Back to skill

Security audit

通联手续费发票申请

Security checks for vulnerabilities and agentic risk

Overview

This skill automates a disclosed invoice-application workflow, but users should verify any externally looked-up tax details before sending email.

Before installing, ensure users review the generated spreadsheets and email, especially tax numbers or invoice details that may have been looked up online. Do not let the agent send until the recipient, attachments, invoice amount, invoice type, and customer details have been checked.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to obtain enterprise invoicing information from the internet, which expands the data sources and permissions beyond the stated workflow of reading a user-provided bill, filling templates, and sending email. This can cause the agent to collect incorrect or unverified tax information and process sensitive business data without user approval, creating both integrity and privacy risks.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation phrase "通联发票" is overly general and may overlap with many ordinary invoice-related requests that are not specifically about the Tonglian card-fee application process. Because this skill can collect missing data, generate templates, and prepare external email, accidental invocation could lead to unauthorized or erroneous handling of financial and contact information.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation phrase "通联发票" is overly general and may overlap with many ordinary invoice-related requests that are not specifically about the Tonglian card-fee application process. Because this skill can collect missing data, generate templates, and prepare external email, accidental invocation could lead to unauthorized or erroneous handling of financial and contact information.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The instruction that invoice information can be looked up on the internet without explicit user opt-in permits external data gathering that is unnecessary for the core task and may bypass user control. In this context, the skill handles tax and billing details, so using unapproved external sources increases the chance of privacy violations, inaccurate invoicing, and compliance issues.

Static analysis

No suspicious patterns detected.