Back to skill

Security audit

晓蜜智能外呼

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate outbound-calling purpose, but it can start real bulk calls and expose contact data with safeguards that are too weak for that impact.

Review this skill before installing. Only use it with least-privilege Alibaba Cloud credentials, verified caller-number authorization, recipient consent or another valid legal basis, and a human confirmation process outside the script. Do not pass whole CRM records, resumes, order histories, or sensitive notes into agentProfile.background; include only the minimum data needed for the call. Treat call recordings and signed download links as sensitive personal data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/bundle.cjs:83765
Finding

Bulk outbound calls can execute without programmatic confirmation

Content
View full analysis
validSet.has(c.phoneNumber) ); const result = await executeOutboundCallFlow( valid, options.instanceId, options.scriptId, taskInput.scenarioDescription, taskInput.agentProfile, validContacts ); return { taskInput, jobGroupId: result.jobGroupId, instanceId: result.instanceId, scriptId: result.scriptId, totalPhones: valid.length }; } catch (error) { console.error(` \u274C \u4EFB\u52A1\u6267\u884C\u5931\u8D25: ${error.message} `); throw error; } } ``` The called flow starts the external operation directly: ```javascript console.log("\n6. \u542F\u52A8\u5916\u547C\u4EFB\u52A1..."); await client.startJobGroup(jobGroupId, phoneNumbers, contacts); ``` The documentation states that explicit user confirmation is mandatory, but the executable does not enforc ...[truncated 2801 chars]
Remediation
View remediation
` before any cloud mutation or call initiation. 5. Reject expired tokens and reject approval if any task field changes after confirmation. 6. Place the authorization check immediately before instance creation, script creation, contact assignment, and `startJobGroup`, rather than relying solely on Agent instructions. 7. Add configurable limits for maximum contacts per task, maximum daily calls, concurrency, and estimated cost. 8. Require a separately configured automation policy before allowing `--no-interactive`. 9. Record an audit event containing the approving identity, task hash, timestamp, contact count, and resulting job-group ID. 10. Use least-privilege Alibaba Cloud credentials restricted to only the necessary OutboundBot operations and resources. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:108
Finding

Instructions encourage excessive transmission of contextual personal data

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
node scripts/bundle.cjs taskInput.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
node scripts/bundle.cjs taskInput.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
node scripts/bundle.cjs taskInput.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 183)May include surrounding context.

md
node scripts/bundle.cjs taskInput.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
node scripts/bundle.cjs taskInput.json

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 208)May include surrounding context.

md
node scripts/bundle.cjs taskInput.json

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/bundle.cjs (reported line 1302)May include surrounding context.

js
_this;
        }
        return BaseError2;
      })(Error)
    );
    exports2.BaseError = BaseError;
    var ResponseError = (
      /** @class */
      (function(_super) {
        __extends(ResponseError2, _super);
        function ResponseError2(map) {
          var _this = _super.call(this, map) || this;
          _this.name = "ResponseError";
          _this.data = map.data;
          _this.description = map.description;
          _this.retryAfter = map.retryAfter;
          _this.accessDeniedDetail = map.accessDeniedDetail;
          if (_this.data && _this.data.statusCode) {
            _this.statusCode = Number(_this.data.statusCode);
          }
          return _this;
        }
        return ResponseError2;
      })(BaseError)
    );
    exports2.ResponseError = ResponseError;
    var UnretryableError = (
      /** @class */
      (function(_super) {
        __extends(UnretryableError2, _super);
        function UnretryableError2(message) {
          var _this = _super.call

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
85% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 20354)May include surrounding context.

js
var utils = __importStar(require_utils());
    var http_1 = require_http();
    var config_1 = __importDefault(require_config());
    var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
    var RsaKeyPairCredential = class extends session_credential_1.default {
      constructor(publicKeyId, privateKeyFile) {
        if (!publicKeyId) {

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
85% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 21411)May include surrounding context.

js
var utils = __importStar(require_utils());
    var http_1 = require_http();
    var config_1 = __importDefault(require_config());
    var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
    var RsaKeyPairCredential = class extends session_credential_1.default {
      constructor(publicKeyId, privateKeyFile) {
        if (!publicKeyId) {

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
85% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 21428)May include surrounding context.

js
var utils = __importStar(require_utils());
    var http_1 = require_http();
    var config_1 = __importDefault(require_config());
    var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
    var RsaKeyPairCredential = class extends session_credential_1.default {
      constructor(publicKeyId, privateKeyFile) {
        if (!publicKeyId) {

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
85% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · scripts/bundle.cjs (reported line 21447)May include surrounding context.

js
var utils = __importStar(require_utils());
    var http_1 = require_http();
    var config_1 = __importDefault(require_config());
    var SECURITY_CRED_URL = "http://100.100.100.200/latest/meta-data/ram/security-credentials/";
    var RsaKeyPairCredential = class extends session_credential_1.default {
      constructor(publicKeyId, privateKeyFile) {
        if (!publicKeyId) {

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill proceeds directly to executeOutboundCallFlow and start real outbound calls after parsing input and validating phone numbers, without an explicit confirmation step warning the operator that real contacts will be dialed. In a bulk-calling skill, this is dangerous because a mistaken input, malicious upstream context, or automation misfire can immediately trigger calls to real people at scale.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill instructs use of environment credentials and execution of a Node.js script that can perform external API calls, but it declares no explicit tool scope or allowed-tools boundary. That creates an authorization gap where an agent may access env secrets and network capabilities more broadly than intended, increasing the chance of secret exposure or unintended outbound actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly encourages collecting personal details, CRM fields, resume data, and history, then embedding them into call content/background without a strict necessity test, minimization rule, or user-facing privacy warning. In an outbound-calling context, this can disclose sensitive personal data to third-party systems and to call recipients, creating material privacy, compliance, and data-leak risks.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instruction to aggregate 'all known information' into agentProfile.background encourages over-collection and broad disclosure of caller/callee and upstream-system data. In this skill’s context, that data is then used to generate and execute automated phone outreach, which amplifies the blast radius of any excessive or inaccurate personal data included.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 180)May include surrounding context.

md
**查询子命令:**

| 子命令          | 说明                        | 用法                                                                                                     |
| --------------- | --------------------------- | -------------------------------------------------------------------------------------------------------- |
| `query`         | 查询任务组整体进度          | `node scripts/bundle.cjs query <instanceId> <jobGroupId>`                                                 |
| `query-jobs`    | 查询各 Job 详细结果(分页) | `node scripts/bundle.cjs query-jobs <instanceId> <jobGroupId> [--page N] [--size N] [--status Succeeded]` |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs users to submit phone numbers and called-party names for automated outbound calls, but provides no privacy notice, consent requirement, retention guidance, or data-handling limitations. In an outbound-calling skill, this omission is materially risky because it normalizes collection and transfer of personal data without safeguards, increasing the chance of unauthorized use, compliance violations, or privacy harm at scale.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

L053 明确写明 agentProfile 为“⛔ 必填,不可省略”,但 L086-L089 又说明在无法提供时系统会根据 scenarioDescription 自动推断基础角色。这不是单纯信息不完整,而是对输入要求与实际处理行为的直接矛盾,可能误导调用方对技能必需参数和兜底行为的理解。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guidance says agentProfile.background should contain all known contextual information, including called-party identity, role, event details, and prior-step data, without any minimization boundary. In this skill context, that creates a strong risk of over-collection and prompt-level exposure of sensitive personal or business data to the calling system, potentially leaking more information during calls or into logs than is necessary for the task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill content, including the user-facing guidance and prompts, is written only in Chinese and does not indicate that language selection is optional or limited to a China-specific deployment context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The scenarios encourage bulk outbound calling and promotional outreach using phone numbers, including numbers sourced from prior workflow steps or files, but provide no guidance on consent, lawful basis, privacy notice, or safe handling of personal data. In this skill context, that omission is meaningful because the core function is automated contact at scale, which can facilitate privacy violations, unlawful marketing calls, or misuse of personal information if operators assume the workflow is approved by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file includes commands for exporting ALIBABA_CLOUD_ACCESS_KEY_ID and ALIBABA_CLOUD_ACCESS_KEY_SECRET, which are sensitive credentials. The surrounding guidance does not warn users about protecting secrets, avoiding shell history exposure, or using a secure credential-management method.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code automatically discovers or creates an outbound bot instance and binds a tenant phone number, which is broader than a simple 'place outbound calls' capability. While not inherently malicious, this is a privileged infrastructure-management action that can change cloud resources and telephony configuration without a clearly separated approval step.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill includes a get-recording path that retrieves recording metadata and a signed download URL, which goes beyond the manifest’s described scope of placing outbound calls and tracking task progress. That scope expansion increases privacy risk because call recordings may contain sensitive personal data, and exposing access without clearly declaring or gating the capability can enable unauthorized retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The recording retrieval flow returns a signed URL for downloading call recordings without any warning, privacy notice, or secondary confirmation. Because recordings can include sensitive customer conversations and personal data, silently exposing downloadable links materially increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.