Back to skill

Security audit

Baby record

Security checks for vulnerabilities and agentic risk

Overview

This baby-care record skill has a coherent purpose, but its local file handling can read, overwrite, or delete JSON files outside its intended data folder and it includes under-disclosed permanent deletion.

Install only after reviewing the local-file risks. The skill is not showing network exfiltration or hidden persistence, but it should validate dates, confine all file access to its data directory, disclose deletion, and require explicit confirmation before saving or deleting sensitive baby-care records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/daily_tracker.py:20
Finding

Arbitrary JSON File Access Through Date Path Traversal

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared behavior does not match the actual capability surface: the skill promises image/voice-style intake that is not implemented, while static analysis indicates an undeclared delete capability. Undisclosed destructive functionality is particularly risky because users and reviewers cannot accurately assess what actions the skill may take on stored baby-care records.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a Python script that reads and writes local JSON files, but it declares no explicit tool scope or permissions. This weakens least-privilege controls and makes the skill’s file access harder to review or constrain, increasing the chance of unintended filesystem access if the implementation changes or is abused.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该技能在描述中列出“帮我看看这张表(图片)”“宝宝日记”“每日情况汇总”等触发内容,其中部分短语缺少足够的领域约束,可能在一般聊天或图片理解场景中也会出现。说明中也未提供排除条件或负例来界定何时应触发、何时不应触发,因此存在非预期调用风险。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The oral-input flow instructs the agent to save user-provided health-related data immediately without a pre-save notice or confirmation step. Because the data concerns a baby’s daily care and is persisted to disk, accidental, misheard, or injected information could be stored permanently and later relied upon as if accurate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

“所有交互使用中文”属于明确的语言限定,但文档中未说明这是用户可选项,也未解释该技能为何必须仅使用中文。按照语言/locale 政策要求,未经用户选择即强制特定语言可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all headings, field descriptions, and usage guidance exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring is entirely in Chinese and presents the tool as a Chinese-only baby care record utility. Under the policy rules, forcing a specific language without user opt-in is a natural-language locale violation when no alternative language choice or justification is provided.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes this skill as supporting baby daily data entry, lookup, and summary generation, with data stored as JSON files. The code also implements a delete command that removes daily records from disk, which is a materially different destructive behavior not suggested by the manifest description or trigger phrases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The delete operation permanently removes stored baby-care records immediately when invoked, with no confirmation, undo, or soft-delete behavior. In an agent context, an accidental, ambiguous, or manipulated command could cause irreversible loss of sensitive caregiving history, affecting record integrity and availability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The save path persists sensitive baby health and care information to local JSON files without any disclosure, consent flow, retention notice, or protection mechanism. In skill/agent usage, users may assume ephemeral processing, so silent persistence increases privacy risk if the host environment is shared, backed up, or otherwise accessible.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.