Back to skill

Security audit

万方查重

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed WanFang paper-check workflow that uploads user-selected documents to fixed public endpoints and hands payment back to the official page without hidden persistence or credential handling.

Install only if you intend to use the CQCCJY WanFang paper-check service and are comfortable uploading the selected document to that service. Review the live price and product type before submitting; payment, card use, and captcha entry remain user-controlled in the browser.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill clearly instructs use of local scripts, reference files, and live HTTPS endpoints, which implies file and network access, but it does not declare any explicit tool scope or permission boundaries. That creates an authorization ambiguity where a host agent may grant broader-than-necessary capabilities or users may be unaware that external network actions and local file operations will occur.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description is entirely in Chinese and presents the skill behavior as fixed, with no indication that users may interact in another language or choose a locale. Under the policy rule, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The config contains natural-language strings such as "检测卡号支付", "微信支付", and "支付宝" in a single language, with no accompanying indication that the skill is region-specific or that users can opt into a preferred locale. This may violate the language/locale policy because it forces one language presentation by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The entire skill reference is written only in Chinese and does not indicate any user language choice, fallback, or region-specific justification. Per the policy category, forcing a specific language without opt-in can constitute a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The JSON includes user-facing product names, units, and price labels entirely in Chinese (for example, productName, unit, and priceLabel) but provides no indication that the skill is region-specific or that users can opt into this locale. Under the policy, forcing a specific language without user choice can be a natural-language policy issue even in config/data files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all operational guidance in Chinese and does not indicate that the user can choose another language. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_wanfang_client.py:13