Back to skill

Security audit

industry-chain-intelligence

Security checks for vulnerabilities and agentic risk

Overview

The skill is a business report generator, but its reviewed artifacts can produce authoritative-looking reports from static or unverified data and include several under-scoped safety issues.

Review this skill carefully before installing. It does not show malicious OS-level behavior, but you should treat generated reports as templates unless MCP calls and source binding are verified, avoid opening reports generated from untrusted company/chain inputs, and do not rely on person-level targeting or government-mode profiling without policy review.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_report.py:1136
Finding

Stored HTML and JavaScript Injection Through Unescaped Report Parameters

Content
View full analysis
str: brand = f"{ctx['company']} 产业链战略报告 · {ctx['report_id']}" pages = [ build_p1(ctx), build_p2(ctx, brand), build_p3(ctx, brand), build_p4(ctx, brand), build_p5(ctx, brand), build_p6(ctx, brand), build_p7(ctx, brand), build_p8(ctx, brand), build_p9(ctx, brand), build_p10(ctx, brand), ] html = f""" {ctx['company']} 产业链战略报告 · {ctx['report_id']} {WHITEPAPER_CSS} {''.join(pages)}
""" if output_path: Path(output_path).parent.mkdir(parents=True, exist_ok=True) with open(output_path, "w", encoding="utf-8") as f: f.write(html) ``` The affected values originate from command-line arguments: ```python parser = argparse.ArgumentParser(description="企业决策者产业链战略报告系统 v2.0") parser.add_argument("--company", required=True, help="目标企业名称") parser.add_argument("--chain", default="", help="产业链名称(可选)") ``` Additional unescaped interpolation occurs in page construction: ```python
{ctx["company"]}
产业链战略研判报告
{ctx["company"].upper()} · {ctx["chain"].upper()} INDUSTRY CHAIN STRATEGY REPORT
``` ### Technical Analysis The `--company` and `--chain` command-line values are copied into the rendering context and interpolated directly into generated HTML. No context-sensitive HTML escaping, sanitization, or safe templating mechanism is applied. ...[truncated 1773 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/report_template.html:7
Finding

Remote JavaScript Dependency Loaded Without Integrity Verification

Content
View full analysis
``` ### Technical Analysis The report template loads and executes ECharts directly from a third-party CDN whenever the document is opened with network access. Although the package version is specified, the script has no Subresource Integrity hash and is not shipped as a reviewed local artifact. Consequently, the code executed by the report is not fully represented by the audited project. A compromise of the CDN, package publication process, referenced artifact, or delivery path could cause modified JavaScript to run without changing this repository. ### Attack Path 1. The CDN account, package artifact, upstream release process, or delivery infrastructure is compromised. 2. The resource returned for the referenced script URL is replaced or modified. 3. A user opens `references/report_template.html` while network access is available. 4. The browser retrieves the remote script. 5. Because no integrity metadata is present, the browser accepts and executes the modified resource. 6. The malicious script runs with the browser privileges and origin context of the report. ### Impact Assessment A compromised remote dependency can execute arbitrary JavaScript in every report session that loads it. It can alter report data, capture information available to the page, create deceptive user interfaces, issue network requests, and retrieve additional payloads. The issue does not by itself grant native operating-system privileges, but it compromises the confidentiality and integrity of the browser-rendered report and any same-origin data accessible to the page. ]]>
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/generate_report.py:19
Finding

Unpinned and Unused Python Dependency Installation Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill promises real-time Zhihuiya MCP-backed analysis and authoritative conclusions, yet the finding indicates it may instead use placeholder or default data and still present a polished executive report. This creates a high risk of deceptive output, causing users to make business decisions on fabricated or stale data while believing it is externally verified.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 521)May include surrounding context.

md
调用 `scripts/generate_report.py` 渲染最终HTML。

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Generic trigger phrases like '一键报告 / 战略研判报告' overlap with ordinary conversation and can accidentally invoke the skill outside a clearly bounded workflow. In this context, accidental activation is more concerning because the skill is designed to perform broad analysis, assemble executive conclusions, and potentially write output files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger allows activation on a standalone company name combined with contextual inference, which is too broad for a high-impact report-generation skill. Overbroad invocation can cause unintended activation, surprising users, unnecessary data access/tool use, and generation of authoritative-looking reports without explicit user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document hard-codes lang="zh-CN", and the visible UI content throughout the template is exclusively Chinese. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest promises a 10-page whitepaper-style HTML report strictly following coolingstyle_v2_whitepaper.html DNA, using specific fonts and a 960px/52px whitepaper layout, with data defaulting to 2012-current and sourced via 智慧芽MCP in real time. This file instead implements an interactive dashboard template for a fixed '污水处理' example, uses a different visual system and fonts, embeds hardcoded sample/inferred data, and shows a 2020–2025 range rather than the stated default scope.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The deep-analysis workflow claims data will auto-fill after enterprise selection, but the script later writes to a non-existent element (signal-list), which can trigger a runtime error and break the panel. In this skill context, broken analysis rendering can suppress risk signals or incomplete evidence while presenting the report as authoritative, which is dangerous for executive decision-making.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code claims to filter enterprises by selected node, but silently pads results with unrelated enterprises from other nodes. In a decision-support/reporting skill, this can mislead users into making strategic decisions on false associations, undermining trust in the report and potentially causing materially wrong business conclusions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Manifest 明确称数据“通过智慧芽MCP实时获取”,且统计范围默认到当前年月;但这里直接构造固定默认上下文,并在 main 中直接用该默认数据渲染报告,没有任何 MCP 调用、实时获取或按当前时间窗口查询的实现。该行为会生成看似正式的数据报告,却与技能声明的数据来源和实时性明显不一致。

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The inventor-targeting section profiles named individuals using public-profile visibility, publication recency, and inferred mobility signals, then recommends direct outreach. In this context, that is dangerous because it operationalizes personnel targeting for competitive advantage, creating privacy, ethics, insider-risk, and potential harassment concerns beyond ordinary business analysis.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The instructions encourage users to query business registries and directly use contact information for outreach, normalizing collection and operational use of contact data without consent, minimization, or policy guardrails. In a competitive intelligence skill, this increases the risk of privacy violations, policy abuse, and socially engineered targeting of suppliers.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The report includes a 'government mode' hidden-champion candidate list inside enterprise output, exposing potentially sensitive profiling of non-public companies beyond the stated business purpose. In this strategic-intelligence context, unnecessary disclosure broadens access to business-sensitive targeting data and can enable unfair competitive intelligence or misuse by unintended audiences.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code comment suggests conditional display by mode, but the implementation uses 'or True', causing government-mode content to be shown unconditionally. This is a real authorization/segregation failure: context-sensitive data intended for a restricted audience is always included, increasing leakage risk in a report-generation system used for strategic decision-making.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code explicitly sets the generated HTML document language to zh-CN, and the surrounding report strings and CLI descriptions are also fixed in Chinese. The file does not provide any user opt-in or configuration for language/locale selection, which can violate language/locale policy requirements for broadly applicable skills.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

技能描述给人的预期是输入公司名称或产业链后,系统基于外部数据自动分析并生成报告;但主流程仅创建随机报告编号、填充默认样例数据并写出 HTML 文件。虽然输出形式是 10 页 HTML,核心“产业链情报分析”能力在该文件中并未真正实现,属于能力表述与实际代码的语义落差。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.