Back to skill

Security audit

Weekly Report Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill appears non-malicious, but it substantially overstates its current features and asks to install Pandoc for Word/PPT output that the code does not implement.

Review this skill before installing because the package may install Pandoc even though the current code does not use it, and the advertised monthly, Word/PPT, chart, and file-output features are not actually present. It looks like a simple Chinese weekly-report text generator rather than a harmful skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码的核心实现仅围绕“周报”展开:模板名为 WEEKLY_TEMPLATE,generate_report() 生成的是周工作报告,main() 只是从命令行读取输入并打印结果。没有任何月报模板、月度周期计算、总结类模板,也没有 python-docx、pptx 或文件导出逻辑。因此,声明的主要功能范围明显大于代码实际能力,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Manifest 描述在 L003 直接声明“支持 Word/PPT 格式输出”,但更新日志 L288-L296 显示 v1.0.0 仅支持 markdown,Word/PPT 输出属于 v1.1.0 的计划功能。基于该文件可见信息,技能对外宣称的能力超出了当前版本实际提供的范围。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill's natural-language description, instructions, examples, and templates are all written in Chinese, which effectively forces a specific language experience. Under SQP-3, a language or locale policy violation should be flagged when a skill imposes a language without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

v1.0.0 更新日志在 L291-L292 明确写明当前版本仅“支持 markdown 输出”,而 L003、L043-L046、L054-L058、L261、L266 以及 v1.1.0 计划项又把 Word/PPT 输出描述为已支持或即将新增。这不是单纯遗漏,而是同一文件内对当前能力状态的直接矛盾,容易误导用户对技能实际功能的理解。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code includes user-facing descriptions, template content, and CLI usage text only in Chinese, which effectively forces a specific language for users. The file does not provide any opt-in, fallback, or justification that this is a region-specific skill, so it matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says it can automatically generate weekly/monthly reports and work summaries with Word/PPT format output. In this file, the implementation only fills a hardcoded weekly report template and prints the resulting text to stdout; there is no logic for monthly reports, work summaries, or Word/PPT export.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file documents an --output path and states that the skill generates markdown/Word/PPT files, which implies file writes to the local filesystem. However, the description provides no user warning about creating or potentially overwriting files at the specified path, despite SQP-2 requiring disclosure for behaviors affecting user data or system integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.