Back to skill

Security audit

pitch-visit-proposal

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese B2B sales-visit playbook with no executable code or hidden install behavior, though users should treat its China-specific and WeChat/CRM guidance as contextual business advice.

Install only if you want Chinese-language, China-market B2B sales-visit guidance. Before using its WeChat, gift, CRM, and follow-up recommendations, check your employer's privacy, anti-bribery, record-retention, and customer-communication policies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The section '中国化独有,不按字面听' instructs users to interpret customer language through a specifically Chinese cultural lens, and elsewhere the document states that '中国客户' behave in these ways. While the tag mentions 'china', the skill body does not clearly state that the skill should only be used for China-region contexts or require user confirmation before applying these locale-specific assumptions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Line L03 explicitly states '加中国化字段' and the document consistently frames the skill around China-specific communication norms and classifications. Because the file does not offer an opt-in or explain that this template is only for a China-specific sales context, it can be read as forcing a locale-specific approach by default.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest explicitly says the skill should not be used for deal progression/closing and points that work to another skill, but this file instructs the rep to treat confirmed next-step actions as a pass and 'immediately record in CRM.' It also frames the content as '临门一脚推进动作' and '闭合', which is sales-advancement behavior rather than visit/proposal support only.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages collecting a personal WeChat contact as a success signal and communication upgrade without any privacy notice, consent standard, data-minimization guidance, or corporate-channel preference. In enterprise contexts, this can pressure users into moving business communication onto personal contact channels, increasing privacy, compliance, record-retention, and social-engineering risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Section three explicitly derives from a customer-success '续约 / 增购 / 转介绍' framework and adapts it into hooks such as trial, POC, pilot, and reference-visit motions. Those are commercial expansion/progression tactics, which the manifest excludes in favor of a different skill focused on progression/closing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file defines a '双方行动计划', pass/fail criteria, upgrade warning signals, and warm walk-away logic for whether the opportunity is advancing. This is materially similar to deal progression/closing methodology, whereas the manifest expressly excludes deal progression/closing from this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file presents all operational guidance in Chinese and does not provide any user opt-in, alternative locale, or justification that the skill is intentionally limited to Chinese-speaking users. Under the natural-language policy rule, forcing a specific language without user choice is a policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This file is a full post-visit debrief workflow, while the skill metadata explicitly says the skill should not be used for post-call structured debrief. That mismatch can route users into unsupported or unintended workflows, causing policy bypass, wrong tool selection, and leakage of conversation content into the wrong process path.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document opens with Chinese-localized guidance and asserts a China-specific practice baseline without any user opt-in or locale detection. While not directly a security exploit, forced locale assumptions can produce inappropriate guidance, mishandle user expectations, and increase the chance of incorrect business advice when used in broader contexts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The closing section explicitly sends users into progression, closing, and follow-up workflows that the manifest says belong to another skill. This weakens skill-boundary enforcement and can let an agent drift into adjacent high-stakes sales actions without the controls, prompts, or validation expected in the designated skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The text explicitly frames the methodology as requiring a '中国化改造', indicating the skill is tailored to a China-specific communication and decision-making context. This imposes a locale-specific operating model in the skill content without offering user choice or clearly documenting that it is only intended for China-region use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L03 states '加中国化变量', which directs the skill content toward a specific locale/language context by default. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the regional constraint is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The title and opening note explicitly frame the guidance as Chinese-local practice only, with no opt-in or acknowledgement of other language or locale contexts. This can violate language/locale policy because it prescribes a specific cultural-linguistic mode by default rather than offering user choice or clearly scoping it as optional regional guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file is fully Chinese-language and presents itself as a 'Chinese version' adaptation, but it does not state that the skill is intended only for Chinese-speaking users or offer any language choice. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation unless the locale restriction is explicit and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all operational guidance in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.