Back to skill

Security audit

行业情报助手

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an industry-intelligence assistant, but its scheduling helper can execute user-controlled shell input and create persistent cron tasks, so it needs careful review before installation.

Review this skill before installing. Use it only in an isolated environment, avoid the scheduling script until shell execution is fixed, prefer TAVILY_API_KEY over passing keys on the command line, do not use --break-system-packages, and confirm all recipients before sending or scheduling reports.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/schedule_intel.py:29
Finding

Shell Command Injection in Cron Task Creation

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/intro.md:3
Finding

Unpinned Dependency Installation Bypasses System Package Protections

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/tavily_industry_search.py:65
Finding

API Keys Accepted Through Process-Visible Command-Line Arguments

Content
View full analysis
`. 2. The command, including the secret, may be retained in shell history or automation logs. 3. While the process is running, the argument may also be visible through process-inspection interfaces, subject to operating-system access controls. 4. Another local user, administrator, support operator, or log consumer retrieves the key. 5. The exposed key is reused to access the associated Tavily account or consume its service quota. ### Impact Assessment The exposure is limited to the Tavily credential provided to the command. An attacker who obtains it may issue API requests under the associated account, consume paid quota, access functionality authorized to that key, or cause service disruption through quota exhaustion. This ...[truncated 219 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较完整的行业情报助手,包含自动监控、热点抓取、结构化简报生成、多渠道推送和定时编排。实际代码只覆盖其中一部分:Tavily 搜索和结构化简报生成。它没有看到任何企业微信、飞书、钉钉相关接口调用,也没有定时任务、调度器、后台监控、数据库持久化或分发逻辑。因此,代码行为是声明功能的一个子集,且缺少声明中较关键的自动化与推送能力,属于描述与实际行为不完全一致。未发现额外的未声明高风险能力;问题主要在于声明明显超出了该代码片段实际实现范围。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

声明描述的是一个较完整的行业情报平台型技能,涵盖监控、分析、简报生成、分发和定时编排等多项能力。但提供的代码块只包含单一的 Tavily 搜索功能,没有看到任何定时执行、数据持久化、监控逻辑、结构化简报生成模板、或企业微信/飞书/钉钉推送代码。代码与声明中的“核心功能(1) Tavily搜索获取行业资讯”一致,但其余核心功能均未在该代码块中体现。因此,该描述相对于此代码块明显夸大了能力范围,构成描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The subprocess invocation grants the user indirect control over a powerful system tool through shell evaluation. Because this is an industry-intelligence assistant, shell-level scheduling is not inherently required for end users, so the mismatch between capability and business purpose makes abuse more dangerous and easier to overlook.

Content

Scanner excerpt · scripts/schedule_intel.py (reported line 44)May include surrounding context.

python
f'--enabled'
    )
    print(f"执行命令: {cmd}")
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    return result

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises shell execution, environment-variable use, and file-writing behavior through its documented commands, but it does not declare any explicit tool scope or permissions. This creates a least-privilege failure: operators and enforcement layers cannot clearly constrain what the skill may access, increasing the chance of unintended command execution, secret exposure, or filesystem modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes automated pushing of collected reports to enterprise messaging platforms and recurring scheduled delivery without clearly warning that content will leave the local workflow and may be sent unattended. This can lead to accidental disclosure of sensitive internal research, competitor tracking notes, or misrouted reports to external recipients or large internal groups.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The push instructions tell users how to deliver a report file to WeCom/Feishu/DingTalk but omit any warning that the entire file contents will be transmitted to configured enterprise recipients. In an intelligence-collection context, reports may contain proprietary summaries, sensitive URLs, or internal commentary, so silent delivery behavior materially raises data-leak risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scheduling instructions allow creation of recurring unattended push tasks but do not warn users that automation may repeatedly collect and distribute content without further review. In this skill context, that increases the risk of persistent misconfiguration, repeated sensitive-data disclosure, spam, or unnoticed distribution to the wrong audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The report is entirely framed in Chinese, including the title and section labels, with no indication that language choice is optional or limited to a China-specific use case. This creates a natural-language locale policy concern because the skill appears to enforce a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script exposes a --language zh|en option, but all user-facing descriptions, progress messages, section headers, and saved-report labels are hardcoded in Chinese. This creates a language/locale policy issue because users are not actually given a functioning language choice despite the apparent opt-in mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The payload message explicitly instructs the downstream agent to output results in Chinese. This is a natural-language locale constraint, and the file does not offer the user any language choice or explain why Chinese is mandatory.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The script builds a shell command by interpolating user-controlled values such as query, schedule, channel, and timezone into a single string, then executes it with shell=True. This enables command injection if an attacker supplies shell metacharacters or crafted quoting, and the scheduled-task context can persist the malicious payload for repeated execution.

Content

Scanner excerpt · scripts/schedule_intel.py (reported line 44)May include surrounding context.

python
f'--enabled'
    )
    print(f"执行命令: {cmd}")
    result = subprocess.run(cmd, shell=True, capture_output=True, text=True)
    return result

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This helper exposes a broader-than-necessary execution surface by dynamically constructing and executing shell commands for scheduling. In this skill's context, the danger is elevated because untrusted input is used to create persistent cron jobs, so a single injection can both execute immediately and install recurring malicious behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language strings such as the title, usage text, argument descriptions, and output labels are all Chinese-only. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless a locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The manifest description is entirely in Chinese and frames the skill's use cases in that language, which can amount to an implicit locale/language constraint. Although one script later exposes a zh|en parameter, the top-level natural-language description does not clearly state that users may choose their preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide instructs users to set a Tavily API key directly in configuration but does not state that the key is a sensitive secret or recommend secure handling practices. This can lead to accidental exposure through shell history, shared configs, screenshots, or commits, enabling unauthorized use of the API and possible data/account abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation encourages scheduled push delivery to WeCom/Feishu/DingTalk without warning that collected intelligence content may be transmitted to third-party messaging platforms. In an enterprise-intelligence context, this can cause unintentional external distribution of sensitive summaries, competitor tracking data, or proprietary analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This Python file performs an external API call with client.search(...), sending the supplied query to a third-party service. Although the script name implies search behavior, there is no explicit warning in code comments, docstrings, or runtime output that user-provided search terms are transmitted off-box to Tavily.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.