Back to skill

Security audit

pcs转储

Security checks for vulnerabilities and agentic risk

Overview

This skill performs the stated PCS-to-EBP data transfer, but it automatically moves internal operational data with weak controls and plaintext HTTP.

Review before installing. Only run this in the intended internal environment, with authorization for both PCS export and EBP import. Prefer HTTPS endpoints, narrow the activation trigger, add explicit approval before upload, verify the destination, and delete or protect the generated Excel file after use. Avoid enabling the cron example until logging, validation, and rollback procedures are in place.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:7
Finding

Operational Data Transmitted Over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Third-Party Dependencies Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically uploads the generated Excel file to another application without any confirmation, validation of destination, or user-visible notice that scraped data will be transmitted. In this skill context, the whole purpose is cross-system data transfer from PCS to EBP/EPBP, so unintended transmission of sensitive operational data is a realistic risk if the wrong environment, session, or dataset is used.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is very broad and generic for an automation skill that performs data extraction, Excel file creation, and upload into another system. Broad activation terms like 'pcs', 'epbp', and 'RPA' increase the chance of accidental invocation in unrelated conversations, which could cause unintended automation against internal systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description explains how to run a workflow that scrapes data from an internal page, writes it to a local Excel file, and uploads it into another system, but it does not clearly warn users that these side effects occur automatically. Without prominent notice and confirmation requirements, users may trigger data movement and file creation without understanding that internal operational data is being exported and transferred between systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script's user-facing prints, comments, and UI text assumptions are entirely in Chinese, and there is no indication that users may choose another language or that the skill is intentionally restricted to a Chinese-only environment. This can violate language or locale policy when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script persists data scraped from the PCS page into a local Excel file without any consent prompt, retention notice, or cleanup step. If the table contains sensitive business data, this creates an avoidable data-at-rest exposure on the automation host and may leave residual files accessible to other users, processes, backups, or malware.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.