Back to skill

Security audit

Rental Management

Security checks for vulnerabilities and agentic risk

Overview

This Taiwan rental-management skill is mostly coherent, but its tenant-screening guidance raises privacy and fairness risks around sensitive documents, ID photos, monitoring, and nationality-based scrutiny.

Review this skill carefully before installing or following it. Treat the tenant-screening checklist as high-risk: verify applicable Taiwan privacy, rental, credit-reporting, and anti-discrimination requirements; avoid nationality-based screening; collect only necessary documents; prefer visual verification over retaining ID copies or ID photos; secure any records; and define deletion timelines for rejected applicants and expired tenancies.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
references/tenant-screening.md:38
Finding

Excessive Collection and Unsafe Retention of Sensitive Tenant Data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is described as an operational rental-management SOP, but it also exposes a Python ROI calculation workflow that reads an input file and writes an output file. This mismatch is dangerous because users and orchestration systems may trust the declared purpose while overlooking code-like behaviors that expand the skill's effective access and data-handling surface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Flagging 'foreigners' as a yellow-light category for extra scrutiny applies nationality-based screening criteria without a stated legal or objective necessity. In a tenant-screening context, this is especially dangerous because it can directly enable discriminatory rental practices, unequal documentation burdens, and potential legal liability for users who follow the SOP.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises executable scripts and declares a runtime requirement (python3), but it does not define any explicit tool or permission boundaries despite implying file input/output operations. In an agent environment, missing scope declarations can cause the skill to run with broader filesystem access than users expect, increasing the risk of unintended reads or writes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Most operational guidance, tables, and instructions are written in Traditional Chinese, effectively forcing a specific language for use of the skill. Although the subject matter is Taiwan-specific, the file does not explicitly state that the language choice is intentional or offer users an alternative language option.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the user to run an analytics script and notes that installation usage is automatically recorded, but it does not disclose what telemetry is collected, where it is sent, or whether any identifiers are included. Hidden or opaque analytics in an agent skill can lead to unintended disclosure of usage metadata or environment information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains natural-language guidance only in Chinese, which can amount to a language/locale constraint without user opt-in. Under the policy rule, forcing a specific language is a violation unless the locale limitation is explicitly documented and justified or the user is given a choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document title and all operational guidance are written exclusively in Traditional Chinese, indicating a fixed language/locale for the skill content. The file does not offer any language choice, fallback, or note that the content is region-specific, which can violate a language/locale policy requiring user opt-in or explicit justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document describes collecting highly sensitive personal and financial data for screening without any warning about privacy obligations, secure handling, retention limits, or legal basis. That omission is dangerous because operational users may interpret the checklist as permission to collect and store extensive applicant dossiers in insecure or excessive ways.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The SOP instructs landlords to collect multiple sensitive identity and financial documents, including ID copies, income records, credit reports, guarantor identity documents, and landlord references, without any minimization, retention, consent, or legal-compliance guidance. In a general rental-management skill, this creates unnecessary privacy and misuse risk because users may over-collect or indefinitely retain personal data beyond what is proportionate for screening.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance endorses monitoring-like practices and identity-photo retention without warning users about consent, proportionality, or privacy law implications. In practice, this could lead landlords or agents to create unnecessary surveillance records and invasive monitoring routines that expose tenants to privacy harms and identity-theft risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The SOP recommends tactics such as frequent inspections, leveraging neighbors as informal monitors, and taking a tenant photo with their ID, but provides no privacy, consent, necessity, or legal-boundary safeguards. This can normalize surveillance-like behavior and identity-record retention that exceeds reasonable property management needs and may facilitate harassment, data misuse, or unlawful monitoring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file contains multiple user-facing comments, report text, verdicts, and console messages in Chinese, and the generated report is entirely localized to that language. Because the script does not provide user opt-in, a language selection mechanism, or a documented region-specific justification, this is a natural-language locale policy violation under the stated rules.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest description lists broad conditions such as 'Managing a rental property' and 'Planning property maintenance schedules,' which are expansive everyday tasks rather than narrowly scoped invocation cues. The file does not provide exclusion conditions or negative examples to clarify when this skill should not be used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.