Back to skill

Security audit

崖州区企业服务

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed enterprise-service reporting workflow with some privacy and activation caveats, but no hidden execution, exfiltration, persistence, or destructive behavior was found.

Before installing, confirm this skill should activate only for Yazhou District enterprise-service work. Generated Word reports may contain business and personal-identifying details, so store, share, and delete them according to your organization’s data-handling rules. Verify current policies and financial data from official or trusted sources before relying on recommendations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The description presents a comprehensive regional enterprise-service skill with several substantive capabilities: enterprise querying, targeted policy recommendation, safety-production supervision, local industry-based development advice, and multi-enterprise reporting. The supplied code only partially aligns with the enterprise query/policy-report aspects. Its main runtime behavior is to print suggested search queries and public query channels for a single enterprise, instructing the user to use external WebSearch/WebFetch tools manually. Although there are helper functions for report generation and simple policy matching, they operate on already-supplied enterprise_info data and are generic rather than Yazhou-specific. There is no implementation for safety supervision, no local industrial-development analysis, no real data retrieval, and no simultaneous multi-enterprise support. Therefore the declared description materially overstates and misrepresents the implemented behavior.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README advertises Word report generation for one or more enterprises but does not warn users that enterprise information may be compiled into a file artifact. This creates a risk of unanticipated persistence, sharing, or mishandling of potentially sensitive business information, especially when batch reports are produced for multiple entities.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list contains broad terms like '企业服务', '企业查询', and '发展建议' that are likely to match ordinary business conversations and cause the skill to activate unexpectedly. In a skill that can query enterprise data and generate reports, overbroad activation increases the chance of unintended data access, confusing tool invocation, or silent file generation in contexts where the user did not explicitly request this skill.

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest uses very broad trigger phrases covering generic enterprise, policy, safety, and development topics, which can cause the skill to activate in situations outside its narrow intended context. Over-broad activation increases the chance that the agent routes unrelated user requests into this skill, causing inappropriate tool use, irrelevant data retrieval, or unverified policy/safety guidance presented with undue authority.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The usage criteria are ambiguous about when this skill should handle requests versus when general policy, industry, or advisory questions should be answered normally. This ambiguity can lead to over-selection of the skill for broad public-policy or industry questions, resulting in unnecessary data collection, misleading official-style outputs, or unsupported compliance/safety recommendations.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document explicitly instructs staff to collect detailed enterprise and personal data, including a legal representative's identity-related information and business metrics, but provides no guidance on data minimization, lawful basis, consent, storage, retention, access control, or secure transmission. In an enterprise-service skill that may generate reports for multiple companies, this increases the likelihood of over-collection, unauthorized disclosure, and privacy/compliance violations.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The file title and all instructional content are written entirely in Chinese, including the guidance for how to provide enterprise development advice. There is no indication that the skill is region-specific by design or that users may choose another language, which can violate a language/locale policy requiring opt-in or explicit justification.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The file’s docstring and all user-facing guidance are written exclusively in Chinese, and the script does not provide any opt-in or alternative language handling. This can violate language/locale policy when a skill forces a specific language for all users without explicit justification.

Natural-Language Policy Violations

Low
Confidence
71% confidence
Finding
The natural-language description presents the skill entirely in Chinese and targets a specific local administrative context, but it does not explicitly offer a language choice or state that Chinese is optional. This can be interpreted as forcing a specific language/locale without user opt-in under the stated policy rule.

Missing User Warnings

Low
Confidence
76% confidence
Finding
The README states that listed-company financial data can be queried via a dependent skill, but it does not warn users that requests may be sent to an external data source or that query contents may be transmitted outside the current skill. For markdown files, externally sourced or potentially privacy-relevant behavior should be disclosed when it may affect user expectations.

Natural-Language Policy Violations

Low
Confidence
77% confidence
Finding
The skill description and all user-facing examples are fixed in Chinese and scoped to a Chinese local-government workflow, but the file does not state that the language is optional or selected based on user preference. Under the policy, forcing a specific language without opt-in can be a natural-language locale constraint issue.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
This markdown file presents all headings, descriptions, and notices exclusively in Chinese, but does not state that the skill or content is intended only for Chinese-speaking users or a China-specific locale. Under the language/locale policy rule, forcing a single language without user opt-in or explicit justification can be a natural-language policy violation.

Natural-Language Policy Violations

Low
Confidence
91% confidence
Finding
The file’s natural-language content is exclusively Chinese from title to end, and there is no indication that users may choose another language or that the document is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation.

Static analysis

No suspicious patterns detected.