the Python helper. Avoid untrusted or unusual project names, especially names containing slashes, backslashes, drive prefixes, or '..', because the current script does not confine project files to its intended state/projects directory. The methodology documents themselves appear purpose-aligned.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/seven_steps.py:40
Finding

Path Traversal Enables Arbitrary JSON File Read and Overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger terms are broad marketing phrases like '营销策划', '项目定位', and '传播策略' that can match many ordinary business conversations, causing the skill to activate outside the author's intended context. Overbroad activation can inject unsolicited domain-specific guidance into unrelated chats, increasing the chance of context confusion, workflow disruption, or accidental use when sensitive business discussions are occurring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire template is written in Chinese and presents a fixed-language structure for the skill artifact, with no indication that users may request another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description, docstrings, templates, usage text, and runtime messages are all presented only in Chinese, which imposes a specific language without any visible opt-in or alternative. Under the stated policy, language constraints should either be user-selectable or clearly documented as a justified locale-specific limitation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code creates a JSON file under the state/projects directory and writes project content to it, but the function itself provides no prompt, warning, or explanatory comment that user data will be persisted locally. The same pattern appears elsewhere in the file, indicating the skill performs file writes that could affect user data without clear disclosure at the point of operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The save_project function writes the full project object back to the project's JSON file, replacing prior contents, but there is no confirmation prompt or user-facing warning about overwriting stored data. Because this changes persisted project state, it is a safety-relevant file write lacking visible disclosure in the code path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The file includes an English overview, but the core description and the full operational content are primarily in Chinese and do not state that the user can choose their preferred language. This can amount to a locale/language policy issue when a skill implicitly defaults to one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown guide presents all instructions and content exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. The policy requires avoiding forced language or locale constraints unless the choice is offered or the limitation is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.