Back to skill

Security audit

success-renewal-management

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executable renewal playbook, but it under-scopes privacy-sensitive customer communication signals and blurs its own boundary against expansion work.

Review before installing. Use only where China-focused, Chinese-language B2B renewal guidance is intended. Do not let the skill process chat screenshots, personal social-media interactions, or private group communications unless your organization has explicit approval, notice, lawful basis, retention limits, and access controls. Keep expansion or upsell work in a separate, user-approved workflow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file directs renewal workflows toward upsell and expansion actions, including '增购钩子', 'upsell', and an explicit handoff to 'success-expansion', even though the skill metadata says it must not be used for account expansion. This scope creep can cause the agent to act outside its authorized purpose, producing misaligned recommendations and potentially inappropriate customer handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The reference explicitly frames the skill around a China-specific operating context, including Chinese enterprise types, localization compliance, and WeChat/WeCom as the primary battlefield. This creates a locale-specific constraint in the skill without any visible user choice or clear statement in the main skill body that the skill is only intended for that regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file title and all guidance are written exclusively in Chinese, and the content is framed as a China-specific adaptation without any indication that users may choose another language or locale. Under the policy rule, forcing a specific language or locale without explicit opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document explicitly recommends using personal and social interaction signals such as WeChat activity, Moments interaction, group chat screenshots, and leadership WeChat recognition as inputs to customer health scoring. These data points are intrusive, weakly justified for the stated business purpose, and can lead to privacy violations, biased account treatment, and unauthorized processing of personal communications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance instructs collection and use of potentially sensitive customer interaction content, including complaints in enterprise chat groups, screenshots, and interpersonal signals, without any privacy notice, consent model, retention rule, or warning about user impact. In a customer success context, this increases the likelihood of covert monitoring and secondary use of communications beyond reasonable expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file’s instructional content and templates are presented in Chinese throughout, which can impose a specific language on users without any stated opt-in or explanation. Under the policy, forced language or locale constraints should be flagged unless the skill offers a choice or clearly documents a justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The section titled “中国沟通节奏” prescribes communication channels and practices specifically for China, and the entire document is written in Chinese with no indication that language or locale is optional. Under the policy rule, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless clearly documented as region-specific and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The file content is presented primarily in Chinese with embedded English terminology such as "renewal matrix," "Healthy," and "Critical," but does not state that language choice is optional or targeted to a specific locale. Under the language/locale policy, skills should not force a language or mixed-locale presentation unless the constraint is justified or the user is offered a choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.