Back to skill

Security audit

崖州招商通

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly coherent for Chinese government investment-support work, but it requires saving every answer as a local Word file, which can persist sensitive business or policy material without a clear opt-in.

Review this skill before installing if you handle confidential company research or internal policy discussions. It should only be used where automatic .docx creation on the desktop or current working directory is acceptable, or where users can override that behavior and confirm export locations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a substantial招商/investment-analysis skill with domain-specific capabilities and external information retrieval. The actual code chunk does not implement any of those functions; it is a minimal placeholder script whose only behavior is printing a fixed example string. This is a material description-to-behavior mismatch because the primary purpose and capabilities described are absent from the code provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs automatic creation of .docx files on the user's desktop or working directory, which is a persistent side effect beyond simple analysis. Undisclosed file writes can leak sensitive investigative or policy content to shared devices, sync folders, or monitored directories, and they normalize writing local artifacts without explicit user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow imposes automatic local file creation without a clear warning or consent step, creating a hidden side effect. In this skill's context, reports may contain sensitive company assessments, investment strategy, or contact information, so silent persistence materially raises confidentiality and privacy risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The policy Q&A flow also mandates local .docx generation, creating persistent files even when the user may only want an answer in chat. This can expose internal policy interpretations or notes through filesystem artifacts and exceeds the least-surprise principle for a lookup-oriented skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Automatic .docx output in the policy workflow similarly creates undisclosed persistent artifacts. Even if the content is partly public policy, user-specific interpretation requests, internal notes, or case context may be captured in local files and later exposed through backups, desktop sharing, or endpoint monitoring.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The instructions require outputs in Chinese government-document format and specify Chinese fonts and presentation rules, but do not indicate that the language/locale is optional or user-selectable. This can violate language or locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

A global rule requiring every response to be saved locally broadens the skill's behavior into automatic persistent storage. If the skill processes company due diligence, policy analysis, or recruitment-related information, mandatory file creation increases the risk of inadvertent disclosure, retention, and compliance issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The global mandate to save every response compounds the risk because it turns all interactions into local data writes without prominent notice. In a government招商 context, this may create an untracked archive of sensitive business intelligence and decision-support materials on endpoints that are not designed for secure records handling.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document title and usage note are entirely in Chinese and present the FAQ as a general reference for招商工作人员, with no indication that language choice is optional or that the Chinese-only format is a justified locale constraint. Under the policy rule, a skill artifact that imposes a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains natural-language content exclusively in Chinese, and there is no note indicating that the skill or reference is intended only for Chinese-speaking users or a China-specific compliance context. Under the language/locale policy, forcing a specific language without user opt-in can be a policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.