Back to skill

Security audit

Master Data Matching

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated data-matching purpose, but it deserves review because it handles sensitive business and HR records while documenting broad triggers and optional HITL-bypass behavior, and its active-learning code has a real unsafe dynamic-key bug.

Install only if you will keep this skill inside a controlled matching workflow, require explicit human approval before creating or updating master records, and fix or isolate the active-learning dynamic-key handling before processing untrusted OCR fields or review payloads. Be especially cautious with HR, finance, tax, bank, and employee identifier data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:604
Finding

Prototype Pollution Through Attacker-Controlled Active-Learning Keys

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
import mdm from './index.js';

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
import mdm from './index.js';

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad business phrases such as 'finance matching', 'HR matching', and 'human in the loop', which can cause the skill to activate in contexts far beyond entity resolution. In a production agent, unintended invocation can route sensitive finance or HR data into this skill, increasing the chance of inappropriate processing, privacy exposure, or incorrect workflow automation.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · assets/matching-config.json (reported line 39)May include surrounding context.

json
}
  },
  "hitl": {
    "autoConfirmThreshold": 0.98,
    "autoRejectThreshold": 0.3,
    "requireHumanReviewBelow": 0.92,
    "reviewActions": [

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The architecture explicitly supports auto-apply behavior via 'Auto-apply (if skipHitl)' alongside create/update actions that can modify master data records. In a master-data matching system spanning procurement, finance, sales, and HR, silent updates or record creation without an explicit user warning and strong approval controls can cause unauthorized data changes, incorrect entity linkage, and downstream business process corruption.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The example hard-codes locale-specific values such as a China-format phone number and a Beijing address, which nudges the skill toward a specific regional context without documenting that the skill is region-specific or offering locale flexibility. Under the stated policy, locale constraints should be explicitly justified or made optional.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.