Back to skill

Security audit

sticker

Security checks for vulnerabilities and agentic risk

Overview

This sticker skill is not destructive, but it broadly auto-activates and sends conversation-derived sticker searches to a third-party service with unvalidated media URLs.

Install only if you are comfortable with an always-on chat sticker behavior that may contact a third-party sticker API during ordinary emotional or casual messages. Prefer a version that requires explicit sticker requests or consent for external lookups and validates returned media URLs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:44
Finding

Unvalidated Third-Party Sticker Retrieval Can Leak Context and Load Attacker-Controlled URLs

Content
View full analysis
``` ### Technical Analysis The skill sends a keyword inferred from the current conversation to the third-party domain `api.tangdouz.com`. Because the skill is configured to activate broadly and choose keywords from conversational context, use of the skill discloses context-derived information to an external service without an explicit consent or privacy check. The API response is treated as trusted. In particular, the returned `thumbSrc` field is directly passed to the media-rendering mechanism without validation of: - URL scheme - Destination hostname - Redirect destination - Resolved IP address - Response content type - Response size - Whether the destination belongs to an approved image CDN The effective media destination is therefore controlled by the remote API operator or by an attacker who compromises that service. Depending on how the host platform resolves and renders `MEDIA` URLs, this may result in server-side or client-side requests to attacker-selected destinations. A malicious image URL can also act as a tracking beacon and expose request metadata such as IP address, timestamp, user agent, or referrer information. If the media subsystem performs backend fetching and lacks independent network restrictions, a malicious `thumbSrc` could potentially target loopback, link-local, private-network, or cloud metadata addresses. This latter impact depends on the implementation of the surrounding media renderer and is not established by th ...[truncated 1392 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger list is extremely broad and includes common greetings, gratitude, praise, complaints, and general emotional language, while the skill is marked always: true. That makes accidental activation highly likely and can cause the assistant to send stickers in many contexts where the user did not request them, creating unwanted behavior and increasing the chance of unnecessary downstream API use.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Instructions like '默认发表情' and '拿不准就发' remove meaningful boundaries on when the skill should act. Subjective, permissive activation criteria make behavior unpredictable and can override normal conversational appropriateness, especially in mixed-use chats where emotional language appears incidentally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description and trigger list are entirely Chinese-centric, and the skill behavior is framed around Chinese phrases and sticker search terms. There is no opt-in, user choice, or documented reason that the skill should operate only in Chinese, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Telling the agent to act whenever it 'feels' a sticker should be sent delegates invocation to intuition rather than enforceable policy. This weakens control surfaces and makes the skill prone to over-activation, though the direct security impact is lower than data-handling issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs sending conversation-derived keywords to a third-party API without user notice or consent. Even if only a keyword is transmitted, it is still derived from user content and emotional context, which creates a privacy risk and an undisclosed external data flow.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill contains an explicit instruction to contact an external domain and retrieve content for display in the conversation. This creates supply-chain and privacy exposure: user-derived context influences an external request, and the returned image URL is then surfaced back to the user without validation or trust guarantees.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

用 curl 调用表情包 API:

bash
curl -s -m 5 "https://api.tangdouz.com/a/biaoq.php?return=json&nr=关键词"

响应为 JSON 数组,每个元素含 thumbSrc(图片 URL)。从结果中随机选一张,用 MEDIA token 发送图片:MEDIA: thumbSrc的值,然后另起一行写文字回复。

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This line explicitly directs the agent to choose any fitting Chinese keyword, which bakes a single-language behavior into the skill. Because no user opt-in or locale justification is provided, the instruction can be read as an organizational language-policy violation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.privileged_always

Skill is configured with always=true (persistent invocation).

Warn
Code
suspicious.privileged_always
Location
SKILL.md:1