Back to skill

Security audit

Chill Beijing

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to provide live third-party scraping or recommendations, which is purpose-aligned but should be used with privacy awareness.

Install only if you are comfortable with user queries being used for live lookups against third-party platforms. Avoid submitting sensitive personal information, and check whether the skill documents which sites it contacts and whether it uses browser automation or cached/offline modes.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly advertises real-time scraping of multiple third-party platforms but does not disclose that using it will trigger outbound network access, automated browsing, or potential transmission of user queries to external services. This creates a transparency and privacy risk because users may invoke the skill expecting local recommendations while the skill performs live collection against external sites, possibly exposing usage patterns, IP address, and query context.

Static analysis

No suspicious patterns detected.