Back to skill

Security audit

麦肯锡百年知识库

Security checks for vulnerabilities and agentic risk

Overview

This is a Chinese McKinsey-style knowledge-base skill, but it documents use of local IMA credentials with an unaudited absolute-path Node helper, so credential and network behavior needs review before installation.

Install only if you are comfortable with a Chinese-first consulting reference skill that may query an external IMA knowledge base. Do not run the documented IMA commands with real credentials unless you have verified the helper script, understand what data is sent, and can keep the API key out of shell history, logs, and process listings.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:220
Finding

API Credentials Exposed to an Unbundled External Client Through Command-Line Arguments

Content
View full analysis
", "query": "search term", "cursor": ""}' \ '{"clientId":"","apiKey":""}' # Browse knowledge-base content node /Users/wdj/.workbuddy/skills/skill_2053082144792322048/ima_api.cjs \ "openapi/wiki/v1/get_knowledge_list" \ '{"knowledge_base_id": "", "cursor": "", "limit": 50}' \ '{"clientId":"","apiKey":""}' ``` ### Technical Analysis The instructions direct the user or Agent to obtain a client identifier and API key from local configuration files and then place those credentials directly into a process argument. On operating systems where process command lines are visible through process-monitoring interfaces, the credentials may be exposed to other local users, monitoring agents, diagnostic utilities, shell history, terminal capture, or automation logs. Passing secrets in an argument also increases the chance that orchestration or error-reporting systems will retain them. The invoked JavaScript client is referenced through the absolute path: ```text /Users/wdj/.workbuddy/skills/skill_2053082144792322048/ima_api.cjs ``` That file is outside the audited project and was not available for inspection. Consequently, the audit cannot verify its network destination, request handling, logging behavior, or treatment of the supplied credentials. The absolute path also creates a local trust boundary: if an attacker can replace or modify that file, the attacker-controlled program will receive the API ...[truncated 1811 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation rules include broad business and strategy terms such as 管理咨询、战略规划、商业分析, which can cause the skill to trigger in contexts where the user did not intend to use this knowledge base. Over-broad activation increases the chance of unintended context injection, irrelevant guidance, or accidental access to connected knowledge resources during unrelated conversations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation instructs use of local credential files (~/.config/ima/client_id and ~/.config/ima/api_key) and demonstrates authenticated API calls to an external knowledge base, but does not warn about secret handling, least-privilege access, redaction, or user consent for outbound queries. In an agent setting, this pattern can lead to unauthorized credential use, unintended exfiltration of user prompts or local data to third-party services, and accidental disclosure of sensitive identifiers in logs or transcripts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file consists exclusively of Chinese-language instructions and examples, which effectively imposes a specific language on users. Under the policy criteria, a forced language/locale without user opt-in or documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown template is written as a Chinese-language reporting format, including the title and all section prompts, with no indication that users may choose another language. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is in scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

文件整体描述、触发条件和使用指南均默认以中文呈现和操作,且未说明是否支持按用户语言偏好切换。对于通用知识检索类技能,若默认固定单一语言而无用户选择,可能构成语言/locale 选择上的自然语言政策问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructional content exclusively in Chinese and does not provide user opt-in, alternative language guidance, or a documented justification for a Chinese-only constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown skill content is fully presented in Chinese and does not state that the language is optional, user-selected, or justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file is entirely authored in Chinese and does not indicate that the user can choose another language or locale. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructions and content exclusively in Chinese, with no indication that users may select another language or that the locale restriction is intentional. Under the policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.