Back to skill

Security audit

猫眼电影个性化推荐

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Chinese movie recommendation workflow that fetches Maoyan movie data, uses a user-created preference file, and can send scheduled reports to Feishu.

Before installing, expect the skill to fetch current movie data from Maoyan, read your local movie preference profile, and send generated recommendations to Feishu if you configure that delivery. Keep sensitive personal notes out of profile.json, review any profile updates before allowing them, and be aware that the referenced profile-template.json was not present in the inspected package.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

该脚本的实际功能是一个电影数据采集器:调用猫眼的上映列表、即将上映列表和详情接口,整理字段并输出 JSON。代码注释也明确写着“纯数据采集,不做过滤”。声明中的核心能力——个性化推荐、基于用户偏好档案智能排序、飞书周报推送——在代码中完全没有体现,也没有任何用户数据读取、排序打分、消息发送或调度逻辑。因此描述与实际行为存在明显且实质性的不匹配。

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The script performs outbound HTTP requests to Maoyan APIs via urllib.request, so it has network capability that should be explicitly declared and reviewed. Undeclared network access weakens permission transparency and can enable unexpected data exfiltration or policy bypass if the skill is executed in a broader agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The README explicitly instructs users to send personalized movie reports to Feishu while the ranking logic depends on a local preference profile containing detailed taste data and potentially identifiable behavioral information. There is no warning, consent step, data-minimization guidance, or description of what profile-derived content may be transmitted off-device, so users may unintentionally disclose personal preference data to an external platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill handles a personal preference profile and instructs delivery of recommendation reports to Feishu, but the top-level description does not prominently warn users that personalized viewing preferences and derived recommendations may be transmitted to an external service. This can cause unintentional disclosure of sensitive preference data, especially if users assume processing remains local or within the agent environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that the AI will update profile.json in response to conversational requests, but it does not clearly warn users that a persistent local preference file may be modified. This creates risk of silent or unintended changes to user data, which can affect future recommendations and potentially overwrite sensitive notes users did not intend to store.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring explicitly states it is '纯数据采集,不做过滤' and the code only fetches Maoyan now-showing/coming-soon listings plus per-movie details, then prints structured JSON to stdout. Nothing in the file builds user preference profiles, performs intelligent ranking, or pushes a Feishu report, which are central behaviors promised by the manifest description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring is entirely in Chinese and provides the usage description only in that language. This imposes a specific language on users without any opt-in or alternative, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The natural-language instructions throughout the file are entirely in Chinese, and the README does not indicate that the skill is intentionally limited to Chinese-speaking users or offer any language/locale choice. Under the stated policy, forcing a specific language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The natural-language instructions, examples, and interaction model are entirely in Chinese, and the manual trigger phrases are presented only in Chinese. Under the stated policy, forcing a specific language without giving the user a choice can be a locale/language policy violation unless clearly justified as region-specific with documented constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.