Back to skill

Security audit

Gridman古立特

Security checks for vulnerabilities and agentic risk

Overview

This is a China finance and tax assistant skill whose sensitive behaviors are disclosed and gated by user confirmation.

Install only if you want a Chinese finance/tax workflow skill. Configure memory and Tools only in directories you choose, avoid storing credentials in Mind, verify optional npx/MinerU/COM tooling before use, and use a dedicated browser profile or sandbox for external integrations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:190
Finding

Unverified Third-Party MCP Package Executed Through npx

Content
View full analysis

Vulnerability Details

File Location: INSTALL.md, lines 190–199
Vulnerability Type: Third-party supply-chain execution without artifact integrity verification
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "playwright": {
      "command": "npx",
      "args": ["-y", "@playwright/mcp@0.0.78", "--browser", "chromium"],
      "disabled": false
    }
  }
}

The installation guide also recommends executing the package directly for validation:

text
npx @playwright/mcp@0.0.78 --help

Technical Analysis

The documented configuration invokes a third-party npm package through npx. If the package is not already available locally, npx can retrieve it and execute its lifecycle or runtime code from the npm supply chain.

Pinning the package to version 0.0.78 reduces uncontrolled version drift, but it does not independently establish artifact integrity or publisher trust. The documented process does not require an integrity hash, reviewed lockfile, vendored artifact, signature or provenance verification, or inspection of the resolved transitive dependency tree. The -y argument also suppresses the normal installation confirmation.

Because the package runs as an MCP server with browser automation functionality, compromised package code would execute with the operating-system privileges of the host process. Its effective access would depend on the host's MCP sandboxing, filesystem permissions, browser profile, network policy, and tool authorization settings.

Attack Path

  1. An attacker compromises the specified npm package release, its publisher account, a transitive dependency, or the package-resolution infrastructure.
  2. A user follows the installation guide and configures the host to launch npx -y @playwright/mcp@0.0.78.
  3. npx retrieves and executes the compromised package or dependency.
  4. Malicious code runs under the installing user's account ...[truncated 1254 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace ad hoc npx execution with a reviewed installation process using a committed lockfile and integrity-pinned dependency resolution.
  2. Verify npm provenance, publisher identity, package signatures where available, and the resolved artifact checksum before execution.
  3. Review and pin transitive dependencies rather than relying only on the top-level package version.
  4. Remove -y from recommended interactive setup commands so users receive an explicit execution prompt.
  5. Prefer a locally installed, reviewed package invoked with installation disabled, such as npx --no-install, after integrity verification.
  6. Run the MCP server in a sandbox or dedicated low-privilege account with a restricted filesystem view and outbound-network allowlist.
  7. Use a dedicated browser profile without saved credentials, authenticated sessions, payment information, or unrelated browsing data.
  8. Restrict MCP permissions to the minimum browser and output-directory access required for public regulatory-source retrieval.
  9. Document an approved package hash, verification procedure, update policy, and rollback process.
  10. Reassess the package and its dependency tree whenever the pinned version is changed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (121)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

md
- **运行行为与程序规则**:以 `SKILL.md` 和 `operations/` 为准;发生冲突时先保铁律,再按元规则收口。

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · gridman-character/songs.md (reported line 1)May include surrounding context.

md
# 古立特宇宙歌曲集

> 歌曲目录:1. 夢のヒーロー(梦之英雄) | 2. UNION | 3. youthful beautiful | 4. インパーフェクト(不完美) | 5. ストロボメモリー(闪光灯般的回忆) | 6. uni-verse
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · operations/private_resources_rules.md (reported line 182)May include surrounding context.

gitignore
secrets/
outputs/
.env
*.token
*.key
__pycache__/

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file presents the installation guide entirely in Chinese and labels the document in Chinese without any indication that language is optional or user-selectable. Under the policy rule, forcing a specific language or locale without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file is written entirely in Chinese and explicitly describes the skill as a professional core for the China finance and tax domain, but it does not offer users a language choice or state that Chinese is required with explicit user opt-in. Under the policy rule for language or locale constraints, this is a natural-language policy issue because the skill presentation appears to impose a specific language by default.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 40)May include surrounding context.

md
**职业任务** —— 加载对应 Workflow,按步骤走完并做业务复核。当前覆盖:

| 领域       | Workflow                                                                                                                                                                             |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| 审计(14) | 重要性与风险评估、试算平衡与索引表、货币资金、应收与收入、应付与采购、存货与成本、固定资产、税费、内控与穿行测试、审计抽样、会计分录测试、经济责任审计、审计调整与完成、业务承接底稿 |
| 投行(1)  | 资产评估报告审核                                                                                                                                                                     |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · README.md (reported line 43)May include surrounding context.

md
| 领域       | Workflow                                                                                                                                                                             |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| 审计(14) | 重要性与风险评估、试算平衡与索引表、货币资金、应收与收入、应付与采购、存货与成本、固定资产、税费、内控与穿行测试、审计抽样、会计分录测试、经济责任审计、审计调整与完成、业务承接底稿 |
| 投行(1)  | 资产评估报告审核                                                                                                                                                                     |

**执行任务** —— 需要读写表格、解析文档、抓取网页时,古立特声明它需要什么能力,再从宿主实际可用的实现里选一个。找不到就降级,不假装做过。

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The activation description says the skill should trigger for finance, audit, tax, or investment-banking questions generally, which is an extremely broad slice of normal user traffic. Because this skill is authorized to route workflows, access memory, and potentially use host tools or CLI, overbroad activation materially increases the chance of the wrong skill taking control of unrelated conversations and performing actions under an inapplicable persona/policy set.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest description is entirely framed in Chinese and presents the persona and activation behavior as fixed, without indicating that users may choose another language. For a general-purpose finance skill, this can violate language/locale policy when no opt-in or justification for the language constraint is provided.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad, low-specificity terms such as "Hyper Agent" and generic hero-style phrases that can cause accidental invocation outside the intended finance/tax context. Unintended activation can expose the skill's tool-routing, file-read/write, and memory behaviors in sessions where the user did not mean to invoke this specialized agent, increasing the risk of unnecessary data access or confusing tool use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The self-introduction section mandates a specific persona-speaking style entirely in Chinese, including prescribed phrasing and examples, but does not offer the user any language or locale choice. Under the policy, forcing a specific language without opt-in is a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The document title and the entire behavior specification are written as standing rules in Chinese, and there is no indication that the skill offers users a language choice or that the locale restriction is limited to a justified region-specific use case. Under the policy, forcing a specific language without opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains user-facing operational guidance only in Chinese, which effectively forces a specific language for readers and downstream users. The policy allows locale constraints only when user choice is offered or the restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entire operational workflow is written as mandatory Chinese-language instructions and does not indicate that users may choose another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The routing index is written entirely in Chinese and includes instructions such as '古立特默认视为时效敏感', implying the skill operates in Chinese by default. There is no visible opt-in, alternative language option, or justification that this skill is intentionally region- or language-specific, which creates a natural-language policy concern under the locale-choice rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all instructions and usage guidance exclusively in Chinese, and nowhere indicates that the skill is China-specific or that users may opt into another language. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The FAQ states this file loads when users ask broad meta-questions like "为什么 / 能不能 / 报错 / 限制 / 装不上 / 怎么触发", which are very common phrases outside the intended tax/audit domain. Combined with broad trigger aliases in the skill metadata, this increases the chance of unintended activation and context injection into unrelated conversations, causing the agent to follow specialized instructions when not appropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The summon words listed include generic or collision-prone aliases such as "SSSS", "超级特工", and "Access Flash" without clear scoping rules. These terms can appear in unrelated conversations, leading to accidental skill invocation and exposing users to unintended instruction loading, tool-discovery behavior, or handling logic meant only for specialized financial workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The routing guidance in this file maps a wide range of ordinary political, macroeconomic, and public-policy questions to the Gridman skill without meaningful exclusion criteria. In a host agent, this can cause overbroad skill activation, pulling sensitive or off-domain discussions into a specialized workflow and increasing the chance of policy circumvention, biased answers, or unintended handling of political content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation guidance is broad enough to trigger on generic terms like '训练', '练习', '提升思维', or common requests about how to think through a problem. In a host environment, this can cause unintended routing into a specialized finance/tax skill, leading to irrelevant instruction injection, confusion, or accidental handling of requests outside the user's intent.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing instructional content and begins with a Chinese-only title and continues in Chinese throughout the document. Under the language/locale policy rule, forcing a specific language without user opt-in can exclude users and constitutes a natural-language policy violation unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file title and all instructional content are written exclusively in Chinese, with no indication that users may choose another language or locale. Under the policy rule for natural-language constraints, forcing a specific language without opt-in is a reportable issue unless the region-specific restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The entire skill is written in Chinese and presents itself as a general accounting knowledge base, but it does not offer any language choice or state that it is intentionally limited to Chinese-speaking users. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

标题和全文内容均固定为中文表述,但文档中没有说明这是面向特定中文用户群体的区域性资料,也没有给用户提供语言选择或 opt-in。按照规则,强制特定语言且缺乏明确、合理的地域/合规限定,属于自然语言层面的 locale policy 风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.