Back to skill

Security audit

smart-construction-analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is a Chinese smart-construction report workflow with no hidden persistence or destructive behavior, though its bundled Word script is static and should not be mistaken for live analysis.

Install only if you want a Chinese-language report workflow and have intentionally enabled the PatSnap MCP tools. Treat the included Word generator as a static sample/template unless the agent has actually run the described searches and added source-backed findings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个端到端“智能建造技术深度分析”技能,核心能力应包括从多源外部数据中获取信息并进行自动分析,最后输出 HTML/Word 双格式报告。实际代码只负责生成一个固定内容的 Word 文档:输入仅为输出目录,输出仅为 docx 文件,内容全部硬编码在脚本中。代码没有网络访问、数据库访问、文件解析、检索、分析流程、模型推理、实体识别或动态数据处理逻辑,也没有 HTML 生成逻辑。因此其实际行为只覆盖了“Word 报告排版生成”的一小部分,而且还是静态内容,和声明的主要目的存在明显实质性不符。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

There is a clear mismatch between the declared description and the supplied code. The description promises a full-featured analytical skill for infrastructure technology intelligence, but the code chunk is only a minimal placeholder entry script that prints a readiness message. It does not access data sources, perform analysis, generate reports, or implement any of the described capabilities. This is a materially different actual behavior from the declared primary purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description is entirely in Chinese and presents the skill as a fixed Chinese-language experience. Under the policy, language constraints should either offer user choice or be clearly documented as a justified locale-specific limitation; that justification is not stated here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown reference enforces a single language locale for all instructions and content, and there is no indication that users may choose another language or that the Chinese-only constraint is required for a region-specific purpose. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring and the generated report content are explicitly Chinese-language, and the script hardcodes a Chinese output filename and report body. Because this code file provides no user opt-in or configurable locale selection, it appears to impose a specific language by default, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.