Back to skill

Security audit

人生说明书

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its paid report purpose, but it needs review because it can send very sensitive personal data and bearer credentials to a configurable endpoint that may use plaintext HTTP.

Install only in a controlled environment with an operator-approved HTTPS Life Book endpoint. Do not pass API keys or task tokens on the command line; use a protected secret mechanism where possible. Before running report creation, make sure the user explicitly understands what sensitive personal data will be sent, where it will be sent, and that a paid task or payment-confirmation workflow may begin.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/_shared.mjs:25
Finding

Bearer Credentials and Sensitive Personal Data Can Be Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/_shared.mjs:48
Finding

Secret-Bearing Command-Line Arguments Can Leak through Process Inspection and Execution Logs

Content
View full analysis
--edition lite|pro node skills/life-book-generator/scripts/create-report-task.mjs --input '{"version":"intake@1", ...}' --edition lite Optional: --idempotency-key --agent-api-key # or LIFE_BOOK_AGENT_API_KEY `; ``` Task-token usage is similarly documented as a command-line argument: ```js const HELP = `Usage: node skills/life-book-generator/scripts/get-report-result.mjs --task-id --task-token Returns HTTP 202 with result:null until the report is ready. `; ``` ### Technical Analysis The Skill accepts private bearer credentials through `process.argv`. Depending on the operating system and execution environment, command-line arguments can be exposed through: - Process inspection utilities and process metadata. - Shell command history. - Agent tool-call transcripts. - CI/CD logs and job metadata. - Process monitoring and endpoint telemetry. - Wrapper scripts that log complete invocations. - Debugging and error-reporting systems. Task tokens protect private re ...[truncated 1723 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (19)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
node scripts/check-health.mjs

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
node scripts/create-report-task.mjs \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 148)May include surrounding context.

md
node scripts/confirm-manual-payment.mjs \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

md
node scripts/get-report-task.mjs \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
node scripts/get-report-result.mjs \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
node scripts/wait-report-result.mjs \

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

md
- `create-intake.mjs`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

md
- `create-order.mjs`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
- `get-order.mjs`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README explicitly instructs the agent to collect and transmit highly sensitive personal data, including birth details, geolocation, life history, and core personal problems, but does not present any privacy warning, data-handling notice, minimization guidance, or consent language specific to sensitive-data transmission. In the context of a paid report-generation workflow, this increases the chance that operators or end users will submit intimate personal data without understanding retention, sharing, or exposure risks, which can lead to privacy harm and regulatory issues if the service or integration is compromised or misused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description is broad enough to trigger on general requests to 'buy' or 'generate' a Life Book report, which can cause the agent to enter a payment-oriented workflow without clear user intent confirmation. In a skill that can create paid tasks and handle payment state, overbroad activation increases the risk of unintended commercial actions and unnecessary collection of sensitive intake data.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
Use `--channel wechat` or `--channel evm` when appropriate.

This only marks the order as awaiting operator review. It does not auto-confirm receipt.

### 6. Check Task Status

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction 'Speak Chinese unless the user asks otherwise' sets a default language policy that forces a specific language absent user consent. This is a natural-language policy issue because the skill does not first offer a language choice or require locale-specific context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The default prompt encourages invoking the skill whenever a user wants to create or retrieve a Life Book report, but it does not define clear eligibility, consent, billing, or confirmation boundaries. In a paid task-generation context, broad implicit triggering can cause unintended purchases, premature task creation, or disclosure/retrieval of sensitive generated reports without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This example data uses Chinese text throughout and fixes the timezone to Asia/Shanghai, which implies a specific language/locale context without any visible opt-in or alternative. The policy forbids forcing a specific language or locale unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code sends the user-provided intake JSON to a remote API endpoint via an HTTP POST request. In this file there is no confirmation prompt, user-facing log/print, or explanatory comment/docstring warning that supplied data will be transmitted over the network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This script performs a network call and transmits a task bearer token in the Authorization header. In this file there is no confirmation prompt, visible user-facing notice, or explanatory comment/docstring disclosing that credential-backed polling of a remote endpoint occurs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language instructions throughout the README are presented only in Chinese, which effectively forces a specific language for users of the skill. The file does not offer an alternative language, opt-in language selection, or a documented justification that the skill is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The short description is in Chinese while the default prompt is in English, but the manifest does not indicate whether language selection is based on user preference or locale. This can create a language-policy ambiguity because the skill appears to impose or assume language behavior without explicit opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.