Back to skill

Security audit

支出预警管控虾

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malicious, but it needs review because it advertises automatic budget controls and notifications while the included checker is limited and can produce unsafe financial recommendations.

Review before installing for production or approval workflows. Treat outputs as recommendations only, require human approval for yellow/red or missing-budget cases, validate input files independently, and avoid wiring it directly to Feishu notifications, budget updates, or automatic approvals until scope limits and fail-closed validation are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/budget-check.py:62
Finding

Invalid numeric values can bypass budget controls

Content
View full analysis
0 else 0 if new_usage_rate >= 100: status = 'red' action = '🔴 拦截,需升级审批' elif new_usage_rate >= threshold: status = 'yellow' action = '🟡 通知负责人,允许通过' else: status = 'green' action = '🟢 自动通过' ``` The affected values originate from unvalidated floating-point conversions: ```python float(args.amount) ``` ```python float(row.get('金额', 0)) ``` ### Technical Analysis The application converts user-controlled values with `float()` but does not verify that they are finite, positive, and within an acceptable range. Python accepts special values such as `nan`, `inf`, and `-inf`. If `amount` is `nan`, `new_usage_rate` also becomes `nan`. Comparisons involving `nan` are false, so both the red and yellow conditions fail and execution reaches the green branch. Negative expense amounts can similarly reduce the computed utilization rate. Budget totals also lack validation. When `total` is zero or negative, the conditional expression assigns a utilization rate of zero, causing the request to be treated as green unless a negative threshold was configured. This is fail-open behavior in a financial control decision. ### Attack Path 1. An attacker or untrusted data source supplies a request using `--amount nan`, or inserts `nan` into the amount column of a batch CSV. 2. `float()` accepts the value without raising an exception. 3. The utilization calculation produces `nan`. 4. Both `new_usage_rate >= 100` and `new_usage_rate >= threshold` evaluate to false. 5. The application returns a ...[truncated 801 chars]
Remediation
View remediation
0 else 0` fallback with explicit rejection. Invalid budget configuration must fail closed rather than result in green approval. 6. Return a dedicated validation-error status that downstream systems cannot interpret as approval. 7. Add automated tests for `nan`, positive and negative infinity, zero, negative amounts, negative budgets, extremely large values, and malformed numeric strings. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/budget-check.py:107
Finding

Batch expenses are evaluated independently and can collectively exceed the budget

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documented behavior claims real-time monitoring, anomaly detection, configurable rules, and notification/approval actions that are not actually implemented. This creates a dangerous trust gap: operators may rely on the skill for financial control decisions, assuming protections exist when the tool only performs limited manual checks and text recommendations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises capabilities that imply writing data or logs, but it does not declare an explicit tool scope such as permissions or allowed-tools. In an agent environment, undeclared write capability weakens least-privilege boundaries and can enable unintended file modification or persistence if the skill or referenced scripts are invoked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s natural-language description is written entirely in Chinese and does not indicate that other languages are supported or that Chinese is required for a region-specific compliance reason. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing natural-language documentation entirely in Chinese, including the module docstring and usage examples. Under the stated policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The argparse description and subcommand help strings are presented only in Chinese, which constrains the user experience to a single language. The file does not offer a locale option or explain that the skill is intentionally limited to a specific region or language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill file is written only in Chinese, including headings, rules, and operational descriptions, with no indication that users may choose another language or that the locale restriction is intentional. Under the stated policy, a skill that effectively requires a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire template library is written in Chinese and provides only Chinese-language notification content. This can violate a language/locale policy when a skill forces one language without user opt-in or documenting that it is intentionally region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.