Back to skill

Security audit

Real Estate Debt Analysis

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it presents generated estimates as real real-estate market and auction data for financial decisions.

Install only if you treat the output as a rough demo or heuristic model, not as verified market or auction data. Do not rely on its prices, coverage ratios, or investment recommendations without independent source checks, and avoid submitting confidential property or debt records until logging, privacy disclosure, and real data provenance are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/real_estate_analysis.py:21
Finding

Synthetic randomized estimates are presented as platform-derived market and auction data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/real_estate_analysis.py:936
Finding

Property addresses and debt information are logged without redaction

Content
View full analysis
0 and cleaned_info['area'] > 0 ): processed_data.append(cleaned_info) else: print(f"跳过无效数据:{property_info}") ``` Other parsing branches use the same unsafe pattern: ```python except (ValueError, IndexError): print(f"跳过无效行:{row}") ``` ```python except (ValueError, KeyError): print(f"跳过无效项:{item}") ``` ```python except (ValueError, IndexError): print(f"跳过无效行:{line}") ``` ### Technical Analysis The Skill accepts records containing exact property addresses, debt principal amounts, and property areas. When validation or conversion fails, several parsing branches interpolate the complete attacker- or user-controlled record into standard output. In Agent runtimes, containers, serverless platforms, and orchestration systems, standard output is commonly collected by centralized logging infrastructure. Those logs may be visible to operators, support personnel, other tenants, monitoring integrations, or anyone with log-reader permissions. Their retention period may also exceed the lifetime of the original analysis request. The vulnerability is triggered specifically by malformed records, meaning a record can contain valid sensitive fields while deliberately causing another field to fail numeric conversion. Printing the complete row then exposes all fields rather than only the validation rea ...[truncated 1399 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill description materially misrepresents behavior: it claims live price comparison, external search, and report generation, while the implementation reportedly relies on local defaults/random estimation and returns a fabricated localhost report URL. This is dangerous because users may make financial decisions based on false provenance and fabricated outputs, and the hidden expansion to broad input-handling paths increases the attack surface beyond what the declared purpose suggests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module documentation states that the script calls web-search and report-generator skills, but the implementation does not do so and instead returns placeholder or local values. This creates deceptive system behavior and weakens operator trust, especially where downstream users may assume externally validated search and reporting occurred when it did not.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill claims to compare real Anjuke intermediary prices and Alibaba auction transaction prices, but it instead generates synthetic values from hardcoded tables and random fluctuations. In a financial decision-support context, fabricated market data can materially mislead investment or debt-recovery decisions, causing users to rely on outputs presented as factual when they are not.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares execution via a script and documents environment-variable use, file-based configuration, and network-dependent data collection, but it does not declare any explicit tool scope such as allowed tools or permissions. That weakens least-privilege controls and can let the runtime grant broader file, environment, or network access than users expect, which is risky given the skill processes potentially sensitive debt and property data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill states that it uses network search, external data processing, and report generation, but it does not clearly warn users that supplied property and debt information may be sent to external services or written to output files. This is particularly sensitive in the real-estate debt context because addresses, debt principal, and related asset details can be confidential financial information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The context trigger terms are very broad and include common real-estate vocabulary, making accidental activation likely in unrelated conversations. In a skill that may read files, process extracted content, or contact external services, overbroad triggering can cause unintentional handling or disclosure of user data without sufficiently clear intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The collaboration triggers for files, images, audio, and multimodal inputs use everyday phrases like 'help me analyze this file/image,' which can match many benign requests. Because the skill is designed to extract structured debt and property data from multiple media types, these broad phrases raise the chance of unintended ingestion of sensitive content and unexpected cross-skill activation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The module description, comments, messages, and outputs are all in Chinese, and the parsing logic is tailored to Chinese field names and labels. There is no indication that users can opt into another language or that the Chinese-only behavior is a documented, justified locale constraint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest presents a specialized analysis skill focused on comparing two real-estate pricing sources. The main docstring and parsing logic expand the skill into a general multi-format, multimodal document ingestion pipeline, which is broader than the stated purpose and adds substantial capability beyond the core comparison task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill processes sensitive property addresses, debt principal amounts, and potentially extracted content from files, images, audio, and multimodal inputs without any visible privacy notice, consent flow, minimization policy, or retention disclosure. In a debt-analysis context, this data can be highly sensitive and may expose individuals or portfolios if logged, reused, or transmitted without clear controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.