Back to skill

Security audit

daily-briefing

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a daily operations briefing, but it asks for broader access and secrets than it explains while reading and sending sensitive business, account, and system status data.

Review this before installing if the environment contains real business data. Only enable it for an administrator who should see sales, order, account-cookie status, service-health, and risk-alert summaries; remove unexplained secrets such as SILICONFLOW_API_KEY, avoid granting memory_search unless a concrete need is documented, and verify where QQBot notifications and local briefing files will be stored.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (15)

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/daily_briefing.py (reported line 61)May include surrounding context.

python
import requests
    try:
        resp = getattr(requests, method.lower())(url, timeout=timeout, **kwargs)
        if resp.status_code == 200:
            try:
                return {"success": True, "data": resp.json()}

Tainted flow: 'dailyhot_url' from os.environ.get (line 359, credential/environment) → requests.get (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/daily_briefing.py (reported line 360)May include surrounding context.

python
try:
        import requests
        dailyhot_url = os.environ.get("DAILYHOT_BASE_URL", "http://localhost:6688")
        resp = requests.get(f"{dailyhot_url}/health", timeout=5)
        if resp.status_code != 200:
            tasks.append({
                "department": "工部",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

该技能的核心方向与描述部分一致:它确实在聚合多个“部门”的运营任务并生成今日任务清单,也能推送到QQBot。但描述不准确且不完整。代码不仅做待办汇总,还执行了基础设施健康检查、账号配置检查、风控文件读取、数据库销售统计、发货跟踪分析,并把结果落盘保存;此外触发/输出方式也并非仅限QQBot,脚本主要通过CLI参数决定推送到stdout、qqbot、all及输出文件,代码中没有实现管理员QQ消息触发逻辑。因此按照“存在未声明能力或触发上下文不符即算不匹配”的标准,应判定为 mismatch。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a scheduler/reporting skill that aggregates departmental to-dos and pushes a daily briefing. Granting an exec capability would allow arbitrary command execution, which is not justified by the described purpose in this file and goes beyond obvious implementation needs for generating and sending a task summary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documented workflow focuses on reading operational status, sales/order information, and sending a QQBot briefing, but the manifest also requires SILICONFLOW_API_KEY, ALIST_BASE_URL, and XIANYU_COOKIE_1 without explaining their role in the described behavior. These sensitive inputs imply broader capabilities than the stated purpose justifies from the documentation alone.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill description and usage examples consistently frame delivery as QQBot-based, yet the exception-handling section says failures degrade to enterprise WeCom push via WECOM_WEBHOOK_URL. This is not merely omitted detail in the manifest header; it actively changes the destination/channel of notifications compared with the documented intent.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a generator that aggregates departmental to-dos and pushes a personalized daily list to an administrator QQBot. In addition to aggregation, the code actively probes multiple service /health endpoints and inspects whether XIANYU cookies are configured, which expands behavior into infrastructure monitoring and operational credential auditing rather than just compiling task items.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest centers on pushing the generated daily task list to an administrator QQBot, but the code persists a briefing JSON file, optionally writes an output report file, and supports direct console output. These are additional delivery and storage behaviors not reflected in the stated description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level documentation explicitly states '支持QQBot和企业微信推送'. However, push_to_wecom is documented as deprecated and simply forwards to QQBot, and main() also rewrites wecom push requests to QQBot, so the documentation contradicts actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown states that the skill automatically aggregates departmental to-do items and pushes a personalized task list to an administrator QQBot. The description does not warn that business metrics, account status, and system-health information may be transmitted over messaging channels, which is relevant to user data, privacy, and system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The exception-handling table says QQBot push failures degrade to enterprise WeCom push using a webhook URL. This changes the destination and transport for the same operational data, but the markdown does not provide an explicit warning or consent note about this alternate channel.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest description specifies Chinese-only trigger phrases such as "今日任务" and the rest of the skill instructions are presented solely in Chinese. This may impose a fixed language/locale behavior without stating that the user can choose a language or that the locale restriction is intentional and documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, usage/help context, and all user-facing task/push text are written exclusively in Chinese, indicating the skill is designed to operate in a single language without opt-in or fallback. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file contains multiple natural-language comments, messages, and docstrings exclusively in Chinese, including autogenerated notes and test descriptions. Under the policy, forcing a specific language without user opt-in or clear documented justification is a locale/language policy violation, and no opt-in or region-specific justification is present in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.