Back to skill

Security audit

维普查重与报告验真

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed VPCS paper-check workflow that can upload user documents only after consent and hands payment, CAPTCHA, and report verification back to the browser.

Install only if you intend to use this VPCS service for Chinese-language paper checking. Before running submit, confirm the exact product and that you are willing to upload the selected document to the VPCS/OSS workflow; payment and CAPTCHA should remain in your browser, and final prices and school acceptance rules should be checked on the live site or with your institution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
86% confidence
Finding

代码与声明有部分一致之处:它确实支持订单提交、文件上传、订单查询,并且不代替用户支付、也不绕过验证码,整体仍围绕维普查重工作流。但声明描述的是一个更完整的多 SKU 商品/FAQ/价格/上传/订单/报告/验真辅助 Skill,而实际代码只实现了订单提交与状态查询这条最小工作流。尤其缺少价格刷新、SKU 快照、FAQ、以及验真功能本身;报告下载也不是主动实现下载流程,只是在服务端返回真实 HTTPS 链接时透传。因此声明显著高估了代码能力,属于描述与实际行为不完全匹配。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 436)May include surrounding context.

md
- `assets/report-guides/01-word-character-count.jpg`:Word/WPS 字符数(不计空格)预检;

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 437)May include surrounding context.

md
- `assets/report-guides/02-vpcs-report-number.jpg`:查重报告首页报告编号;

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 438)May include surrounding context.

md
- `assets/report-guides/03-report-download-archive.jpg`:报告压缩包和解压;

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 439)May include surrounding context.

md
- `assets/report-guides/04-report-authenticity.jpg`:查重报告验真线索;

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 440)May include surrounding context.

md
- `assets/report-guides/05-aigc-report-authenticity.jpg`:AIGC 报告编号和验真线索;

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 441)May include surrounding context.

md
- `assets/report-guides/06-verify-report-code.jpg`:验真页输入编码,前后不要有空格。

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · assets/faq/faq-03-system-note.png (reported line 1508)May include surrounding context.

text
fn!��hb��Ղ���C"��,B|4��B�O�5C‰�+��k`-��Y�Q`0�2Z#1>���_Y�\��|�\N1?H[�aWx�4����~`��^���!��Տ�Z��d<���o�s�d�'�;���,��\[���_�߹��$I!�B!ă-�������3<=mM���C�{MR�\
�IP��CUkV��"X�0�1����P��FG12���s�#�C���)��eB�p�°��dCJ�PvAl�'4k�qM���ψ�o�\���
[	���6L�yc?z�#��O��κ�����"C*	N��T�l�B!����2[7��O�����c!��O�+ă��	��+�5�Yl��5������Gpspy|l~ddidlqd�<;�Ki �� LX��.KʆL��*��`�*R�H)V�-`)c
V�Hn�ITj5n_������s�QX�����,�qhy��d}LD�0@
J����;K^!�B�@3�r�t��c"1�O�JI��9����"(����U@E��h`]��u?�}�J��D
l,E
��Z����1:��1��bphydtitd������&��fSc��l�E�������ި,D��l	[�5��.8ߚ԰��z���%W0)_�r6C_���J��.�G���w��R
�ҷe�do	!�B!�@A+�J)�vDB�[��B��K�ʆj������`��k���
�*�ް��`C@!���8���Ã##�ѱ����*��a�ÄE2�a��c�>33>1�	�Q�j6���Q[ו��'�Z-�B!�B�!�5!�=Iu!�O���%h�6��� ~4�"���h
���bh##''�o/L�-ON��8`C�Uc갆M�)c](�P3keG>q��=욕G�Q��d�/�<ouI�C!�B!�B�!�!��	b@1\k�B�Pu

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes behaviors that imply file access, network interaction, and possible file creation/upload orchestration, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, missing scope declarations can cause over-broad tool availability or ambiguous enforcement, increasing the chance that the agent accesses files or networks beyond what reviewers and users expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation criteria are extremely broad, covering many ordinary questions about the vendor, products, workflow, ordering, payment handoff, reports, and verification. Over-broad triggering can invoke this skill in situations where file upload, order handling, or network actions are unnecessary, increasing the risk of unintended data collection, premature workflow execution, or confusion about user consent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The entire API contract is written only in Chinese and does not indicate that other languages are supported or that users may choose their preferred language. Under the stated policy, a skill that imposes a specific language without opt-in can be a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The entire tutorial and the agent response guidance are written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to Chinese-speaking users. Under the policy for natural-language organizational violations, a fixed language requirement without opt-in can be a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The entire README is written as a Chinese-only operating document and instructs agent behavior in Chinese, but it does not mention any option for users to choose another language or explain that the skill is intentionally restricted to a Chinese-only regional context. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The section '给 agent 的强制输出格式' mandates a fixed response template entirely in Chinese for any product consultation, and the rest of the file consistently instructs the agent in Chinese without indicating that language should follow user preference. This can violate a language/locale policy when users have not opted into Chinese output.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description and the document content instruct and respond in Chinese, but there is no stated user opt-in or explanation that the skill is limited to Chinese-speaking users or a China-specific deployment. This can violate language/locale policy when a skill implicitly forces one language for all users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest-like JSON includes user-facing labels in Chinese only ("检测卡号支付", "微信支付", "支付宝"). Because this file does not indicate that the skill is region-specific or that users can opt into a language/locale, it appears to hard-code a locale choice in a way that may violate language/locale policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all instructions and content only in Chinese, with no indication that users can opt into another language or that the restriction is explicitly documented as a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file presents all user-facing content exclusively in Chinese, which can violate a language/locale policy when no user opt-in or alternative language path is offered. The file does not state that it is intentionally limited to Chinese-speaking users or a China-specific audience beyond the topic itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This JSON manifest embeds product names, aliases, usage descriptions, and constraints exclusively in Chinese, which can amount to a forced language/locale experience if consumed directly by the skill without offering alternatives. The file does not document that the language is region-specific or that users can opt into another locale.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_vpcs_client.py:12