Back to skill

Security audit

企业AI落地诊断免费出报告

Security checks across malware telemetry and agentic risk

Overview

The skill coherently analyzes user-provided business materials and renders local reports, with disclosed report-generation steps and fixed consultation links but no hidden data sending or persistence found.

Before installing, confirm you are comfortable giving the agent access to the business documents you provide and with reports containing the fixed luodi.xixisys.com consultation links. Review generated outputs before sharing them externally, especially when they include customer, employee, pricing, contract, production, or other confidential data.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding
The skill instructs the agent to read files, write output files, and execute a shell command to render reports, but no permissions are declared. This creates a capability/authorization mismatch: a host may expose file and shell access implicitly, letting the skill perform side effects users and operators did not explicitly approve.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding
The skill claims to perform enterprise AI opportunity analysis, but the behavior described in the finding indicates it can skip substantive analysis, rely on local headless browsers, and always inject fixed external contact links into outputs. This is dangerous because it can mislead users about what was actually analyzed, exfiltrate business context into third-party contact workflows, and use local execution capabilities unrelated to the declared high-level purpose.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.