Back to skill

Security audit

LegalBot法律助手

Security checks for vulnerabilities and agentic risk

Overview

This is a static Chinese legal helper with no execution behavior, but one rental-contract template contains realistic-looking personal and bank details that users could accidentally reuse.

Review this skill before installing if you may generate or share documents from it. Replace the hard-coded identity, phone, address, and bank-account details in the rental contract template with placeholders or your own verified information, and treat the legal guidance as PRC/Chinese-language reference material rather than professional legal advice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
templates/租房合同.md:6
Finding

Plaintext Sensitive Personal and Financial Data Embedded in a Distributed Template

Content
View full analysis

Vulnerability Details

File Location: templates/租房合同.md, lines 6, 8, 14, 30, and 110–114
Vulnerability Type: Plaintext exposure of sensitive identity, contact, residential, and financial data
Risk Level: Medium

Vulnerable Code Snippet

text
Line 6: Landlord: Wang Jianguo; national ID number: 440106198501011234; telephone: 13800138000.
Line 8: Tenant: Li Xiaohong; national ID number: 440105199203025678; telephone: 13900139000.
Line 14: Property address: Room 101, No. 18 Huacheng Avenue, Zhujiang New Town, Tianhe District, Guangzhou.
Line 30: Account holder: Wang Jianguo; bank account: 6222023602112345678.
Line 110: National ID numbers: 440106198501011234 and 440105199203025678.
Line 112: Telephone numbers: 13800138000 and 13900139000.
Line 114: Signature dates: March 28, 2026.

Technical Analysis

The rental agreement template is populated with realistic-looking names, national identification numbers, telephone numbers, a complete residential address, and a bank account number. These values are stored directly in plaintext and distributed as part of the Skill package.

Other project templates generally use placeholder fields, making the pre-populated values in this file unnecessary for functionality. The repository does not establish whether these values are genuine or synthetic. Nevertheless, distributing realistic sensitive values creates a privacy and data-handling risk because package recipients, source-code indexers, generated-document users, and automated processing systems can extract and reproduce them without access controls.

This is an insecure coding and content-management practice rather than a code-execution vulnerability. No authentication bypass, command execution, privilege escalation, persistence, or network exfiltration mechanism was identified.

Attack Path

  1. An attacker or unauthorized recipient obtains the Skill package or accesses a repository containing it.
  2. Th ...[truncated 1323 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace every pre-populated sensitive value with explicit placeholders, such as:
    • {{landlord_name}}
    • {{tenant_name}}
    • {{national_id}}
    • {{telephone_number}}
    • {{property_address}}
    • {{account_holder}}
    • {{bank_account_number}}
    • {{signature_date}}
  2. Use conspicuously invalid examples only when examples are essential. Do not use values that match production identity, telephone, or bank-account formats.
  3. Review repository history, release archives, caches, and published packages for earlier copies of the exposed values.
  4. If any values are genuine, notify the affected individuals and follow applicable incident-response and privacy-reporting procedures. Ask the relevant financial institution whether account monitoring or replacement is necessary.
  5. Add automated secret and personally identifiable information scanning to the release pipeline, including checks for national ID formats, telephone numbers, bank card numbers, full addresses, and account-holder combinations.
  6. Require a manual privacy review for legal-document templates before publication.
  7. Validate generated documents before export so unresolved placeholders or bundled example identities cannot be submitted accidentally.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The template embeds realistic-looking personally identifiable information and financial data, including full names, national ID numbers, phone numbers, a precise home address, and a bank account number. In a legal-document skill, users may copy, reuse, or mistake these as safe defaults, causing privacy exposure, accidental disclosure of third-party data, or propagation of sensitive data into generated contracts and downstream systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JSON file contains all titles, labels, suggestions, and contract type descriptors exclusively in Chinese, such as '高风险条款' and related guidance text. Because there is no accompanying indication that the skill is China-specific or that users can opt into this locale, it appears to impose a specific language/locale by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON contains user-facing natural-language values exclusively in Chinese, including category names and legal descriptions. Under the stated policy, forcing a specific language without opt-in or a clearly documented regional justification can be a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This JSON file uses Chinese-language titles and notes throughout, which may impose a specific language/locale on downstream users without any documented opt-in or alternative. Under the policy, forcing a specific language without user choice can be a natural-language policy violation unless the regional constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This JSON resource presents all user-facing content in Chinese and does not indicate that the skill is China-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This JSON file contains user-facing legal reference labels and values entirely in Chinese, which can constitute a language/locale policy issue when no opt-in or justification is provided. The rule for natural-language policy violations applies to all file types, including JSON manifests/data files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This JSON file contains all user-facing legal Q&A keys and answers only in Chinese, with no indication that users can select another language or that the locale restriction is intentional. That can violate a language/locale policy requiring user choice or explicit justification for a single-language experience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire template, including the title and all body text, is written exclusively in Chinese and does not indicate that the skill is intended only for Chinese-speaking users or China-specific workflows. Under the policy, language-specific content should either offer user choice or clearly justify the locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This template is entirely specified in Chinese and presents a fixed Chinese legal document format with no indication that users may choose another language or locale. Under the policy rule for language/locale constraints, this is a natural-language policy issue unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file contains user-facing natural language only in Chinese and does not indicate that the template is intended exclusively for Chinese-speaking users or offer an alternative language option. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.