Back to skill

Security audit

IDC Enterprise Agent COMPASS

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only enterprise Agent planning skill with some packaging and localization issues, but no evidence of hidden execution, credential access, exfiltration, or persistence.

Before installing, expect a business-strategy advisory skill oriented toward Chinese/bilingual IDC COMPASS workflows. Review the packaging because the listed reference paths and actual file names do not fully match, and verify any vendor or licensing claims independently before relying on them for procurement decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · vendor-enterprise.md (reported line 77)May include surrounding context.

md
**Key questions to ask the user:**
- "Can you trace back through a process and see every action that was taken, by whom or what, and why?"
- "Do your systems have audit logs that capture the full context of each action?"
- "How long are logs retained, and do they meet your compliance requirements?"

**Implications for Agent scenarios:**

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s instructional content and usage guidance are presented in Chinese, and there is no statement that the skill is Chinese-only or that users may choose another language. This can violate a language/locale policy when the skill effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill embeds a rigid response rule requiring a specific output structure and Chinese phrasing without checking the user's language or formatting preference. This can override user intent, reduce transparency, and cause unsafe prompt-priority behavior where the skill dictates presentation constraints that the user did not request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill embeds a hard instruction to output a specific response structure and specific Chinese phrasing before answering user requests, without indicating that this behavior should depend on user preference. While not directly enabling code execution or data exfiltration, it can override user intent, reduce usability, and create prompt-priority conflicts in downstream agent behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · vendor-industry.md (reported line 104)May include surrounding context.

md
### Expansion Phase (3-6 months)
- Human confirms only exception cases and high-impact decisions
- Agent operates in "auto-execute with notification" mode for routine tasks
- Narrow escalation rules based on accumulated trust data

### Maturity Phase (6+ months)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown reference contains substantial Chinese-only headings, table content, and source descriptions alongside English sections, which can force a language/locale on users who are not expecting it. The file does not state that it is intended only for Chinese-speaking users or provide an opt-in/alternative language path, so it appears to violate the language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains bilingual section titles such as "Perception (感知与理解)" and similar mixed-language headings throughout the document. Because the file does not explain that Chinese is required or offer an opt-in language choice, it may violate a language/locale policy requiring user choice or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description mixes English and Chinese trigger phrases as activation conditions, but the file does not state whether multilingual behavior is optional, user-selected, or constrained to a specific locale. Under the policy for natural-language issues, forcing or implicitly assuming a language/locale without opt-in can be a violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.