Back to skill

Security audit

Chexian Baodan Tong

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says overall, but its default ZIP packaging can include unrelated files and API mode can send a bearer key to any configured endpoint without validation.

Install only if you will run it on a dedicated folder containing just the insurance PDFs you intend to rename and package. Prefer local mode, use --no-pack or inspect the archive before sharing it, and avoid --api unless you trust the configured endpoint and understand that your API key and file metadata will be sent there.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/extract_and_rename.py:263
Finding

Recursive ZIP Packaging Collects Unrelated Files

Content
View full analysis
Remediation
View remediation
str: zip_path = os.path.abspath(os.path.join(folder, zip_name)) root = os.path.abspath(folder) with zipfile.ZipFile(zip_path, "w", zipfile.ZIP_DEFLATED) as zf: for file_path in approved_files: file_path = os.path.abspath(file_path) if os.path.commonpath([root, file_path]) != root: raise ValueError("File is outside the approved folder") if os.path.isfile(file_path) and file_path.lower().endswith(".pdf"): zf.write(file_path, os.path.relpath(file_path, root)) return zip_path ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/extract_and_rename.py:143
Finding

API Key Can Be Transmitted to an Arbitrary or Plaintext Endpoint

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:117
Finding

Dependency Installation Is Not Version or Hash Pinned

Content
View full analysis
Remediation
View remediation
--hash=sha256: ``` Install it with: ```bash python -m pip install --require-hashes -r requirements.txt ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tainted flow: 'req' from os.environ.get (line 170, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
95% confidence
Finding

The API endpoint is taken directly from the INSURANCE_API_ENDPOINT environment variable and used for an outbound request without validation, while API mode is intended to process sensitive insurance PDFs. In this context, a malicious or misconfigured endpoint can exfiltrate policy metadata or full document contents to an attacker-controlled server, which is especially risky because the skill handles personal and insurance data.

Content

Scanner excerpt · scripts/extract_and_rename.py (reported line 180)May include surrounding context.

python
method="POST"
    )
    try:
        with urllib.request.urlopen(req, timeout=60) as resp:
            result = json.loads(resp.read().decode("utf-8"))
        content = result["choices"][0]["message"]["content"]
        # 尝试解析 JSON

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented purpose understates several security-relevant behaviors: API mode can transmit policy document contents to an external service, the ZIP step can include all files in the target folder rather than only processed PDFs, and renaming can expose policy numbers when plate numbers are unavailable. In an insurance-document workflow, these undisclosed behaviors materially increase the risk of sensitive data exfiltration and over-collection of unrelated files containing personal or regulated information.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares no explicit tool scope even though its documented behavior includes reading environment variables, reading and writing local files, creating archives, and optionally making network requests. Missing permission scoping increases the chance that users or host systems will not understand the full capability set, weakening least-privilege controls and making misuse or overreach harder to detect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The API-mode description does not clearly warn that insurance policy data will be sent to an external AI endpoint for processing. Because policy PDFs commonly contain PII and potentially regulated insurance data, insufficient disclosure can cause users to upload sensitive documents to third parties without informed consent or appropriate compliance review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The docstring and manifest describe an API mode that parses insurance-policy PDFs via an external AI service, and the code even reads and base64-encodes the PDF. But the constructed request never includes the encoded file bytes, only a text prompt and the basename, so the implemented behavior does not match the claimed PDF-upload parsing behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

API mode is designed to send insurance-document data to an external AI service, but the CLI does not provide a strong user-facing privacy warning or explicit consent checkpoint. Because insurance policies commonly contain personal, vehicle, and policy identifiers, undisclosed external transmission materially increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The code is configured to communicate with an external API endpoint, which creates a real data-exposure surface in a tool that handles sensitive insurance records. External transmission is not automatically malicious, but in this skill context it is security-relevant because it may send regulated personal or policy data off the local machine.

Content

Scanner excerpt · scripts/extract_and_rename.py (reported line 138)May include surrounding context.

python
api_key = os.environ.get("INSURANCE_API_KEY", "")
    endpoint = os.environ.get(
        "INSURANCE_API_ENDPOINT",
        "https://api.openai.com/v1/chat/completions"
    )
    model = os.environ.get("INSURANCE_API_MODEL", "gpt-4o")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The ZIP routine walks the entire target folder and archives every file it finds, not only the processed insurance PDFs. In a folder that contains unrelated sensitive files, this can unintentionally bundle and redistribute extra documents, increasing exposure of private or regulated data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language description, prompts, CLI help, and extracted field names are all presented only in Chinese, implying a fixed language/locale experience. The file does not offer user opt-in for language selection or document that the tool is intentionally limited to a Chinese-language or region-specific workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The code performs in-place file renaming with os.rename, which changes user files on disk. While each rename is printed after it happens, the command-line description and argument help do not clearly warn users that renaming is enabled by default and will modify filenames unless --no-rename is used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.