Back to skill

Security audit

M A3 Core Suite

Security checks for vulnerabilities and agentic risk

Overview

The skill looks purpose-aligned, but it needs review because its optional API is broadly exposed without authentication and its cross-agent data-sharing behavior is loosely scoped.

Review this skill before installing in any shared or production environment. If you use it, run the API only on localhost or behind authentication, avoid sending sensitive business, supplier, pricing, customer, or credential data until Agent World sharing is clearly scoped, and verify any optional API keys or external-service integrations before enabling them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
api_server.py:29
Finding

Unauthenticated API Exposed on All Network Interfaces with Permissive CORS

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
agents/chief_of_staff.py:255
Finding

Untrusted Task Content Embedded Directly into Downstream Agent Instructions

Content
View full analysis
str: """Generate Agent execution instructions""" return ( f"Call {agent.name} ({agent.role}) to perform the following task:\n" f"Task description: {task.description}\n" f"Brand involved: {task.brand or 'Not specified'}\n" f"Context: {json.dumps(task.context, ensure_ascii=False)}\n" f"Integrate the result and return it to the user when complete." ) ``` The source code uses Chinese instruction text, but the security-relevant construction is reproduced above in English: `task.description`, `task.brand`, and serialized `task.context` are inserted directly into the same instruction string as trusted orchestration commands. ### Technical Analysis The dispatcher combines trusted control instructions and untrusted user data in one natural-language message without structural separation or trust labels. An attacker can place instruction-like text in the task description, brand, or context fields. If the resulting `dispatch_instruction` is later submitted to an LLM-backed Agent, the downstream model may interpret the embedded content as orchestration instructions rather than as data. The current implementation only returns the generated instruction and does not itself call an LLM or execute tools. Consequently, direct exploitation does not occur entirely within the audited code. The weakness becomes exploitable when the documented dispatch workflow is completed and this string is forwarded to a specialist Agent. JSON serialization does not neutralize prompt injection because it only creates a textual representation; it does not establish a security boundary or prevent the model from following instructions contained i ...[truncated 1686 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

ChiefOfStaff uses very broad everyday trigger keywords such as “帮我”, “分析”, “查询”, “制定”, and “优化”, which are likely to appear in many unrelated user requests. In a multi-agent routing system, this can cause unintended invocation of the entry-point orchestrator, expanding the scope of tasks handled and increasing the chance of misrouting, over-collection of context, or unsafe downstream delegation.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'uvicorn' resembles popular package 'gunicorn'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises multiple POST endpoints and explicit cross-agent collaboration capabilities, but it provides no warning about data sharing, external side effects, privacy boundaries, or required operator consent. In a multi-agent operational system, this omission can cause users or integrating agents to send sensitive business data to components or workflows that may propagate it further, increasing the risk of unintended disclosure or actions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill describes operational behavior that includes reading local reference files, but it does not declare any explicit tool scope or permissions boundary. This creates a mismatch between documented capabilities and declared restrictions, which can lead hosts to invoke the skill without clear sandboxing expectations and increases the risk of unintended file access if the runtime grants broader read capabilities than users expect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest states that no environment variables are required, but later documentation says advanced features need API keys or environment variables. This inconsistency can cause insecure deployment decisions, surprise operators into enabling secrets post-installation, and bypass review processes that depend on the manifest for trust and risk assessment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several trigger phrases in the manifest are generic, such as terms related to multi-agent, operations, commerce, or collaboration, which may match ordinary conversation unrelated to this skill. Ambiguous triggers increase the probability of silent or unintended activation and can expose user inputs to broader orchestration logic than expected.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger condition is phrased broadly around commercial operations and multi-agent collaboration, making accidental invocation likely for many unrelated business queries. Over-broad activation increases the chance that user data is routed into workflows or external integrations the user did not intend to use, especially given the documented cross-agent and API-based behaviors.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents use of an external Agent World API for cross-agent collaboration but does not provide a clear warning that user data, task details, or outputs may be shared with external systems or other agents. In this context, hidden cross-agent transmission is more dangerous because the skill is designed for business operations, where prompts may contain sensitive commercial, supplier, pricing, or market information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s user-facing natural-language descriptions, role definitions, and workflow documentation are entirely in Chinese, indicating an implicit language requirement for understanding and use. Under the policy, locale or language constraints should not be forced unless the skill offers choice or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The class docstring states the workflow includes 'dispatch()' and 'integrate()', and the module header likewise says the component handles '结果整合'. In actual code, there are no dispatch or integration methods; execute() only runs receive/classify/route and returns a 'ready_to_dispatch' plan.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The execute() docstring explicitly says it integrates 'receive → classify → route → dispatch'. However, the method only creates a task, classifies it, selects an agent, and returns a dispatch instruction with status 'ready_to_dispatch', meaning dispatch is not performed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This codebase presents its API description and task field descriptions in Chinese and constrains certain inputs to Chinese-only market labels, but does not indicate that users may choose another language or locale. Under the natural-language policy rule, forcing a specific language or locale without opt-in is a policy concern unless clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The target_market field only accepts Chinese-language enumerations for markets, which imposes a locale/language constraint on all callers. The file does not explain that this is a region-specific tool or provide an alternative language choice, so this is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The default routing rule sends all unmatched requests to GEOStrategyAgent, even when there is no clear evidence the request is GEO-related. This creates a catch-all path that can process out-of-scope inputs, leading to confused-deputy behavior, inappropriate task execution, or accidental exposure of user context to an agent not intended for that request.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's natural-language strings, including the module docstring, comments, test inputs, and console output, are entirely in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file includes natural-language guidance that mandates specific languages for content, such as '英文为主' for North America. Because the policy category applies to all file types, fixed language requirements without an explicit user choice can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The line states '英语通用,附加德语/法语本地化,' which imposes a language approach rather than presenting it as an opt-in or user-selected preference. Under the stated policy, language constraints should either be optional or clearly justified as region-specific compliance requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The document says '中文/英文混合,视国家而定,' which is a fixed language directive and does not explicitly offer the user a choice of supported languages. This creates a potential language/locale policy issue because the recommendation is framed as mandatory guidance rather than opt-in localization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The line specifies '西班牙语(巴西为葡萄牙语)' as the language rule for the region. While market-specific, it is not framed as a documented user choice or justified compliance constraint, so it may violate the language/locale policy described in the audit rules.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The statement '英语通用,阿拉伯语辅助' prescribes a language hierarchy for content. Because the file does not indicate that users can choose the language or that the constraint is mandatory for compliance, this is a potential natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to natural-language policy issues in all file types. The user-facing documentation is fully Chinese and does not indicate that the skill is Chinese-only, region-specific, or that another language option is available, which can amount to forcing a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The package description is written entirely in Chinese, which can constitute a language-policy concern if the skill is presented to users without offering a language choice or documenting a locale-specific scope. There is no indication elsewhere in this file that the package is intended only for Chinese-speaking users or that alternative language support is available.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.