Back to skill

Security audit

Product Requirement Miner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local product-review analysis workflow, with ordinary file outputs and minor dependency/data-handling cautions rather than evidence of hidden or malicious behavior.

Install in a virtual environment, review or pin the chardet dependency if reproducibility matters, and avoid processing reviews that contain sensitive personal, account, or confidential business data unless local retention in the generated files is acceptable.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unpinned Third-Party Dependency Creates a Supply-Chain Risk

Content
View full analysis
=5 ``` ### Technical Analysis The Skill instructs users to install a third-party package using a version constraint with no exact pin, upper bound, package hash, or locked artifact. The `>=5` constraint allows pip to select any current or future qualifying release from its configured package index. Because Python package installation and subsequent imports can execute package-controlled code, the effective code trusted by the Skill can change after this project has been reviewed. If a qualifying package release or the configured package index is compromised, installation or import of the resolved dependency could execute attacker-controlled code. This finding does not establish that the current `chardet` package is malicious. The vulnerability is the absence of controls ensuring that users receive the specific dependency artifact that was reviewed. ### Attack Path 1. An attacker compromises a future qualifying `chardet` release, its publisher account, a package mirror, or another package source configured in the victim's pip environment. 2. The victim follows the documented command: `python -m pip install -r requirements.txt`. 3. Pip resolves the attacker-controlled release because `chardet>=5` permits future versions. 4. Package-controlled code executes during installation or when `scripts/read_csv.py` imports `chardet`. 5. The malicious code acts with the permissions of the user running pip or the CSV-processing script. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the installing user's privileges. Depending on that user's permissions and environment, the attacker ...[truncated 377 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/read_csv.py:25
Finding

Unbounded CSV Read Can Exhaust Process Memory

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是一个较完整的评论需求挖掘与分析工具,但提供的代码片段只是一个CSV读取与评论导出脚本,属于数据导入/预处理的早期步骤。它没有执行声明中的核心分析能力,如需求提取、分类、聚类、路线图生成或优先级排序。虽然读取CSV评论数据与声明场景相关,但当前代码的主要目的与声明的主要功能相比明显更窄,构成描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly instructs reading CSV input and writing multiple local output files, but it does not declare any explicit tool scope such as allowed-tools or permissions. This creates an authorization gap where the runtime may permit broader file access than users expect, reducing transparency and weakening least-privilege controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs saving raw review text and processed review data to local files without warning about sensitive content, retention, or redaction. Product reviews can contain personal data, contact details, account identifiers, or confidential business information, so indiscriminate local storage increases privacy and data leakage risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template uses Chinese headings and field labels throughout, which imposes a specific language on generated output. The file does not state that Chinese is optional, user-selected, or justified for a region-specific workflow, so it appears to force a locale without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing guidance only in Chinese, and there is no indication that users can select another language or that the skill is intentionally limited to a Chinese-speaking context. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code performs a file write containing raw review text, which may include user-provided or sensitive data. Although it prints a success message after writing, there is no prior warning or disclosure in the script's usage/help text or comments that running the script will persist extracted content to a local file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language instructions in the description are presented only in Chinese, which can effectively force a specific language experience on users. Under the stated policy, language constraints should either be optional via user choice or explicitly justified as a documented locale-specific skill.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
50% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
chardet>=5

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's docstrings and console messages are written in Chinese, which imposes a specific language on users without any opt-in or indication that the tool is intended only for a Chinese-speaking context. Under the policy, fixed language behavior should either offer user choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.