Back to skill

Security audit

cgma-finance / 世界一流财务管理体系建设专家

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent finance-document generation skill, with disclosed local file creation and PDF validation side effects users should understand before use.

Install only if you want a skill that can generate local finance-report files and validate presentations with browser automation. Confirm the output directory first, especially because the SKILL.md names a /Users/wdj/WorkBuddy/{session_id} path, and avoid providing confidential company data unless you are comfortable with it being written into generated deliverables.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states that mentioning relevant keywords in conversation will automatically trigger the skill, but it does not define clear boundaries for when activation should occur. In a chat environment, broad auto-triggering can cause unintended invocation on incidental mentions, leading to unexpected generation of files or finance outputs without explicit user intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The triggering instructions tell users to directly describe their needs for automatic activation, again without precise constraints or disambiguation rules. This increases the chance that normal discussion about finance restructuring or CGMA could unintentionally activate the skill and initiate multi-file output behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list is extremely broad and overlaps with ordinary finance requests, which can cause unintended skill activation. In a skill that writes files and invokes extra tooling, accidental invocation materially increases the chance of unexpected actions being taken on behalf of the user.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction that users can activate the skill by 'simply describing your needs' creates an ambiguous activation boundary. This makes it easier for normal conversation to unintentionally trigger a multi-step workflow with filesystem writes and auxiliary tool usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs automatic creation of multiple files in a specific local filesystem path without clearly warning the user or obtaining explicit consent. Unprompted local writes are dangerous because they create side effects outside the chat boundary, can overwrite or scatter files, and become more risky when combined with broad activation conditions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow instructs the agent to use Playwright to generate and validate PDFs, which expands the skill from document generation into browser automation. Browser automation can load active HTML, invoke additional tooling, and increase attack surface, especially when the generated content may incorporate user-controlled material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README advertises automatic generation of multiple deliverable files, but it does not clearly warn users at that point that files will be created in the working directory. In agent environments, silent or poorly disclosed file creation can surprise users, clutter workspaces, or overwrite expectations about what the skill is permitted to do.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill embeds the author's personal email address and phone number directly in the documentation, creating unnecessary exposure of personal contact data. Even if not directly exploitable for system compromise, this increases privacy, spam, social-engineering, and impersonation risk without being needed for the skill's core finance-deliverable function.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.