Back to skill

Security audit

太湖云水务知识库

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible water-equipment knowledge assistant, but it needs review because it stores sensitive interaction data and has an under-disclosed third-party credential/query data flow.

Review before installing. Use provider-specific credentials, do not place a real OpenAI key in this configuration unless the embedding endpoint is corrected, and assume quote details, prompts, tool data, and retrieval snippets may be written to local logs. Enable cron only if you want recurring background updates, and restrict the configured file paths and log access to trusted users.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/query-knowledge.py:32
Finding

API Credential May Be Disclosed to an Unintended External Provider

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit-logger.py:58
Finding

Unredacted User Inputs and Tool Data Are Stored in Plaintext Audit Logs

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (17)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The logger persists raw user input, tool inputs, tool outputs, user identifiers, and retrieval metadata directly to disk, which can capture sensitive data such as personal information, secrets, internal documents, and model/tool outputs. In an agent skill context this is particularly risky because these fields may include prompts, credentials, proprietary retrieval results, or regulated data, and the code provides no minimization, redaction, consent, retention control, or access protection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The audit configuration states that user input, output, session identifiers, user identifiers, and tool activity are logged, but the skill provides no visible warning to users that their interactions are being recorded at this granularity. This creates a privacy and compliance risk because sensitive prompts, personal data, or business information may be captured and retained unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly asks users to provide personal and business contact details such as company, contact person, and phone number to generate a quote draft, but it does not present any privacy notice, purpose limitation, retention policy, or handling instructions. In the same file, the skill also enables detailed audit logging, which increases the chance that submitted personal data will be stored and processed without informed user consent or clear safeguards.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

步骤3: 配置Cron任务(可选)

bash
# 在Linux/macOS上
crontab -e
# 添加以下内容
0 2 * * * python /path/to/water-knowledge-assistant/scripts/knowledge_base_import.py
0 3 * * * python /path/to/water-knowledge-assistant/scripts/tavily_update.py

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Natural-language content throughout the file, including comments, docstrings, and printed messages, is written exclusively in Chinese. Under the policy, forcing a single language without opt-in or clear region-specific justification is a locale/language policy issue.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

With no manifest available, the skill's intended scope is unknown, so external network access and likely use of API credentials from environment variables are not justified by any declared purpose. The code creates OpenAI-compatible embeddings against an Alibaba DashScope endpoint, which transmits user queries off-box and depends on secrets loaded from the environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sends user-supplied query text to an external embedding API without any warning, consent flow, or data-sensitivity check. If users enter proprietary, personal, or regulated data, that content may be disclosed to a third party unexpectedly, creating confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/tavily-daily-update.py (reported line 25)May include surrounding context.

python
def tavily_search(query, max_results=5, time_range="year", include_domains=None):
    """调用 Tavily API 进行搜索"""
    url = "https://api.tavily.com/search"
    headers = {
        "Content-Type": "application/json",
    }

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This code transmits query data to an external API endpoint, which is expected behavior for a search integration, but it still creates a real data-exposure boundary. In this skill, the danger is increased because the same function can be reached with user-derived input and there are no safeguards around sensitive data, consent, or logging of what was sent.

Content

Scanner excerpt · scripts/tavily-daily-update.py (reported line 41)May include surrounding context.

python
}
    
    try:
        response = requests.post(url, headers=headers, json=data)
        response.raise_for_status()
        return response.json()
    except Exception as e:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The on_demand_update function forwards raw user_query content to the external Tavily API whenever trigger words are present, without user notice, consent, or minimization. This can expose sensitive user-entered data to a third party unexpectedly, especially in an assistant or skill context where users may not realize their prompt is being transmitted off-platform.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The description forces a specific language/locale presentation without indicating user choice or that the skill is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, language constraints should either be optional for the user or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire skill file is written in Chinese and does not indicate that language selection is optional or that the content is intentionally limited to a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without user opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file presents all headings, field names, and descriptions exclusively in Chinese, which can amount to a language policy violation if users are not given a choice of locale. There is no indication that the file is intentionally region-specific or that non-Chinese users can opt into another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing natural language only in Chinese, which can amount to a language/locale policy issue when no opt-in or alternative language is provided. The content does not indicate that the skill is region-specific or that the user can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code contains natural-language strings and comments exclusively in Chinese, including status and error messages shown to the user. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script's visible output, usage instructions, and error messages are all fixed in Chinese. This creates a language/locale constraint without any opt-in, fallback, or documentation indicating that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Comments, status prints, and returned messages are written in Chinese throughout the script, which effectively forces a specific language for user-visible behavior. There is no opt-in, language selection, or documented justification that this skill is intended only for a Chinese-language context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.