Back to skill

Security audit

China Tour

Security checks for vulnerabilities and agentic risk

Overview

This travel-guide skill mostly matches its purpose, but it needs review because one helper sends user questions and optional conversation history to an undisclosed unencrypted remote server by default.

Review before installing. Use offline/local fallback or configure CHINATOUR_API_URL to a trusted HTTPS endpoint before using API-backed answers, and avoid sending sensitive travel plans, family details, or unrelated conversation history. Also verify opening hours, tickets, and no-photo rules with official sources before travel.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/api_client.py:32
Finding

Undisclosed Plaintext Transmission of User Questions and Conversation History to a Remote Server

Content
View full analysis
Dict: """ Make HTTP request to API Args: endpoint: API endpoint (e.g., '/api/v1/guide/ask') method: HTTP method data: Request body data Returns: Response dict """ url = f"{self.api_url}{endpoint}" headers = {'Content-Type': 'application/json'} self._log(f"Request: {method} {url}") try: if data: body = json.dumps(data, ensure_ascii=False).encode('utf-8') request = urllib.request.Request( url, data=body, headers=headers, method=method ) else: request = urllib.request.Request(url, headers=headers, method=method) with urllib.request.urlopen(request, timeout=self.timeout) as response: response_body = response.read().decode('utf-8') self._log(f"Response: {response.status}") return json.loads(response_body) ``` The transmitted request body can contain both the current question and the complete conversation history supplied by the caller: ```python def ask( self, question: str, attraction_id: Optional[int] = None, language: str = 'auto', ...[truncated 3956 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (90)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · DEVELOPMENT.md (reported line 157)May include surrounding context.

...

text

### Step 4: Update SKILL.md

Add new attraction to the supported list in `SKILL.md`.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code does not implement an AI-powered tour guide. Instead, it performs deterministic user-profile extraction from conversation history using hardcoded regex patterns and inferred categories. While profile extraction could be a supporting component of a tour guide, the supplied chunk lacks the core declared behaviors: scenic-spot guidance, route planning, backend API usage, offline fallback handling, photo-spot recommendation, and cultural narration. Therefore the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code does partially match the description in that it recommends personalized routes for Chinese scenic spots and includes photo/cultural highlights. However, several material parts of the declared purpose are not implemented in this chunk: there is no backend API usage, no offline fallback mechanism between API and local mode, and no bilingual support logic. The implementation is a standalone local recommendation CLI using static markdown data, not an AI-powered backend-enhanced tour guide. Because the declared description prominently includes capabilities absent from the code, this is a mismatch.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The development guide consistently frames user conversations, feedback keywords, and example interactions in Chinese, and only later mentions English support as an additional data file. This creates a natural-language policy concern because the skill appears to assume a specific language by default rather than offering a user language choice up front.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The English introduction states the skill is "fully offline," while the manifest and later Chinese documentation say it supports backend API enhancement with offline fallback. This is an active contradiction in documented intent about whether the skill uses network-backed functionality.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger examples include generic phrases such as 'What's next?', 'Best photo spots?', and 'Tell me the story behind this place' that can easily appear in normal conversation outside the intended skill context. In an agent ecosystem, overly broad triggers can cause accidental activation, context hijacking, or unintended routing of user input into this skill when another tool or no tool should handle it.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Chinese usage section says that asking directly at a scenic spot will trigger the skill and gives broad examples like '接下来去哪' and '这里有什么故事.' These phrases are highly generic and may overlap with ordinary conversation, increasing the chance of unintended invocation or prompt routing collisions with other skills in a shared assistant environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill documentation advertises code-capable behaviors such as backend API access, local file loading, and fallback logic, but it declares no explicit tool scope or permission boundary. In an agent ecosystem, this can cause the runtime to grant broader implicit capabilities than users expect or make reviewers unable to verify whether network, file, or environment access is intentionally authorized.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Broad triggers like 'What's next?' or '接下来去哪儿?' can cause the skill to activate outside the intended travel context, increasing the chance of prompt hijacking, accidental invocation, or interference with other skills. Over-triggering is dangerous in agent systems because it routes unrelated conversations into a workflow that may request profile data or produce misleading guidance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

全文以中文固定定义触发词、回复词和模板输出格式,例如要求用户回复“继续”“调整”“提问”等,但没有提供语言/locale 选择或说明该技能仅面向中文用户。按规则,这属于自然语言层面的语言/地区策略约束且缺少显式 opt-in。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

T2 的触发场景包含“每站导览的默认输出”“用户到达新景点”等宽泛条件,但没有说明如何判定“到达”、是否需要位置或上下文确认,也没有说明在何种情况下不应触发。类似模糊激活条件会增加非预期调用风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The profile-collection template asks for companionship, interests, and time availability without any privacy notice, retention statement, or purpose limitation. Even if the data appears low sensitivity, it is still personal preference/context data, and collecting it without transparency can lead to privacy misuse, overcollection, or noncompliant downstream handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该文件是 markdown,适用 SQP-1。意图识别规则使用了“第一次来”“继续”“到了”“拍照”“休息”等非常常见的日常表达作为模板触发关键词,但未提供排除条件、上下文约束或负例,容易在普通闲聊或非导览语境中误判并切换模板。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all user-facing content in Chinese, including headings, directions, and service information, with no indication that the user can choose another language. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document clearly states that photography is prohibited inside all caves, yet it also marks 'special caves' as highly suitable for photos in the attractions table. This contradictory guidance can mislead users into violating site rules or cultural heritage protection requirements, especially because 'special caves' are interior attractions where photography is explicitly banned.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file title explicitly defines this as an English version, and the content is entirely presented in English without any visible instruction to ask for or honor the user's language preference. This can violate language/locale policy when a skill constrains output language by default rather than offering user choice or documenting a justified locale limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file presents all guidance, examples, and instructional text exclusively in Chinese. Under the policy, forcing a specific language without user opt-in or a documented regional justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill content is written as Chinese narration material and labels all explanation levels and techniques in Chinese, with no indication that users may choose another language. This creates a natural-language locale constraint that is not presented as optional or justified as a region-specific compliance requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The heading explicitly labels the skill content as English, and the file consistently presents all user-facing material only in English. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The heading explicitly labels the skill content as English-only, and the file consistently presents all material in English without indicating that users may select another language or locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and there is no indication that users may select another language or that the material is intentionally limited to a Chinese-only audience. Under the policy rule for language/locale constraints, forcing a single language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is explicitly labeled and structured as English-only content, and there is no indication that users can choose another language or that the locale restriction is required for a region-specific purpose. That creates a natural-language locale policy concern under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file contains user-facing instructional content entirely in Chinese, and there is no indication that users may select another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The entire markdown file is written in Chinese and provides no indication that alternative languages are available or that Chinese is a justified locale-specific requirement. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document presents all user-facing instructions and descriptions exclusively in Chinese, and there is no indication that the skill is region-specific or that users can opt into this language. Under the policy rule for language or locale, forcing a specific language without user choice is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.