Back to skill

Security audit

feasibility-review

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent feasibility-review workflow, with a caution that its optional exporter can write a local review.json file to a caller-selected directory.

Use this skill when you intend an agent to read uploaded feasibility-review documents, perform PatSnap/MCP and web policy searches, and generate a local HTML report. Keep MCP credentials scoped to this work, and only run scripts/export_json.py with an output directory you control because it can overwrite review.json there.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs the agent to read uploaded files, write a Python script into the session filesystem, persist progress files, and generate an HTML report, but it declares no explicit tool scope or allowed-tools boundary. This creates an avoidable over-privilege condition: if the runtime grants broader file or environment access than intended, the skill can read, write, and potentially expose sensitive local/session data beyond the minimum required for feasibility review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition includes broad wording such as requests for '立项审查、可研审查、开题审查等相关任务', which lacks clear boundaries on when the skill should activate. Overbroad activation can cause the skill to run in unintended contexts, leading to unnecessary file access, external searches, and generation of derived reports on documents the user did not intend to process with this high-capability workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill that parses uploaded documents, performs formal/substantive review, and generates a structured review report to assist decision-making. This script's documented purpose is to write data directly into a website's data/review.json, which is a deployment/publication side effect rather than the review-generation behavior described in the manifest.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script accepts an arbitrary filesystem path from --output-dir or REVIEW_OUTPUT_DIR and writes review.json there without validation. In an agent or automated pipeline context, an attacker who can influence arguments or environment variables could cause writes to unintended locations, leading to file clobbering, overwriting application data, or persistence in writable directories.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.