Back to skill

Security audit

鲸采云SRM

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real procurement-system integration, but it asks for raw passwords, stores usable access tokens locally, persists remote tool metadata, and can change financial/business records.

Review before installing in any production SRM environment. Use a limited test account first, verify the Yidea API host, avoid pasting real passwords into chat or command lines, protect or remove config/config.json after use, and require explicit review of every create, update, delete, order, contract, receiving, deduction, or payment action.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (6)

T01 · Skill Instruction Hijacking

Error
Location
references/workflow.md:3
Finding

Skill instructions attempt to override host-level agent behavior

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
references/auth.md:18
Finding

Unvalidated remote tool definitions are written to persistent agent memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/yidea-provision.js:30
Finding

Bearer token is persisted in a plaintext tracked configuration path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/yidea-provision.js:91
Finding

Plaintext password is accepted through process command-line arguments

Content
View full analysis
{ console.log(JSON.stringify(r)); }) .catch(e => { process.exit(1); }); ``` ### Technical Analysis The command-line interface receives the username and plaintext password from `process.argv`. Command-line arguments are commonly visible through process inspection tools and may also be retained in shell history, automation logs, telemetry, crash reports, or orchestration metadata. Unlike protected stdin or a secret store, process arguments are not designed to carry authentication secrets. The exposure occurs before the credential reaches the intended HTTPS login endpoint. ### Attack Path 1. The agent or user invokes the provisioning script with the username and password as arguments. 2. The operating system exposes the complete process command line while the process runs. 3. A local user, monitoring agent, or diagnostic tool records or reads the command line. 4. Alternatively, the shell stores the invocation in command history. 5. The attacker recovers the Yidea username and password. 6. The attacker authenticates independently and obtains a fresh access token. ### Impact Assessment This exposes reusable account credentials rather than only a temporary bearer token. An attacker can repeatedly authenticate until the password is changed and may obtain the full Yidea privileges assigned to the user. The compromise can therefore affect all SRM records and operations accessible to that account. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/yidea-provision.js:9
Finding

Configuration-controlled endpoint can receive raw user credentials without origin validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/yidea-provision.js:91
Finding

Documented authentication module cannot be safely imported

Content
View full analysis
{ console.log(JSON.stringify(r)); }) .catch(e => { process.exit(1); }); ``` No corresponding export is present: ```javascript // Missing: // module.exports = { provision }; ``` ### Technical Analysis Node.js executes a module's top-level code when it is loaded with `require`. Because the CLI entry point is not guarded by `if (require.main === module)`, importing this file runs the argument check and may terminate the hosting process. In addition, `provision` is not exported, so destructuring it from the module returns `undefined`. The documented “atomic” authentication flow therefore cannot operate as described. This reliability defect has a security consequence because operators are likely to bypass the documented module flow and invoke the CLI instead, exposing passwords through process arguments. Unexpected `process.exit` behavior can also terminate an agent or gateway process and cause denial of service. ### Attack Path 1. The agent follows `references/auth.md` and imports `yidea-provision.js`. 2. The module executes its top-level CLI code. 3. If the host process does not contain the expected arguments, `process.exit(1)` terminates the process. 4. If suitable unrelated arguments exist, the module may attempt authentication with unintended values. 5. Even if execution continues, the imported object does not contain `provisio ...[truncated 477 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (31)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 32)May include surrounding context.

text
.nuxt

# dotenv environment variable files
.env
.env.local
.env.*.local

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 62)May include surrounding context.

text
.nuxt

# dotenv environment variable files
.env
.env.local
.env.*.local

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 33)May include surrounding context.

text
# dotenv environment variable files
.env
.env.local
.env.*.local

# npm cache directory

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description frames the skill as business/form processing, but the behavior includes credentialed remote authentication, local token/config storage, MCP connectivity testing, and tool enumeration. This mismatch hides security-relevant capabilities from reviewers and users, making risky behavior easier to invoke without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger keywords are extremely broad business terms like '采购', '合同', '申请', and '管理', which can match ordinary conversation and unintentionally activate a write-capable procurement skill. Because the skill can drive sensitive actions such as vendor, contract, pricing, and payment operations, accidental invocation materially raises the chance of unintended data access or modification.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to collect the user's raw username and password in chat on every use, which creates a direct credential-harvesting path and unnecessary exposure of secrets to the agent, logs, and any downstream integrations. Requiring this for routine SRM actions is especially dangerous because the same credentials likely unlock sensitive supplier, contract, and payment workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill tells the agent to request a username and password directly but provides no safe-handling warning, no minimization guidance, and no secure collection mechanism. This normalizes unsafe secret sharing in chat and increases the likelihood of credential leakage via transcripts, telemetry, or reuse across systems.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Mandating that the agent solicit and accept system credentials in plain conversation is a direct secret-handling anti-pattern. In this skill, the danger is amplified by the surrounding procurement and payment capabilities, because compromised credentials could enable unauthorized access to supplier data, contracts, orders, and financial workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README describes very broad natural-language invocation patterns such as '帮我发起采购申请' and '查询一下待办' without clear scoping or confirmation boundaries. In an agent environment, this raises the chance of accidental activation from ordinary conversation, which is especially risky because the skill can perform business actions like procurement, contract, and payment workflows.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The install command uses npx clawhub@latest, which fetches and executes the latest published package at runtime instead of a pinned, reviewed version. That creates a supply-chain risk: if the package or one of its dependencies is compromised, users installing the skill could execute attacker-controlled code on their machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that after login the system saves config/config.json to the workspace and stores values including tenantId, token, and baseUrl, but it does not clearly warn users that authentication data will be written locally. This can expose reusable credentials or session tokens to other local users, backups, logs, or accidental source control commits.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The functionality list advertises create, update, delete, ordering, contract, receipt, and payment capabilities without prominent warnings about their destructive or financially binding nature. In this procurement context, accidental or socially engineered use could create unauthorized orders, alter supplier data, delete records, or trigger payment-related actions with real business impact.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill exposes network and environment-backed operational capability but does not declare any explicit tool scope or allowed-tools boundary. That makes the effective authority of the skill less transparent and increases the risk of overbroad execution or misuse when handling procurement operations and credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description and trigger design are written to operate in Chinese and the skill appears to assume Chinese-language usage, but it does not explicitly offer a language option or state that the skill is intentionally limited to Chinese-speaking users for a documented reason. This can constitute a language/locale policy issue under the natural-language policy rules.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Conversational examples such as '帮我买', '替我买', or '看看我有什么待办' are broad enough to be triggered during casual discussion, increasing the risk that the skill activates without the user realizing it. In a procurement context, even read-only activation can expose sensitive business data, and write-capable flows amplify the risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill supports create, update, and delete operations for procurement records without requiring clear risk disclosures or explicit confirmation for potentially irreversible business changes. In SRM/procurement systems, accidental or rushed mutations can impact supplier onboarding, pricing, orders, receiving, and payments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The documentation directs the agent to run local Node/PowerShell-style commands as part of normal operation, expanding the skill from business logic into local command execution. Even if intended for integration, this increases attack surface by enabling filesystem interaction, script execution, and potential command misuse beyond the procurement use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The entire skill is written to operate only in Chinese and does not offer the user any language or locale choice. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern unless the regional constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples "帮我买" and "替我买" are overly broad natural-language triggers that can match casual conversation and cause the agent to enter a procurement workflow unexpectedly. In a skill that can initiate business actions and collect or submit form data, ambiguous activation increases the risk of unintended purchases, workflow launches, or disclosure of procurement-related schemas and records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs storing server-returned tool definitions into session context and persistent memory without any minimization, TTL, or user notice. Persisting authentication-derived capability metadata can unnecessarily broaden later tool access, leak internal schemas across turns, and create downstream abuse if memory is exposed or reused in unrelated conversations.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The login response is authentication-derived, and the guidance says to persist returned tool definitions into memory for future use. Even if the tools array does not contain the token itself, retaining auth-scoped capability data beyond immediate need can enable privilege confusion, unintended reuse across tasks, and additional exposure if session memory is inspected, serialized, or shared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file’s instructions and examples require responses to be presented in Chinese, including fixed Chinese phrasing for successful operations shown to customers. This is a natural-language locale policy constraint, but the document does not mention any user preference, opt-in, or justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The entire protocol is written as mandatory operational guidance in Chinese and does not offer any language choice or state that the skill is region-specific. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The protocol requires the agent to automatically query related records as soon as it detects a query_ field, without any user confirmation or visibility into what data source will be accessed. In an SRM/procurement context, those related tables may contain supplier, pricing, contract, or workflow data, so automatic lookup can disclose metadata or records the user did not explicitly request and may bypass expected consent or least-privilege interaction patterns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction hard-codes a Chinese user-facing fallback message: 未找到匹配的关联记录,请检查数据或联系管理员. This enforces a specific language for end-user communication without indicating that the skill is region-specific or that users can choose their preferred language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.