Back to skill

Security audit

JIANYAOFANGAN01

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for drafting IT proposals, but it persists sensitive proposal state and cloud folder tokens locally and uploads final documents to Feishu without enough scoping or retention guidance.

Install only if you are comfortable with local plaintext proposal state files and Feishu cloud upload. Before use, confirm where state files are stored, avoid saving sensitive infrastructure details or credentials, delete proposal JSON files after completion, and prefer a pinned dependency setup for python-docx.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
references/template.md:48
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:30
Finding

Plaintext Persistence of a Cloud Folder Token in Workflow State

Content
View full analysis
.json 2. The state file contains the proposal title, budget format, current phase, confirmed content from each phase, and timestamps. ``` ```json { "title": "Full proposal title", "budget_type": "Text summary | Detailed table", "current_phase": 2, "phases": { "0": { "confirmed": true, "title": "...", "budget_type": "..." }, "1": { "confirmed": true, "content": "..." }, "2": { "confirmed": false, "user_input": "Original current-state information supplied by the user" } }, "template_path": "Path to the user-provided template file (optional)", "folder_token": "Feishu Drive folder token (optional)", "created_at": "ISO 8601", "updated_at": "ISO 8601" } ``` ### Technical Analysis The Skill directs the agent to persist workflow state in a regular JSON file and explicitly includes a Feishu Drive folder token in that state. It does not specify restrictive file permissions, encryption, a credential store, token redaction, expiration, or deletion after the proposal is completed. The same JSON state may also contain the user's original infrastructure information, proposal content, and template path. This increases the sensitivity of the persisted file and creates unnecessary exposure to other local processes, users, backup systems, source-control operations, or later agent sessions that can read the project directory. A Feishu folder token may function primarily as a resource identifier rather than a complete authentication credential. Therefore, possession of the token alone i ...[truncated 1641 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The pause/resume trigger phrases are broad enough to match ordinary conversation, which can cause the skill to save, pause, or resume unexpectedly. In this skill, that can lead to unintended persistence of sensitive proposal content or loading the wrong saved proposal, especially because the content may involve government, state-owned enterprise, or security-planning information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the system to persist full proposal state to local JSON files without an explicit user warning or consent flow. Because proposals may contain internal planning, network/security details, budgets, and other sensitive enterprise information, silent local retention increases the risk of privacy leakage, accidental disclosure, and over-retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow directs the generated document to be uploaded to Feishu cloud storage but does not clearly warn users that potentially sensitive proposal data will leave local processing and be stored in a third-party cloud environment. Given the stated use cases include government, SOE, and cybersecurity planning documents, unannounced cloud upload materially raises confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document explicitly requires a specific language/style regime, including '政府公文风格' and banned expressions, which effectively forces output into a particular locale/register. Because the file does not indicate user opt-in or that this is a narrowly justified regional/compliance-only skill, it creates a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The state schema marks folder_token as optional at L064, but the documented workflow at L155 requires uploading the final document to a specified Feishu cloud folder. This is a documentation-level contradiction about whether that value is required for the promised completion path.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.