Back to skill

Security audit

大乐透开奖查询

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed China Sports Lottery result lookup helper that makes limited outbound web requests, with some data-accuracy caveats but no evidence of hidden persistence, credential access, or destructive behavior.

Install only if you want a China 大乐透 lookup skill and are comfortable with it contacting the listed lottery websites. Treat third-party-source results as advisory and verify important ticket checks against the official lottery.gov.cn site.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/dlt_lottery.py:340
Finding

Insufficient Validation of Untrusted Lottery Data

Content
View full analysis

Vulnerability Details

File Location: scripts/dlt_lottery.py:340-356, 388-397
Vulnerability Type: Weak validation and overly broad parsing of untrusted third-party HTML
Risk Level: Medium

Vulnerable Code

python
# 号码 - 彩经网通常有表格格式
# 尝试匹配表格中的号码
table_matches = re.findall(r'<td[^>]*>\s*(\d{2})\s*</td>', html)
if len(table_matches) >= 7:
    result['front'] = table_matches[:5]
    result['back'] = table_matches[5:7]
else:
    # 回退到通用匹配 - 找连续的 7 个两位数
    combo_match = re.search(
        r'(\d{2})\s+(\d{2})\s+(\d{2})\s+(\d{2})\s+'
        r'(\d{2})\s+(\d{2})\s+(\d{2})',
        html
    )
    if combo_match:
        result['front'] = list(combo_match.groups()[:5])
        result['back'] = list(combo_match.groups()[5:7])
    else:
        numbers = re.findall(r'\b(\d{2})\b', html)
        if len(numbers) >= 7:
            result['front'] = sorted(
                set(numbers[:5]),
                key=lambda x: int(x)
            )
            result['back'] = numbers[5:7]

return result
python
html = fetch_lottery_page(url, source['timeout'])

if not html.startswith("ERROR:"):
    draw = parse_draw(html, source['name'])

    # 验证数据完整性
    if draw['issue'] or (
        len(draw['front']) >= 5 and len(draw['back']) >= 2
    ):
        return (True, draw)

Technical Analysis

The application downloads HTML from several external sources, including third-party lottery websites, and treats it as untrusted input. Some parser fallbacks search an entire page for generic two-digit values or table cells and then interpret the first seven matches as lottery numbers. These matches are not necessarily located in the lottery-result section and may instead represent dates, navigation content, advertisements, prices, or attacker-controlled page content.

The acceptance condition does not implement the validation strategy documented in references/data_sources.md. It accepts a parsed response if either an issue number exists or enough number str ...[truncated 2162 chars]

Remediation
View remediation

Remediation Suggestions

  1. Implement a central validation function and call it before returning success:

    • Require a correctly formatted issue identifier.
    • Require exactly five unique front-area numbers in the range 1–35.
    • Require exactly two unique back-area numbers in the range 1–12.
    • Reject non-numeric, duplicate, missing, and out-of-range values.
  2. When a specific issue is requested, require the parsed issue to equal the requested issue. Do not report a list page's latest draw as the requested historical draw.

  3. Replace page-wide numeric fallbacks with source-specific parsing scoped to a single draw-result container. Reject the response if the expected container or schema cannot be identified reliably.

  4. Change the success condition so an issue number alone is never sufficient. Require a complete, validated draw record:

python
def validate_draw(draw, requested_issue=None):
    issue = draw.get('issue', '')
    front = draw.get('front', [])
    back = draw.get('back', [])

    if not re.fullmatch(r'\d{7,8}', issue):
        return False
    if requested_issue and issue != requested_issue:
        return False
    if len(front) != 5 or len(set(front)) != 5:
        return False
    if len(back) != 2 or len(set(back)) != 2:
        return False

    try:
        front_values = [int(value) for value in front]
        back_values = [int(value) for value in back]
    except ValueError:
        return False

    return (
        all(1 &lt;= value &lt;= 35 for value in front_values)
        and all(1 &lt;= value &lt;= 12 for value in back_values)
    )
  1. For third-party results, obtain matching data from a second independent source before presenting the result as verified. If agreement cannot be established, clearly mark the result as unverified or fail safely.

  2. Add unit tests covering advertisements before result tables, duplicate values, out-of-range values, issue-only responses, mismatched requested issues, truncated pages, and c ...[truncated 19 chars]

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
python scripts/dlt_lottery.py

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
python scripts/dlt_lottery.py

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

md
python scripts/dlt_lottery.py

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest description and core instructions are written entirely in Chinese and define usage in Chinese-only terms, but do not state that the skill is region-specific or offer language/locale opt-in. Under the policy, forcing a specific language without user choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This markdown file presents all instructions and guidance exclusively in Chinese, with no user opt-in or alternative language option, which can be interpreted as forcing a specific language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Accept-Language header is fixed to 'zh-CN,zh;q=0.9,en;q=0.8', which imposes a specific locale preference in network interactions. The file does not provide a user opt-in, configuration option, or region-specific justification for this language/locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This file presents its description and runtime output entirely in Chinese, including usage context and user-facing messages. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.