Tp4
- Category
- MCP Tool Poisoning
- Confidence
- 96% confidence
- Finding
代码的核心实现仅围绕“周报”展开:模板名为 WEEKLY_TEMPLATE,generate_report() 生成的是周工作报告,main() 只是从命令行读取输入并打印结果。没有任何月报模板、月度周期计算、总结类模板,也没有 python-docx、pptx 或文件导出逻辑。因此,声明的主要功能范围明显大于代码实际能力,属于描述与行为不一致。
- Content
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears non-malicious, but it substantially overstates its current features and asks to install Pandoc for Word/PPT output that the code does not implement.
Review this skill before installing because the package may install Pandoc even though the current code does not use it, and the advertised monthly, Word/PPT, chart, and file-output features are not actually present. It looks like a simple Chinese weekly-report text generator rather than a harmful skill.
代码的核心实现仅围绕“周报”展开:模板名为 WEEKLY_TEMPLATE,generate_report() 生成的是周工作报告,main() 只是从命令行读取输入并打印结果。没有任何月报模板、月度周期计算、总结类模板,也没有 python-docx、pptx 或文件导出逻辑。因此,声明的主要功能范围明显大于代码实际能力,属于描述与行为不一致。
Manifest 描述在 L003 直接声明“支持 Word/PPT 格式输出”,但更新日志 L288-L296 显示 v1.0.0 仅支持 markdown,Word/PPT 输出属于 v1.1.0 的计划功能。基于该文件可见信息,技能对外宣称的能力超出了当前版本实际提供的范围。
The skill's natural-language description, instructions, examples, and templates are all written in Chinese, which effectively forces a specific language experience. Under SQP-3, a language or locale policy violation should be flagged when a skill imposes a language without user opt-in or clear justification.
v1.0.0 更新日志在 L291-L292 明确写明当前版本仅“支持 markdown 输出”,而 L003、L043-L046、L054-L058、L261、L266 以及 v1.1.0 计划项又把 Word/PPT 输出描述为已支持或即将新增。这不是单纯遗漏,而是同一文件内对当前能力状态的直接矛盾,容易误导用户对技能实际功能的理解。
This code includes user-facing descriptions, template content, and CLI usage text only in Chinese, which effectively forces a specific language for users. The file does not provide any opt-in, fallback, or justification that this is a region-specific skill, so it matches the language/locale policy violation category.
The skill description says it can automatically generate weekly/monthly reports and work summaries with Word/PPT format output. In this file, the implementation only fills a hardcoded weekly report template and prints the resulting text to stdout; there is no logic for monthly reports, work summaries, or Word/PPT export.
This markdown file documents an --output path and states that the skill generates markdown/Word/PPT files, which implies file writes to the local filesystem. However, the description provides no user warning about creating or potentially overwriting files at the specified path, despite SQP-2 requiring disclosure for behaviors affecting user data or system integrity.
No suspicious patterns detected.