Back to skill

Security audit

Lithium Promo Research

Security checks for vulnerabilities and agentic risk

Overview

This is an incomplete but purpose-aligned market-research reporting skill, with local report-output risks but no evidence of malicious behavior.

Install only if you are comfortable with a Chinese-language, partly unfinished reporting helper. Use explicit output paths, review generated spreadsheets before sharing, and treat any JSON input or scraped data as untrusted until the Excel formula-sanitization issue is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/generate_excel.py:54
Finding

Untrusted Data Written to Excel Without Formula Neutralization

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a broader end-user research platform for overseas promotion resources, including country/platform/product-line analysis and Excel-format reporting. The supplied code chunk is much narrower: it parses an existing JSON input of search tasks/results, fabricates basic platform entries from those tasks, and saves a raw JSON file. Although this could be a supporting component of such a system, the actual behavior in this chunk does not implement the key declared outcomes such as true cross-country platform research, detailed extraction, or Excel dashboard generation. Therefore the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个完整的“国际推广平台调研系统”,核心能力应包括跨国家资源调研、平台发现/收集,以及Excel看板式分析输出。而提供的代码只是一个离线评分脚本:读取现成平台JSON数据,依据影响力、受众、语言、价格、备注等字段打分,生成等级并保存结果。它不执行任何网络调研、数据采集、国家级资源搜索或报表看板生成。因此其实际行为仅覆盖了调研流程中很小的一部分“评分/排序”后处理,和声明的主要用途存在明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a full 'research system' that investigates overseas promotion platforms and produces Excel dashboard reports for analysis. The supplied code only builds search URLs from hardcoded query templates, groups them by country/type, and saves the resulting task list as JSON. This is related to the declared domain, but it is a much narrower preparatory utility rather than the described end-user research/reporting system. There are no undeclared dangerous behaviors, but there is a clear description-to-behavior gap in primary functionality and output.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill describes workflows that read local files, write reports, and perform network-based research, but it does not declare any explicit tool scope such as permissions or allowed-tools. In agents that honor declarative scoping, this can lead to over-broad execution authority or ambiguous enforcement, increasing the chance of unintended file access, report overwrite, or unrestricted outbound requests if the runtime defaults are permissive.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad trigger phrases can cause the skill to activate on loosely related requests, leading the agent to perform network research and file-generation actions when the user did not intend to invoke this skill. In a system with multiple skills, this increases the risk of prompt-routing mistakes, unnecessary data handling, and accidental use of external resources.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manual trigger example "生成推广平台调研报告" is vague and lacks domain constraints, so the skill may be selected for generic marketing or platform-research requests outside the intended lithium-equipment context. That broad activation surface can misroute user prompts and trigger unnecessary browsing, parsing, or file output in contexts where another skill or no automation should be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The phrase '日语资料必备,英语接受度有限' states that Japanese-language materials are required, which is a natural-language locale constraint. Under the policy, forcing a specific language without user opt-in or a clearly documented justified regional compliance reason should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file is written primarily in Chinese while providing search templates for multiple countries, but it does not state that the language choice is optional or region-specific. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code file contains natural-language strings and descriptions exclusively in Chinese, including the top-level purpose statement, CLI description, and user-facing status/error messages. Under the policy rule for language/locale, this appears to force a specific language without user opt-in or an explicit region-specific justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The docstrings and status messages for run_search, run_parse, and run_score indicate that the code searches platforms, fetches details, and scores results. In reality, each function contains a TODO, performs no actual processing, and merely constructs or rewrites filenames, which actively misrepresents the implemented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language documentation entirely in Chinese, and the CLI description/help text elsewhere in the file follows the same pattern. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation because users are not offered any locale choice or fallback.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The argparse description, argument help, and error/output messages are presented only in Chinese. This imposes a single language on all users without opt-in or documented justification, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents itself entirely in Chinese and includes a scoring dimension that rewards support for Chinese manufacturers, indicating a locale-specific policy baked into the skill. Because the script does not offer any user opt-in, language choice, or explicit justification that it is intended only for a China-specific workflow, this is a natural-language locale/policy concern under the stated rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Line L37 states '韩语为主,英语辅助' as a directive, which imposes a specific language preference in the guidance. Under the policy, forcing a language or locale without user opt-in can be a natural-language policy violation unless it is explicitly framed as optional or justified as region-specific compliance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

Line L43 states '俄语资料必备' ('Russian-language materials are mandatory'), which imposes a specific language requirement in natural language. The file does not present this as an optional recommendation, offer alternatives, or explain a formal region-specific policy basis for requiring that language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all guidance only in Chinese and does not provide user opt-in, alternatives, or justification for restricting content to that language.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest describes generating Excel-format dashboard reports for platform research, but does not indicate that the skill will place output directly in a user Desktop location by default. The code explicitly resolves Path.home()/Desktop and writes the generated report there when --skip-search is used, which is a broader filesystem side effect than the description suggests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The module docstring is entirely in Chinese, describing the script's purpose without any indication that other languages are supported. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern, especially in a general-purpose script.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The argparse description and argument help strings are all Chinese-only, which constrains user interaction to a specific language without presenting a choice. This matches the language/locale policy violation category for natural-language content embedded in code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.