Back to skill

Security audit

TVKH SRU Query

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward library catalog search tool that makes a disclosed network request to one public SRU endpoint and returns parsed JSON results.

Install this if you are comfortable with the skill sending your catalog search terms to the Khánh Hòa Provincial Library SRU service. Expect Vietnamese catalog content and some Vietnamese messages; no local credential, file, persistence, or destructive behavior was found.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The entire skill description is written in Vietnamese and does not provide an alternative language or indicate that the skill is intended only for Vietnamese-speaking or region-specific users. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill documentation describes network access to an external SRU endpoint, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates a mismatch between declared and actual capabilities, which can undermine least-privilege controls and cause the agent runtime to permit or deny network behavior unpredictably.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file uses Vietnamese-only comments, error messages, and output-facing text such as parser/help descriptions and runtime diagnostics, but does not provide any user opt-in or alternate locale handling. That can violate language/locale policy when a skill implicitly forces a specific language for interaction without giving the user a choice.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The comment at L027 describes aggressively raising the retrieval size to 150 to dig through many noisy newspaper records, while the broader skill purpose is to query and return structured catalog results subject to user limits. The code at L028 hard-codes fetch_limit=150 and only later trims results, which makes the comment partly describe behavior but also conflicts with the user-facing notion of maximum records as the effective retrieval bound.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.