Back to skill

Security audit

Vkey Bid Standardizer

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real Chinese banking bid-document formatter, but its install metadata creates an avoidable dependency-resolution risk.

Review the install path before using this skill. Prefer installing Python dependencies from a pinned requirements or lock file, and avoid letting an npm installer resolve the declared python-docx or pytest entries. Run it only on user-selected document copies or with --dry-run/--backup when handling sensitive bid material.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
package.json:35
Finding

Unpinned and Ecosystem-Mismatched Dependency Declarations

Content
View full analysis
=1.0.0" }, "devDependencies": { "pytest": ">=7.0.0" }, "engines": { "python": ">=3.7" } ``` The installation guidance in `SKILL.md`, lines 408-412, also installs Python dependencies without version pins or integrity verification: ```markdown **Install dependencies**: ```bash pip install python-docx pytest ``` ``` ### Technical Analysis The project declares `python-docx` and `pytest`, which are Python packages, inside the npm `dependencies` and `devDependencies` fields of `package.json`. An npm-based installer may therefore resolve packages with these names from the npm registry rather than installing the intended packages from the Python Package Index. Such same-name packages are distinct artifacts and may contain unrelated or hostile installation behavior. The version constraints use open-ended minimum ranges (`>=1.0.0` and `>=7.0.0`). The documented pip command is even less restrictive and does not verify package hashes. No dependency lockfile or hash-pinned requirements file was identified during the audit. Consequently, future or compromised releases can be selected without a corresponding source-code review. This does not prove that the currently resolved packages are malicious. It creates a supply-chain exposure in which package identity and version selection depend on the installer and mutable external registries. ### Attack Path 1. A user or plugin manager installs the project and processes `package.json` as an npm manifest. 2. The installer attempts to resolve npm packages named `python-docx` and `pytest`, rather than the intended Python packages. 3. An attacker publishes, compromises, or gains control of a matching npm package or a later release that satisfies the unrestricted constrain ...[truncated 1018 chars]
Remediation
View remediation
\ --hash=sha256: ``` Place `pytest` in a separate development requirements group and pin it in the same manner. 4. Generate and commit a lockfile using a controlled process such as `pip-tools`, Poetry, or uv. Review dependency updates before regenerating the lockfile. 5. Update `SKILL.md` so installation uses the locked dependency source rather than: ```bash pip install python-docx pytest ``` 6. Configure package managers to use approved registries and enforce integrity verification in CI and release workflows. 7. Add automated checks that reject Python dependency names in npm dependency sections and reject unpinned production dependencies. ]]>
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · vkey_bid_standardizer/patterns.py (reported line 92)May include surrounding context.

python
continue
        groups = list(m.groups())
        title = groups[-1].strip() if groups else text
        return rule, m, title
    return None, None, None

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents operational capabilities that imply reading and writing local files, but it does not declare any explicit tool scope, permissions boundary, or path restrictions. In an agent environment, this ambiguity can lead to overbroad file access, accidental modification of unrelated documents, or misuse of sensitive bid materials if the runtime grants default filesystem access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This Python file contains natural-language strings for usage, help text, and runtime messages entirely in Chinese, such as the module docstring and argparse help descriptions. Because the skill does not offer a language option or explain that it is intentionally limited to a Chinese-speaking/regional context, it appears to impose a specific locale without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The top-level docstring presents the pipeline modes and behavior entirely in Chinese, which indicates a fixed language/locale assumption in the skill's natural-language interface. There is no visible opt-in, language selection, or justification that this skill is intentionally limited to a Chinese-specific compliance or regional context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest-style header describes the skill entirely in Chinese and explicitly sets region: 中国大陆, which signals a fixed locale context. Under the stated policy, locale constraints should either provide user choice or be clearly justified as region-specific; here the banking/bidding context is region-specific, but there is no explicit opt-in or language-choice statement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module docstring and API documentation are written entirely in Chinese, which imposes a specific language on users without any stated opt-in or locale justification. Under the policy, language constraints should either offer user choice or be clearly documented as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The natural-language description is written entirely in Chinese and provides no indication that other languages are supported or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file’s natural-language documentation is written exclusively in Chinese, including the module overview and function docstrings/comments. Under the stated policy, forcing a specific language without user opt-in can be a locale/language policy violation, and this file does not indicate that the skill is region-specific or that alternate language support is available.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The module docstring and inline descriptions are written entirely in Chinese, which constitutes a language-specific constraint in the skill's natural-language content. There is no indication that users can opt into another language or that the locale restriction is documented as a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language value vkey-bid-standardizer 统一规范 embeds a Chinese-only locale assumption in the profile name. For a general skill asset, this can amount to a language/locale constraint without any visible opt-in or documentation that the profile is region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code file contains natural-language documentation in Chinese for the module purpose, and similar Chinese-only instructional text appears throughout comments and docstrings. Under the policy, forcing a specific language without user opt-in or a documented locale-specific reason can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.