Back to skill

Security audit

link-skills

Security checks for vulnerabilities and agentic risk

Overview

This development skill is coherent for its stated Link CRM+AI purpose, but it includes live-looking internal secrets and unsafe operational guidance that users should review before installing.

Do not install this skill into a broadly shared agent environment until the publisher removes and rotates the exposed Nexus credentials and AES key, replaces internal endpoints with placeholders or access-controlled docs, pins or secures dependency and image sources, and adds explicit local-only and approval requirements for signature bypasses, database changes, and Kubernetes/Apollo operations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
references/troubleshooting.md:44
Finding

Hard-Coded Private Nexus Repository Credentials

Content
View full analysis
link-nexus linkcrm hand123654 ``` ### Technical Analysis The troubleshooting guide embeds a Nexus username and password directly in a Maven configuration example. The surrounding instructions direct users to place this configuration into `settings.xml`, making the exposed values operationally reusable rather than merely descriptive. Secrets stored in Skill packages are accessible to anyone who can read the package, its distribution archive, source-control history, or generated audit artifacts. Maven server credentials may be sent automatically whenever Maven connects to a repository whose server identifier is `link-nexus`. ### Attack Path 1. An attacker obtains read access to the Skill package or repository. 2. The attacker extracts the username and password from `references/troubleshooting.md`. 3. The attacker authenticates to the internal Nexus service if it is network-accessible. 4. Depending on the account permissions, the attacker downloads proprietary artifacts or enumerates repository contents. 5. If the account has publication privileges, the attacker uploads or replaces artifacts. 6. Developers subsequently retrieve the modified artifacts during Maven builds, potentially propagating malicious code into application packages and container images. ### Impact Assessment The immediate scope is the Nexus account represented by the exposed credentials. Potential consequences include unauthorized access to proprietary dependencies, disclosure of internal package metadata, credential reuse attacks, and supply-chain compromise. If the account has write or deployment privileges, an attacker could tamper with private dependencies and affect every application tha ...[truncated 93 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/troubleshooting.md:54
Finding

Private Maven Dependencies Retrieved Through an Unencrypted HTTP Repository

Content
View full analysis
link-repo link-nexus http://nexus.saas.hand-china.com/repository/link-maven-repository-proxy/ ``` The same plaintext repository endpoint is also listed in the architecture guide: ```text http://nexus.saas.hand-china.com/repository/link-maven-repository-proxy/ ``` ### Technical Analysis The documented Maven repository uses HTTP rather than HTTPS. Maven builds executed with this configuration can retrieve dependencies and repository metadata without transport confidentiality or server authentication. A network-positioned attacker could observe repository traffic, intercept credentials, alter metadata, or replace dependency and plugin responses. Maven plugins and annotation processors may execute code during a build, while ordinary modified dependencies can become part of the resulting application artifact. The Skill explicitly recommends running Maven builds and creating Docker images from the results, increasing the potential propagation scope. ### Attack Path 1. A developer or agent installs the documented Maven configuration. 2. Maven connects to the repository over plaintext HTTP. 3. An attacker with control of a network segment, proxy, DNS response, or routing path intercepts the request. 4. The attacker captures credentials or returns modified Maven metadata, dependencies, or plugins. 5. Maven processes the attacker-controlled content during compilation, testing, packaging, or plugin execution. 6. The compromised artifact is copied into a Docker image. 7. The image is deployed to the Link environment, allowing the injected code to run with the application's runtime identity and ac ...[truncated 586 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/testing-guide.md:73
Finding

Development Guidance Disables Request-Signature Validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/testing-guide.md:300
Finding

Local MySQL and Redis Examples Expose Weakly Protected Services

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (30)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
加载 `references/coding-standards.md` 获取完整规范。关键红线:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

md
加载 `references/coding-standards.md` 获取完整规范。关键红线:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
加载 `references/coding-standards.md` 获取完整规范。关键红线:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 320)May include surrounding context.

md
加载 `references/coding-standards.md` 获取完整规范。关键红线:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

md
加载 `references/troubleshooting.md` 获取已知问题和解决方案。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 325)May include surrounding context.

md
加载 `references/troubleshooting.md` 获取已知问题和解决方案。

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · assets/templates/MapperMySql.xml (reported line 2)May include surrounding context.

text
<?xml version="1.0" encoding="UTF-8"?>
<!-- MyBatis XML 模板 — 使用时替换以下占位符:
  {Name}   → 类名(PascalCase,如 KbDocument)
  {name}   → 变量名(camelCase,如 kbDocument)
  {module} → 模块名(如 aiAssistant)
  {domain} → 业务域名(如 knowledge)
  {table}  → 表名(如 LNK_KB_DOCUMENT)
  字段部分请根据实际表结构调整
-->
<!DOCTYPE mapper PUBLIC "-//mybatis.org//DTD Mapper 3.0//EN"
    "http://mybatis.org/dtd/mybatis-3-mapper.dtd">
<mapper namespace="com.link.{module}.{domain}.{name}.dao.mybatis.mapper.{Name}Mapper">

    <!-- 结果映射 -->
    <result

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Disclosing a hard-coded AES key in markdown is a direct secret exposure, not merely an informational issue. If this key protects database passwords or related credentials, anyone with access to the document can decrypt protected values and compromise backend systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation instructs users to disable signature verification (sign-check: false) for local development without emphasizing the security consequences or strict scope limitations. This weakens an inbound request authenticity control and can normalize bypassing security checks, increasing the chance the setting is copied into shared or deployed environments.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 35)May include surrounding context.

  1. 配置 settings.xml:
xml
<!-- 路径: link-ai/settings.xml -->
<settings>
  <mirrors>
    <mirror>

Missing User Warnings

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The file contains what appears to be a live Maven repository username and password embedded directly in documentation. Hard-coded credentials in a skill/reference file can be copied, committed, indexed, or exfiltrated, enabling unauthorized access to internal artifact repositories and possible supply-chain compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide tells users to disable signature verification without any warning about the security consequences or guardrails limiting the change to an isolated local environment. That normalizes bypassing request-authentication protections and increases the chance the insecure setting is propagated into shared development, test, or production deployments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides concrete deployment, Helm, Kubernetes, Apollo configuration, and operational guidance that could lead an agent or user to perform production-impacting actions without any explicit safety gating, confirmation requirement, or environment check. In the context of a deployment/ops skill for a real enterprise microservice system, omission of warnings and approval boundaries materially increases the risk of accidental outages, misconfiguration, or unauthorized changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs database validation and related operations without warning about production data sensitivity, write risks, or the need to avoid destructive SQL. Because this skill is tailored to a specific live CRM+AI environment, even 'validation' guidance can normalize direct database interaction that may expose or alter sensitive business data if followed incautiously.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document explicitly recommends a service pattern that forwards requests to a third-party API and notes that authentication tokens are injected automatically, but it provides no accompanying guidance to warn developers about external data transfer, consent, data classification, or logging/sanitization requirements. In this skill context, the omission is more dangerous because this file is a coding standard reference that may normalize sending potentially sensitive CRM or knowledge-base data off-platform without privacy review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The coding standard includes example integrations for non-streaming and streaming AI chat requests to an external service, but it omits warnings that user prompts, identifiers, and generated content may be shared with a third party. In the context of a CRM+AI microservice skill, that omission can lead developers to transmit customer, employee, or internal business data to an external AI provider without notice, minimization, or policy controls.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide exposes internal infrastructure details including hostnames, ports, database names, and an AES key used for password handling. Even in documentation, publishing real-looking secrets and network topology materially helps an attacker with reconnaissance and may enable direct decryption or lateral movement if the key is in use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document states that the knowledge-base module proxies requests directly to a third-party API and shows automatic token injection and HTTP POST behavior. The section does not include any user-facing warning that request parameters may be transmitted to an external service, which is a privacy and system-integrity relevant behavior under the markdown criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/testing-guide.md (reported line 26)May include surrounding context.

md
### 策略一:接口冒烟测试(推荐)

使用 curl 命令逐个测试接口。参考 `knowledge-api-curl.md` 中的 18 个端点完整 curl 命令。

### 策略二:批量冒烟脚本

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/testing-guide.md (reported line 67)May include surrounding context.

md
-d '{"username":"admin","password":"xxx"}' | jq -r '.result.token')

# 2. 带 Token 访问
curl -X POST http://{service-host}:8888/link/aiAssistant/kbDocument/queryByExamplePage \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $TOKEN" \
  -d '{"page": 1, "pageSize": 10}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide provides create, update, and delete API test examples without prominently warning that they mutate live state. In a CRM/AI microservice context, operators may run these against shared dev, test, or even production-like environments, causing unintended data creation, corruption, or deletion.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This troubleshooting guide goes beyond diagnostics and exposes sensitive internal operational details, including internal repository endpoints, cluster/service topology, gateway paths, and credentialed build configuration. In the context of a development/deployment skill for a real microservice system, these details materially lower the barrier for unauthorized access, reconnaissance, and misuse.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 76)May include surrounding context.

方案一:通过网关访问(网关处理签名)

bash
curl -X POST http://{gateway}:8888/linkcrm/ai/aiAssistant/kbDocument/queryByExamplePage \
  -H "Content-Type: application/json" \
  -d '{"page":1,"pageSize":10}'

Static analysis

No suspicious patterns detected.