Back to skill

Security audit

Huoshan Qifu Doc Knowledge Router

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only Feishu document router with one minor over-triggering risk, but no evidence of hidden writes, credential theft, persistence, or exfiltration.

Install only if you expect the agent to use your Feishu account to read Huoshan/Qifu knowledge documents. Be aware it may request Wiki and Docx read-only scopes, and the publisher should ideally narrow the generic source-grounded-answer trigger to avoid accidental activation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The skill description contains broad trigger phrases such as generic knowledge retrieval, document recommendation, and source-grounded answers, which can cause the router to activate for common enterprise queries beyond a narrowly scoped domain. This increases the chance of unintended tool use and unnecessary access to internal document indexes, especially when users did not explicitly request this skill.

Static analysis

No suspicious patterns detected.