Back to skill

Security audit

天机商查(Tianji Business Search)-完全免费

Security checks for vulnerabilities and agentic risk

Overview

This skill searches public company information, but it asks the agent to omit sources in reports and uses a local search helper, so it should be reviewed before use.

Review before installing. The skill is aimed at public company research, but it may send searched company names and business-intelligence intent to a Baidu search helper, and its main instructions tell the agent not to show sources. Ask the agent to include source links and collection dates, verify important claims against official registries, and do not rely on it alone for legal, financial, or reputational decisions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill invokes a shell command to run another skill's Python script, but the manifest does not declare any explicit tool scope or allowed-tools boundary. This weakens containment and reviewability, making it easier for the skill to gain broader execution capability than users or the platform may expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs the agent to present collected business information without citing sources, even though the workflow depends on aggregating public data and recommends verification. Removing provenance prevents users from assessing reliability, detecting errors, or distinguishing official records from third-party summaries, which can mislead due-diligence or compliance decisions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Presenting collected business intelligence without source citations reduces transparency into where the information came from and whether it is trustworthy. In a due-diligence context this can enable silent propagation of stale, incorrect, or selectively framed data while appearing authoritative.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

An instruction to omit sources from the final report facilitates unattributed disclosure of aggregated information and obscures whether data was drawn from authoritative public registries, commercial databases, or news reports. This increases the chance of unsafe reliance on unverified or context-stripped information, especially when reporting legal or reputational risk data about companies or individuals.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This script sends company names and derived business-intelligence queries to an external search component without explicit notice or consent at runtime. In due-diligence or competitive-analysis contexts, the queried target itself can reveal sensitive business intent, so silent transmission creates a real privacy and operational-security exposure.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/business_query.py (reported line 49)May include surrounding context.

python
]

        try:
            result = subprocess.run(
                cmd,
                capture_output=True,
                text=True,

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Natural-language policy violations include forcing a specific language without user opt-in. This skill's description and operating instructions are entirely in Chinese, and there is no indication that users may interact in another language or that the locale limitation is intentional and documented.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The entire skill content is presented only in Chinese, beginning with the Chinese title and continuing throughout the instructions and examples. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

User-facing documentation, query templates, status messages, and report output are primarily hardcoded in Chinese. There is no indication that users can opt into another language or that the Chinese-only behavior is a justified regional constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.