Back to skill

Security audit

clinch-contract-signing

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only China-focused contract-signing SOP; its sensitive contract-data workflows are disclosed and aligned with its purpose.

Before installing, treat this as a China-focused contract operations checklist rather than legal advice. Use only approved OCR, CRM, storage, email, and webhook channels; confirm recipient permissions; minimize personal/contact data; and route non-PRC, cross-border, regulated, or high-value contracts to qualified legal review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description is written entirely in Chinese and frames the skill around Chinese contract-signing practice without any indication that users may choose another language or locale. Under the policy rule, forcing a specific language or locale without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow explicitly processes contract documents and contact details through OCR, CRM linking, layered permissions, and webhook-based handoff, which involves personal and potentially sensitive business data. The document mentions compliance obligations later, but it does not define any notice, lawful basis, minimization, retention notice, or operator-facing privacy controls at the point of collection and sharing, increasing the risk of non-compliant processing and unauthorized propagation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The SOP instructs staff to upload signed contracts, OCR their contents, add metadata tags, and link them into CRM systems, but it does not include any warning or control guidance for handling highly sensitive legal and commercial data. In a contract-signing workflow, this omission increases the risk of oversharing, excessive retention, misconfigured permissions, and unauthorized internal access to confidential contract terms and personal/business data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The SOP requires transferring detailed customer, contract, contact, risk, and due-diligence information, but it does not specify data classification, least-privilege access, approved channels, or masking requirements. In a contract-signing and handoff skill, this omission materially increases the chance of oversharing personal and commercially sensitive information to unauthorized recipients or insecure systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The email handoff template instructs staff to send contract amounts, risk ratings, special notes, and document links by email without requiring secure delivery, recipient validation, or confidentiality controls. Because this skill operates on post-signature contract workflows, the shared content is likely to include sensitive business terms and personal contact data, making misdelivery or mailbox compromise more damaging.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document hard-codes dispute resolution and governing law defaults to PRC law and CIETAC arbitration without documenting jurisdictional scope or requiring user confirmation that the contract is PRC-based. In a contract-signing skill, this can cause users to apply the wrong legal framework to cross-border or non-PRC transactions, creating unenforceable terms, compliance gaps, or biased negotiation positions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

SQP-3 applies to all file types. The phrase "OCR 提取文字(中文 + 英文双语)" imposes a specific language handling requirement, and later guidance repeats bilingual OCR expectations, but the document does not state that this is optional, user-selected, or limited to a clearly justified region-specific use case. That can conflict with language/locale policy requirements where users should have a choice unless the constraint is documented and necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This file presents all guidance exclusively in Chinese and does not provide any opt-in, alternative language, or justification for restricting the content to a specific language audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The guidance requires use of specific domestic e-sign platforms and a Chinese-language/English-paper dual-track process for foreign matters, which imposes a specific locale/jurisdictional workflow in absolute terms. The file does not state that these requirements apply only in China-facing transactions or offer an opt-in/choice, so the natural-language policy is overly prescriptive by locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file presents all operational instructions in a single language and does not state that the skill is intended only for Chinese-speaking users or a China-specific business context. Per SQP-3, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file presents all guidance exclusively in Chinese and does not indicate that other languages are available or that the language choice is intentional and limited to a specific audience. Under the policy rule for natural-language violations, a skill can be flagged when it effectively enforces a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.