Back to skill

Security audit

合规哨兵监控虾

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be an incomplete compliance-monitoring assistant that asks users to rely on persistent third-party risk monitoring without enough scoping or working implementation.

Review before installing. Do not treat this as a working compliance monitor unless you add real data-source queries, tested Feishu integration, scheduling, alerting, and report generation. If used, limit API keys and Feishu tokens, define who receives alerts, confirm partner-list storage with data owners, and document retention and deletion controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill clearly describes capabilities that require network access and likely environment-backed credentials or configuration, but it does not declare any tool scope or permissions boundaries. This creates a least-privilege and transparency gap: an agent may be allowed broader access than users expect, increasing the chance of unintended outbound requests or misuse of secrets during monitoring workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill stores partner compliance records in Feishu Bitable and sends alerts, but it does not explicitly warn users that potentially sensitive third-party business, legal, or adverse-record data will be persisted and transmitted. This can lead to unauthorized retention, over-sharing in notifications, or regulatory/privacy compliance issues, especially where supplier/customer data is sensitive or access-controlled.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The batch import flow asks users to provide supplier/customer lists and then writes them into persistent storage for ongoing monitoring, but it does not explicitly disclose this persistence and continuous processing. Users may upload partner lists without understanding they will become part of a long-lived monitored dataset, creating consent, confidentiality, and data governance risks.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains user-facing natural-language instructions, help text, and descriptions exclusively in Chinese, including the module docstring and usage guidance. Under the policy rule, forcing a specific language without offering the user a language or locale choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata and script behavior materially overstate capabilities such as 7×24 monitoring, batch risk scanning, scoring, and alerts, while the implementation mostly provides placeholders, manual import, and guidance text. In a compliance-monitoring context, this mismatch is especially risky because organizations may assume regulatory or due-diligence controls are operating when they are not, causing missed litigation, sanctions, or credit-risk events.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The report command claims to generate a monitoring report and accepts an output path, but it only prints a blank template and never uses actual monitoring data or writes a file. This can mislead operators into relying on incomplete or fabricated reporting for compliance, audit, or vendor-risk decisions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The monitor command is presented as a continuous monitoring capability with Feishu integration, but it only prints instructions and performs no monitoring, scheduling, data access, or alerting. In a compliance workflow, this can create a dangerous false sense of protection where users believe third-party risks are being watched 24×7 when no checks are actually occurring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The argparse description, subcommand help, and argument help strings are all user-facing text in Chinese only. Because the script does not offer an English or configurable locale option, it imposes a single language on users without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Natural-language policy issues include forcing a specific language without user opt-in. This skill's description, examples, and usage guidance are all Chinese-only, and there is no indication that users may interact in another language or that the skill is intentionally limited to a Chinese-language environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document title and all instructional content are written exclusively in Chinese, with no indication that other languages are supported or that Chinese is a region-specific requirement. Under the policy for natural-language violations, forcing a specific language without user opt-in should be flagged.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains user-facing notification templates exclusively in Chinese, with no opt-in, fallback, or documented locale constraint. Under the policy rule, forcing a specific language without user choice can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing operational content exclusively in Chinese, but it does not state that the skill is intended only for Chinese-speaking users or a China-specific workflow. Under the language/locale policy, forcing a specific language without user opt-in or documented justification can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.