Back to skill

Security audit

发票查验(invoice-verify) - 慧穗云

Security checks for vulnerabilities and agentic risk

Overview

This invoice-checking skill appears legitimate, but it can send invoice and credential data to any API URL configured in the environment, so it needs careful review before use.

Install only if you trust HuiSuiYun and the publisher, and ensure HSY_API_URL is unset or fixed to the intended HTTPS HuiSuiYun host. Treat HSY_AK and HSY_SK as sensitive credentials, avoid running this in environments where untrusted users can change environment variables, and expect invoice numbers, dates, amounts, check codes, and possible tax identifiers to be sent to the remote service.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
invoice-verify-hsy.py:14
Finding

Unrestricted API Endpoint Allows Credential and Invoice Data Exfiltration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Tainted flow: 'check_url' from os.getenv (line 72, credential/environment) → requests.post (network output)

Critical
Category
Data Flow
Confidence
94% confidence
Finding

The destination URL is derived from the HSY_API_URL environment variable and then used for requests that include invoice contents and authentication headers, including the access token. If an attacker can influence the environment or deployment configuration, they can redirect traffic to an attacker-controlled endpoint and exfiltrate sensitive invoice data and tokens. In a skill context, this is more dangerous because the tool is explicitly designed to send sensitive tax/invoice information to a remote service.

Content

Scanner excerpt · invoice-verify-hsy.py (reported line 75)May include surrounding context.

python
check_url = f"{api_url}/api/v2/agent/cdk/invoice/check"

    try:
        response = requests.post(check_url, json=data, headers=headers)
        return response.json()
    except Exception as e:
        return {"error": str(e)}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares runtime requirements indicating access to environment variables and outbound networking, but it does not declare an explicit tool scope such as permissions or allowed-tools. This creates a transparency and least-privilege problem: an agent or user may invoke a skill that can access secrets and send data externally without clear policy constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs sending invoice details and taxpayer-identifying information to a third-party API, but it does not clearly warn users that sensitive business and tax data will leave the local environment. This can lead to unintended disclosure of regulated or confidential data, especially because the sample response includes seller and purchaser names, tax numbers, and invoice line items.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
invoiceList 数组中每个对象的字段:

| 字段名          | 类型       | 必填 | 说明                                                                                                  |
|-----------------|------------|------|-------------------------------------------------------------------------------------------------------|
| invoiceNo       | String     | 是   | 发票号码,如:00517731                                                                                |
| drewDate        | String     | 是   | 开票日期,格式:YYYY-MM-DD,如:2021-06-22                                                            |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
| 字段名          | 类型       | 必填 | 说明                                                                                                  |
|-----------------|------------|------|-------------------------------------------------------------------------------------------------------|
| invoiceNo       | String     | 是   | 发票号码,如:00517731                                                                                |
| drewDate        | String     | 是   | 开票日期,格式:YYYY-MM-DD,如:2021-06-22                                                            |
| invoiceCode     | String     | 否   | 发票代码,如:3300201130(全电发票无需传入)                                                          |
| invoiceType     | String     | 否   | 发票类型:01-增值税专用发票,08-增值税专用发票(电子),04-增值税普通发票,10-增值税普通发票(电子),09-数电发票(增值税专用发票),90-数电发票(普通发票)等 |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
| amount          | BigDecimal | 否   | 金额:专票(01、08、85)传入不含税金额,数电发票(09、90、51、61)传入价税合计                        |
| checkCode       | String     | 否   | 校验码后六位,普票(04、10、11、14、86)必传                                                          |
| originFileFlag  | Integer    | 否   | 是否获取版式文件:1-是,0-否                                                                          |
| exten1-10       | String     | 否   | 扩展字段1-10                                                                                          |

### 返回结果示例(verify)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Multiple docstrings and user-visible messages are written only in Chinese, including configuration and error guidance. This can enforce a specific language experience without user opt-in or any alternative locale handling.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · invoice-verify-hsy.py (reported line 27)May include surrounding context.

python
}

    try:
        response = requests.post(token_url, json=payload)
        result = response.json()
        if result.get("code") == "200":
            return result["data"]

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · invoice-verify-hsy.py (reported line 75)May include surrounding context.

python
check_url = f"{api_url}/api/v2/agent/cdk/invoice/check"

    try:
        response = requests.post(check_url, json=data, headers=headers)
        return response.json()
    except Exception as e:
        return {"error": str(e)}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The code sends the provided invoice payload to a remote API via an HTTP POST request, which can transmit user or business data off-host. Although there are internal comments, there is no confirmation prompt, user-facing log/print, or docstring warning that invoice data will be sent to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Nearly all user-facing instructions and descriptions in this skill are presented only in Chinese, which effectively forces a specific language for operation and comprehension. The file does not offer an alternative language, user opt-in, or a documented justification that the skill is intended only for a Chinese-language or region-specific audience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The skill accesses HSY_AK and HSY_SK from environment variables to authenticate with the external service. While missing configuration is reported to the user, there is no warning or documentation in this file that the skill consumes sensitive credentials from the environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.