Back to skill

Security audit

高校招生监控

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it asks agents to create persistent cron jobs and send reports externally without enough scope or consent detail.

Install only if you are comfortable with an agent that may be asked to fetch configured websites, write reports, edit the school list, set scheduled cron jobs, and send files through QQ. Before using it, require confirmation for any cron entry, QQ transfer, deletion, or schools.json edit, and review configured URLs so they are trusted HTTPS university pages.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/monitor.py:24
Finding

Unrestricted Configurable URL Fetching Enables Server-Side Request Forgery

Content
View full analysis
0: delay = RETRY_DELAY[min(attempt - 1, len(RETRY_DELAY) - 1)] print(f" 🔄 第{attempt + 1}次重试(等待{delay}秒)...") time.sleep(delay) response = requests.get(url, headers=headers, timeout=REQUEST_TIMEOUT) ``` The fetched URL is obtained from each site entry in the configuration: ```python for site in school['sites']: site_name = site['site_name'] url = site['url'] print(f" ▶ {site_name}: {url}") notices = get_exact_notices_for_site(site_name, url) ``` ### Technical Analysis The application treats URLs loaded from the editable `schools.json` file as trusted and passes them directly to `requests.get`. It does not validate: - The URL scheme. - The destination hostname. - The resolved IP address. - Loopback, private, link-local, multicast, or reserved address ranges. - Redirect destinations. - Whether the destination belongs to an approved university domain. Python Requests follows redirects by default. Consequently, validation limited only to an initial hostname would also be insufficient unless every redirect target is checked. A user, automation process, or agent capable of editing `schools.json` can configure URLs such as loopback services, private network hosts, or cloud instance metadata endpoints. The monitor then initiates the request using the network permissions of the proce ...[truncated 1812 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
schools.json:8
Finding

Plaintext HTTP Sources Permit Notice and Link Manipulation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:159
Finding

Third-Party Dependencies Are Unpinned and Incompletely Declared

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes capabilities that read local files, write/export documents, and access external websites, but it does not declare any explicit tool scope or permissions boundary. This is dangerous because an agent may be granted broader-than-necessary filesystem or network access at runtime, increasing the chance of unintended data access or exfiltration beyond the stated monitoring task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs that generated Word documents are sent out through QQ, but the description does not present this as a clear outbound file-transmission warning or require explicit, informed consent at the point of transfer. This is dangerous because scraped results or accidentally included local content could be exfiltrated to a third-party messaging platform, creating privacy, compliance, and data-leak risks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The FAQ instructs users that the AI will configure cron jobs automatically, which implies persistence and system-level task creation beyond passive admissions monitoring. This is dangerous because it normalizes privileged system modification without clearly describing scope, consent, review, or safety constraints, increasing the risk of unintended persistence or abuse if an agent follows the documentation literally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown describes automatic cron creation and configuration file updates by AI without warning that these actions modify the host system and persist beyond the current session. In an agent setting, this can mislead users into authorizing opaque system changes and creates a path for persistence or unsafe configuration drift under the guise of routine monitoring.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The FAQ says the AI can update schools.json and add target schools on the user's behalf, expanding the skill from monitoring into autonomous file modification. That is risky because it encourages an agent to alter local configuration state without an explicit change-management step, which can lead to unintended targets, corrupted configuration, or unauthorized modifications.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language strings throughout the script are fixed in Chinese, and the document formatting explicitly sets a Chinese font, which enforces a locale-specific experience. There is no opt-in, fallback, or documented justification that this skill is intentionally limited to Chinese-language users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language content of the skill, including its name, description, and operating instructions, is entirely in Chinese. Under the language/locale policy, forcing a specific language without user opt-in or a documented region-specific justification is a policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JSON file stores all natural-language labels in Chinese, including school names and site names, with no accompanying metadata indicating that the skill is China-specific or that Chinese is an intentional locale constraint. Under the policy rule for language/locale, forcing a single language without user opt-in or documented justification can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request headers force Accept-Language to zh-CN,zh;q=0.9,en;q=0.8, which encodes a specific locale preference. Under the language/locale policy, hard-coded locale behavior should be user-selectable or explicitly justified, and this file provides neither.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs local file creation and writes collected monitoring results into an output directory when --save is used. Although the CLI flag implies saving, there is no explicit user-facing warning in the help text or at write time about where data will be stored and that the report will persist on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code performs a file write by saving a generated .docx report to /tmp. Although it prints the saved path afterward, there is no advance user-facing warning, confirmation, or descriptive comment/docstring indicating that running the script will create a local output file containing aggregated results.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.