Back to skill

Security audit

Teamgram Client E2E Flow

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill contains no executable code, but it tells users how to bypass Teamgram enterprise feature checks.

Review before installing. The skill is not an executable backdoor and does not request credentials or system access, but it includes instructions that could lead an agent or developer to disable enterprise access controls. Install only if you will ignore or remove that bypass guidance and preserve authorization, licensing, and entitlement checks unless you have explicit approval from the system owner and rights holder.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:122
Finding

Instruction to Bypass Enterprise Feature Authorization Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 122-131
Vulnerability Type: Authorization and entitlement-control bypass guidance
Risk Level: Medium

Vulnerable Content

text
| ERR_ENTERPRISE_IS_BLOCKED | Enterprise feature locked | The enterprise block must be removed (modify the enterprise-checking logic in biz_service) |

## Enterprise Lock Mode

Some features in Teamgram Community Edition are blocked by an enterprise-edition lock, manifested as:
- `ERR_ENTERPRISE_IS_BLOCKED` errors
- Interception through the `checkEnterprise()` function in a helper at the biz_service layer

Unlock method: Modify the enterprise-checking logic in the corresponding biz_service helper and remove or bypass the `checkEnterprise()` call.

The snippet above is an English translation of the audited file's Chinese text.

Technical Analysis

The skill explicitly instructs users or agents to remove or bypass the server-side checkEnterprise() control. This check is described as enforcing the boundary between community and enterprise functionality. Disabling it would circumvent an intended authorization or entitlement decision rather than diagnosing the cause of the error through an approved configuration or licensing process.

This guidance is also inconsistent with the skill's declared documentation-only purpose. Although the package contains no executable code and cannot perform the bypass by itself, an agent following the instructions could modify the referenced server implementation and eliminate the control.

Attack Path

  1. A developer or coding agent loads the skill while troubleshooting ERR_ENTERPRISE_IS_BLOCKED.
  2. The skill identifies checkEnterprise() in the biz_service layer as the enforcement point.
  3. The developer or agent locates the corresponding helper in a Teamgram Server checkout.
  4. Following the skill's instruction, they remove the call, bypass its result, or modify it to alwa ...[truncated 952 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions recommending removal, bypass, or forced success of checkEnterprise().
  2. Replace the “unlock method” with approved remediation paths, such as obtaining the required enterprise entitlement, verifying license configuration, or contacting the project vendor or maintainers.
  3. Retain diagnostic information only at a descriptive level: explain that the error originates from an enterprise feature gate without directing users to defeat it.
  4. If source-level debugging is necessary, instruct developers to confirm that the check is operating as designed and to preserve fail-closed behavior.
  5. Document supported community-edition alternatives for unavailable functionality where applicable.
  6. Add an explicit safety note that authorization, licensing, and entitlement checks must not be disabled without documented approval from the system owner and applicable rights holder.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly describes an 'unlock method' to remove or bypass enterprise feature checks by modifying server-side logic. Even though this is documentation rather than executable code, it provides actionable guidance for defeating licensing or access-control restrictions, which can enable unauthorized feature use and downstream policy bypasses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The line directly instructs readers to modify helper logic to remove or bypass calls to checkEnterprise(), which is clear guidance for circumventing a server-enforced restriction. This crosses from descriptive documentation into operational instructions for defeating access controls, making misuse straightforward.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation gives step-by-step guidance for bypassing enterprise restrictions by editing server-side checks, materially lowering the barrier to unauthorized modification of protected functionality. In the context of a server developer reference, this is more dangerous because the audience is specifically positioned to apply those changes in real deployments.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The substantive skill content is written in Chinese, and the file does not offer an alternative language, user opt-in, or a documented reason for enforcing that locale. This can violate language/locale policy when a skill implicitly requires a specific language without choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.