Back to skill

Security audit

Bahn

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Deutsche Bahn helper, but it automatically stores travel itinerary data locally and ships a dated itinerary in the package.

Review before installing. This skill appears intended for German rail workflows and does not show credential theft, backdoors, or destructive behavior, but expect it to contact DB-related services and to retain parsed travel plans locally unless changed. Remove bundled or generated active.json files you do not want kept, and prefer pinned dependencies for reproducible installs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Node.js Dependencies Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib/helpers.mjs:131
Finding

Plaintext Itineraries Are Automatically Written to a Predictable Path

Content
View full analysis
Remediation
View remediation
`. 2. Keep parsing in memory by default and clearly notify users before retaining itinerary information. 3. Refuse to overwrite an existing file unless a separate `--force` option is supplied. 4. Open new files with exclusive creation semantics and restrictive permissions, such as mode `0600`. 5. Store state under a dedicated per-user application-data directory instead of the current working directory. 6. Validate the destination with `lstat` and reject symbolic links or unexpected non-regular files. 7. Use an atomic write pattern: create a secure temporary file in the destination directory, flush it, and rename it. 8. Document retention and deletion behavior and provide a command for securely removing saved itinerary state. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/connections/active.json:1
Finding

Packaged Artifact Contains a Dated Travel Itinerary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

YARA rule 'php_webshell_known': Known PHP webshell families (c99, r57, b374k, WSO, etc.) [webshells]

Critical
Category
YARA Match
Confidence
90% confidence
Finding

YARA rule matched a known webshell pattern (PHP, Python, JSP, or ASPX webshell).

Content

Scanner excerpt · scripts/lib/messageLookup.mjs (reported line 94)May include surrounding context.

js
ebundene Einstiegshilfe',
  '84': 'Zug verkehrt richtig gereiht',
  '85': 'Ein Wagen fehlt',
  '86': 'Gesamter Zug ohne Reservierung',
  '87': 'Einzelne Wagen ohne Reservierung',
  '88': 'Keine Qualitätsmängel',
  '89': 'Reservierungen sind wieder vorhanden',
  '90': 'Kein gastronomisches Angebot',
  '91': 'Fahrradmitnahme nicht möglich',
  '92': 'Eingeschränkte Fahrradbeförderung',
  '93': 'Behindertengerechte Einrichtung fehlt',
  '94': 'Ersatzbewirtschaftung',
  '95': 'Universal-WC fehlt',
  '96': 'Überbesetzung mit Kulanzleistungen',
  '97': 'Überbesetzung ohne Kulanzleistungen',
  '98': 'Sonstige Qualitätsmängel',
  '99': 'Verzögerungen im Betriebsablauf',
  '900': 'Anschlussbus wartet(?)',
  '1000': 'Kundentext',
  '1001': 'Keine Zusatzhinweise',
  '2000': 'Interner Text',
};

export function lookup(code) {
  return messages[String(code)] ?? `Unbekannte Ursache (code ${code})`;
}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

When the input is treated as plaintext, the function parses it and unconditionally persists the resulting connection data to a local file. There is no confirmation prompt, logging, or inline comment/docstring warning the user that supplying plaintext causes a file write side effect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

todayDateStr() forces the 'sv-SE' locale and 'Europe/Berlin' time zone for date formatting. This is a natural-language/locale policy concern because it imposes a specific regional formatting choice without any opt-in or documented justification in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file defines a large set of user-facing status messages exclusively in German, with no indication that language selection is optional or region-scoped. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.