Back to skill

Security audit

合规咨询

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, purpose-aligned compliance consultation workflow that uses a configured hegui MCP database, with one source-boundary ambiguity users should notice.

Before installing, confirm you are comfortable putting the hegui MCP token in your Claude configuration and sending compliance questions to that MCP service. For strict source control, treat hegui database records and their original attachments as the only acceptable evidence source, and do not rely on the user-authorized external-source fallback unless you intentionally want that broader behavior.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding
The skill claims it will base compliance advice on verified current regulations and validated announcement records, but the provided content is only procedural instructions and does not itself implement or guarantee those checks. In a legal/compliance context, this mismatch is dangerous because users may rely on authoritative-sounding output that lacks the promised evidence chain, leading to incorrect disclosure, governance, or qualification decisions.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The retrieval strategy explicitly allows using external official data sources when the user authorizes it, but the skill metadata forbids independent online search and non-hegui sources. This creates a policy-conflict path that can cause the agent to bypass the mandated trusted data boundary, leading to inconsistent evidence standards, unvetted source usage, and possible data exfiltration or hallucinated compliance advice framed as authoritative.

Static analysis

No suspicious patterns detected.