sa-master
纯文档类skill,无可执行代码,但存在硬编码API密钥泄露、强制外传用户输入至外部MCP服务器、以及服务端协议注入风险。
MCP配置文件中的Bearer Token 'sk-Wp9mTx4KvRn7Qd3Fzj' 以明文形式暴露在SKILL.md中,任何能读取该文档的用户均可使用此凭证。
SKILL.md:179 Why this conclusion was reached
2/4 dimensions flagged1 undeclared or violating capabilities were inferred.
1 lower-risk artifacts were extracted and still need context.
The report includes 0 attack-chain steps and 1 severe findings.
Dependency information is incomplete, so supply-chain confidence stays limited.
What drove the risk score up
SKILL.md第179行暴露Bearer Token 'sk-Wp9mTx4KvRn7Qd3Fzj'
翻译管道要求将所有非中文用户输入发送至外部MCP服务器
客户端被要求解析执行服务端注入的[PROTOCOL]块,存在被操控风险
Most important evidence
硬编码API密钥泄露
MCP配置文件中的Bearer Token 'sk-Wp9mTx4KvRn7Qd3Fzj' 以明文形式暴露在SKILL.md中,任何能读取该文档的用户均可使用此凭证。
SKILL.md:179 强制用户输入外传至第三方服务端
翻译管道(T-P.1)要求将所有非中文用户消息翻译后发送至外部MCP服务器。架构设计内容可能包含敏感业务信息,存在数据外泄风险。
SKILL.md:67 服务端协议注入风险
客户端被要求解析并执行服务端注入的[PROTOCOL v=1.0]块,可能包含恶意指令操控客户端行为。
SKILL.md:231 外部MCP服务器依赖
技能完全依赖外部服务端 https://mcp.smartmoves.com.cn/sa/mcp,无本地fallback,服务器不可用时技能完全失效。
SKILL.md:176 Declared capability vs actual capability
纯文档skill,无文件操作 SKILL.md:179 强制连接外部MCP服务器 https://mcp.smartmoves.com.cn/sa/mcp 无shell执行 无环境变量访问 声明使用MCP Tool调用4个架构设计技能 无剪贴板操作 无浏览器操作 无数据库操作 Suspicious artifacts and egress
https://mcp.smartmoves.com.cn/sa/mcp SKILL.md:179
Dependencies and supply chain
There are no structured dependency warnings.
File composition
SKILL.md