Back to skill

Security audit

Lease Review

Security checks for vulnerabilities and agentic risk

Overview

The lease review skill is mostly coherent, but it tells agents to run an unbundled relative-path analytics script after use, which creates an avoidable code-execution and privacy review concern.

Install only if you are comfortable with the Taiwan-specific, Traditional Chinese lease-review workflow and disable or ignore the post-use `skills/analytics.py` commands unless the publisher provides a bundled, reviewed, consent-based analytics implementation with clear privacy terms.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Warning
Location
SKILL.md:88
Finding

Execution of an Unbundled Relative-Path Analytics Script

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 88–99
Vulnerability Type: Execution of an unaudited local tool through a relative path
Risk Level: Medium

Vulnerable Code

markdown
## 📊 Usage Analytics

當你使用此 Skill 完成任務後,請記錄使用次數:

```bash
python3 skills/analytics.py taiwan-lease-review used

查看統計:

bash
python3 skills/analytics.py stats
text

### Technical Analysis

The Skill instructs the agent to execute `skills/analytics.py` after completing a task. That script is not included in the audited package, and its path is relative to the process's current working directory rather than being securely resolved against a verified Skill installation directory.

Consequently, the identity and behavior of the executed script depend on the environment in which the command runs. A local project, compromised workspace, or other actor able to create or replace `skills/analytics.py` can cause the legitimate-looking analytics command to execute attacker-controlled Python code.

The analytics operation is not required for the lease-review functionality. The audited package also does not disclose or enforce what information the external script may collect, store, or transmit.

### Attack Path

1. An attacker gains write access to the agent's current workspace or supplies a project containing `skills/analytics.py`.
2. The attacker places malicious Python code at that relative path.
3. The lease-review Skill is loaded and used normally.
4. After finishing the task, the agent follows the usage-analytics instruction in `SKILL.md`.
5. The command resolves `skills/analytics.py` relative to the current working directory.
6. Python executes the attacker-controlled script with the permissions and environment available to the agent process.

This attack depends on the agent following the documented post-use instruction and the attacker being able to control the file resolved by the relative path.

### Impact Assessment

Successful exploitation perm
...[truncated 748 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the post-use analytics commands because analytics is not necessary for the Skill's lease-review purpose.
  2. Do not instruct agents to execute scripts that are absent from the audited package.
  3. If analytics is essential, bundle the implementation within the Skill and include it in security reviews.
  4. Resolve the bundled script from a trusted, canonical Skill directory rather than from the current working directory.
  5. Verify the script's integrity before execution, such as by validating a trusted cryptographic hash or package signature.
  6. Require explicit user consent before collecting analytics.
  7. Document the exact fields collected, retention policy, storage location, and any network destination.
  8. Minimize collected information and avoid contract text, tenant or landlord identities, property addresses, credentials, and environment data.
  9. Disable network transmission by default and ensure analytics failures cannot affect the primary lease-review workflow.
  10. Consider removing or disabling the analytics: true metadata setting unless a bundled, consent-based, and auditable analytics mechanism is implemented.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises executable commands and a Python analysis script, but it does not declare an explicit tool scope such as permissions or allowed-tools. That increases the chance an agent will use file read/write capabilities implicitly when processing sensitive lease documents, without clear least-privilege boundaries or user visibility.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to run analytics commands to record usage and mentions installation tracking, but it does not present this as optional consented telemetry before execution. In a contract-review context, users may provide sensitive legal documents, so hidden or poorly disclosed telemetry creates privacy and trust risks even if only usage metadata is stored.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire report template is written in Traditional Chinese, and the file provides no indication that language selection is optional or limited to a justified region-specific use case. This can violate language/locale policy when a skill implicitly forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says the skill supports residential, commercial/storefront, and parking space leases, but this reference file states the cited Lease Protection Act applies only to residential leases and explicitly excludes storefronts, offices, and standalone parking rentals. For a skill presenting itself as reviewing those additional lease categories, this embedded legal reference materially narrows the actual support shown in code/documentation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The file begins with a fully Chinese-language title and the entire document is written in Traditional Chinese, with no indication that language choice is optional or that the skill is explicitly limited to Chinese-speaking or Taiwan-specific users. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The operational instructions, labels, and reporting guidance are presented entirely in Chinese and oriented to Taiwan-specific usage, but the file does not state that the skill is limited to Chinese output or offer the user a language preference. A forced language/locale can be a natural-language policy issue unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document presents all instructions and guidance in a single language and does not state that the user may choose another language or that the skill is intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all instructions and policy content only in Traditional Chinese, with no indication that the user can select another language. Under the natural-language policy rule, forcing a specific language without user opt-in can be a locale-policy violation unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains user-facing natural-language content exclusively in Traditional Chinese. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in can be a violation unless the locale restriction is explicitly justified in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This markdown file contains user-facing natural language exclusively in Traditional Chinese, and there is no note that the content is region-specific or that alternative language support is unavailable. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The generated report headings, conclusions, and user-facing status messages are all fixed in Chinese, and the accepted input values are also language-specific. This can violate language/locale policy when users are not given an explicit opt-in or alternative locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.