Back to skill

Security audit

智能体合同

Security checks for vulnerabilities and agentic risk

Overview

This skill needs Review because it claims autonomous legally binding contract powers without concrete controls, scoping, or implementation to make that safe.

Install only if you treat this as an untrusted drafting aid, not as a system for signing, enforcing, or validating contracts. Do not allow it to run commands, modify files, use credentials, or make legal commitments without explicit human and legal review.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest markets autonomous negotiation, signing, execution, and enforcement of commercial contracts, but the body of the skill is largely a generic content-generation template with no concrete legal workflow, controls, or enforcement logic. This mismatch can mislead users or downstream agents into trusting the skill for high-stakes legal actions it is not actually equipped to perform, increasing the risk of unsafe automation and invalid contractual outcomes.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documentation claims legal-effect automation and lawyer-reviewed assurance, but the actual usage described elsewhere only supports generated content from templates and style guidance. In a legal-contract context, false assurances of legal validity can cause users or agents to rely on output as enforceable or compliant when it may be neither, creating significant legal, financial, and operational exposure.

Intent-Code Divergence

Low
Confidence
88% confidence
Finding
The skill asserts that command execution is limited to a whitelist and performed safely, yet the manifest grants broad exec capability and the file provides no enforceable mechanism for restricting commands. This creates a dangerous trust gap where operators may believe execution is constrained when, in practice, an agent may have wider command-execution latitude than documented.

Vague Triggers

High
Confidence
97% confidence
Finding
The activation guidance is extremely broad, effectively suggesting use whenever AI models, agent orchestration, or LLM applications are involved. Overbroad invocation criteria increase the chance this high-risk legal skill will be loaded in unrelated contexts, expanding attack surface and raising the probability of accidental misuse or unsafe autonomous legal assistance.

Missing User Warnings

Critical
Confidence
99% confidence
Finding
The skill advertises autonomous negotiation, signing, execution, and enforcement of legally binding contracts without strong warnings, approval checkpoints, or prohibitions on unsupervised high-impact legal action. In context, this is especially dangerous because legal commitments can create immediate financial and regulatory obligations, and an AI agent acting autonomously may exceed authority, mishandle terms, or produce unenforceable or harmful agreements.

Static analysis

No suspicious patterns detected.