Back to skill

Security audit

Connector Workflow-Composer

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed connector-workflow planning skill with broad but purpose-aligned connector discovery and automation guidance, guarded by explicit confirmation requirements for write actions.

Before installing, expect the skill to scan the connector marketplace when first used and to help build automations that may read business data or send messages. Confirm destinations, recipients, schedules, and write actions carefully, and only add trusted, desensitized reference examples if you customize it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly mandates a connector-market scan on first load and before any task, which creates an overbroad automatic action unrelated to the user’s immediate request. In a skill that can enumerate a large external connector ecosystem, this increases the chance of unnecessary capability discovery, privacy-sensitive metadata exposure, and unintended tool invocation without clear user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad terms such as '连接器', '工作流', and '自动化流程', which are common in ordinary conversations. Overbroad invocation increases the chance the skill activates unintentionally and performs its mandatory first-run marketplace scan, causing unnecessary tool use, privacy exposure, or confusing context takeover.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares Bash in allowed-tools even though the documented behavior is connector discovery, workflow composition, and template-driven output. Unnecessary shell access expands the attack surface: adversarial prompts or poisoned reference content could steer the agent into local command execution, file aggregation, or unintended data access beyond what this skill needs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document says the skill content must not be modified, but also permits users to add reference files and register them in the exemplar index. That contradiction can weaken trust boundaries: an attacker may use the 'user fill' path to inject unreviewed instructions into references that the skill later loads into context and treats as authoritative guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The template requires user-facing copy to be bilingual ('中英成对') without indicating that this should be conditional on the user's language preference. This is not a classic security flaw, but it is a real policy/UX safety issue because it can cause unnecessary disclosure, confusion, or prompt-injection surface expansion when content is duplicated into a second language the user did not request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The validation rule enforces bilingual output at delivery time regardless of user preference, which can systematically override least-surprise and least-disclosure principles. In a workflow-composition skill, forced duplication of operational content may also increase the chance of mistranslation or inconsistent safety-critical instructions across languages.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The retrieval intent “浏览全部连接器” is specified as a generic action without precise activation boundaries, making it easy for the skill to invoke broad discovery based on ambiguous conversational cues. In this skill’s context, that ambiguity is more dangerous because the whole design centers on scanning, classifying, and composing connectors, so vague triggers can escalate into unnecessary system-wide enumeration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example workflow directs daily sales data to an enterprise WeChat customer group, which is an outbound sharing action involving potentially sensitive business information. Even though this is only a template, presenting the action without any warning, audience validation, or data-minimization guidance can normalize unsafe distribution and lead users to expose internal revenue or customer-related data to an overly broad audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The mapping table marks the enterprise WeChat group messaging step as a write operation but does not pair it with a user-facing caution about outbound or bulk messaging. In a workflow-composition skill, omission of this warning is risky because it can encourage users to automate broad message distribution without verifying recipient scope, message content sensitivity, or approval requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "销售日报" is broad and overlaps with common user language, which can cause unintended invocation of this reusable skill in ordinary conversation. In this skill’s context, accidental triggering is more dangerous because the workflow composer can progress into connector orchestration and potentially propose or execute write-capable automation paths, increasing the chance of unintended actions or user confusion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file’s operational instructions and task descriptions are entirely in Chinese, and there is no indication that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill reference and user instructions are written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-language audience. Under the policy, a language-specific constraint should either be optional for the user or explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The requirements repeatedly mandate Chinese or bilingual output formats without presenting user language preference as an input or routing factor. This can cause unsafe misunderstanding of connector capabilities, authorization prompts, and write-action confirmations when the user is not comfortable in Chinese, weakening informed consent and increasing operational error risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

该模板全文以中文固定呈现,且未见任何允许用户选择语言/地区的说明,也未说明这是仅面向特定中文环境的受限模板。按规则,强制特定语言而无用户选择或明确、合理的区域限定,属于自然语言层面的语言/locale 策略违规。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The top-level description does not clearly warn that first use triggers a full connector marketplace scan. Because the skill is user-invocable and has broad triggers, this missing disclosure can surprise users and cause unexpected enumeration of available integrations before they understand the behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.