Back to skill

Security audit

诉讼费计算

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent legal-fee purpose, but it asks agents to run a mutable third-party CLI and send sensitive case details to an external backend with limited safeguards.

Review this skill before installing. Use it only if you trust the `@delilegal/deli-cli` package and backend service, are comfortable sending fee-calculation facts to that service, and can avoid entering names, IDs, case numbers, addresses, or unrelated confidential details. Prefer a pinned CLI version and safer API-key entry/storage before routine use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Error
Location
references/cli-common.md:10
Finding

Mutable Package Execution Through npx Using the latest Tag

Content
View full analysis
" ``` From `references/cli-common.md:37-40`: ```bash npx @delilegal/deli-cli@latest cmds litigation-fee-calculator@1.0.0 ``` From `references/cli-litigation-fee-guide.md:18-20`: ```bash npx @delilegal/deli-cli@latest run_a1b2c3d4e5f6 calculate --long-text "Property case with a claim amount of CNY 1.5 million; calculate the case acceptance fee and return a segmented breakdown" npx @delilegal/deli-cli@latest run_a1b2c3d4e5f6 estimate --long-text "Divorce case involving property division of CNY 2.5 million; no local base-fee standard was provided, so estimate using the statutory lower bound" npx @delilegal/deli-cli@latest run_a1b2c3d4e5f6 fee-calc --long-text "Apply for property preservation involving CNY 1.2 million; calculate the application fee and determine whether the CNY 5,000 cap applies" ``` ### Technical Analysis The Skill repeatedly directs the Agent to execute `@delilegal/deli-cli@latest` through `npx`. When the package is not already available locally, `npx` may retrieve it from the configured package registry and execute its package code immediately. The `latest` tag is mutable and does not identify an immutable, previously audited release. The repository does not pin an exact dependency version, provide a lockfile or integrity hash, or require verification of the package source before execution. Consequently, the code that ultimately runs can change without any modification to this Skill package. Package lifecycle scripts may also execute during installation unless separately restricte ...[truncated 1498 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/cli-common.md:14
Finding

API Key Exposed Through Command-Line Arguments

Content
View full analysis
" ``` ### Technical Analysis The documented initialization procedure passes the user's API key directly as a command-line argument. Command-line secrets can be exposed through several operating-system and operational channels: - Shell command history. - Process listings and process-inspection interfaces while the command runs. - Terminal session recording. - CI/CD or Agent execution logs. - Error reports, debugging traces, or telemetry that records command arguments. - Wrapper processes that capture the invoked command line. Quoting the key protects shell parsing but does not conceal the value from these channels. The Skill states that the resulting CLI configuration is stored under `~/.deli/cli/config.json`, but the reviewed instructions do not specify secure file permissions or otherwise mitigate the initial exposure through the argument list. ### Attack Path 1. A user creates an API key and follows the documented initialization command. 2. The plaintext key is inserted into the `--apikey` argument. 3. The shell, Agent framework, process monitor, terminal recorder, or automation system records or observes the command line. 4. A local user, log reader, monitoring component, or other party with access to that record obtains the key. 5. The exposed key is used to authenticate to the associated service and consume whatever capabilities and quota the key grants. ### Impact Assessment Exploitation can disclose the user's Deli Legal API credential. An attacker may be able to invoke backend services under the user's account, consume service quota, access functionality authorized to the key, or submit and retrie ...[truncated 255 chars]
Remediation
View remediation

other

Warning
Location
references/cli-litigation-fee-guide.md:18
Finding

Confidential Litigation Facts Are Sent to an External Backend Without a Required Consent or Redaction Step

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (10)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is entirely written to position the skill for Chinese-court fee calculation and only mentions English as compatible search keywords, not as a supported output-language choice. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly documented and justified as a region-specific tool.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs the agent to use npx @delilegal/deli-cli@latest, which pulls and executes whatever package version is current at runtime rather than a reviewed, fixed version. This creates a supply-chain risk: a compromised upstream package, malicious release, or breaking change could alter command behavior, exfiltrate data, or execute unintended code when the skill is invoked.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This repeated instruction again requires runtime execution of npx @delilegal/deli-cli@latest, so the same unpinned dependency risk applies at a second workflow-critical point. Because the skill frames this as the mandatory calculation path, any malicious or unintended upstream package change would directly affect all uses of the skill.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs the agent to execute npx @delilegal/deli-cli@latest check, which fetches and runs the latest package version at execution time rather than a reviewed, immutable release. This creates a supply-chain and time-of-use risk: if the package is compromised or a malicious update is published, the agent could execute attacker-controlled code before performing the requested legal-fee calculation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The command discovery step uses npx @delilegal/deli-cli@latest cmds litigation-fee-calculator@1.0.0, again relying on an unpinned latest package. Because this skill makes the CLI a required pre-step, the unpinned dependency materially increases the chance that a compromised upstream package could alter command output, exfiltrate secrets such as API keys, or execute arbitrary code in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The guide instructs execution of npx @delilegal/deli-cli@latest, which is not a fixed immutable version and will fetch whatever package is current at runtime. If the upstream package is compromised, maliciously updated, or a dependency is hijacked, the agent could execute attacker-controlled code during command discovery, making this a real supply-chain risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This example command again uses npx @delilegal/deli-cli@latest, causing live retrieval and execution of the newest package version rather than a reviewed build. Because the skill explicitly tells the agent to run the tool, the unsafe versioning materially increases the chance of remote code execution via package compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The command sample on this line repeats the same unpinned npx execution pattern, which is dangerous because npx may download and run changed code at execution time. In an agent skill context, repeated normalization of this pattern increases exposure and may cause operators to treat dynamic code execution as routine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This line also instructs npx @delilegal/deli-cli@latest, preserving the same supply-chain execution risk across the skill documentation. The legal-fee-calculator context does not reduce the danger, because the issue is not domain logic but arbitrary package code execution on the host running the agent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The note section instructs how the skill should present results and the entire skill content is written only in Chinese, including output requirements such as citing provisions and showing calculation details. There is no indication that users may choose another language or locale, which can be a natural-language policy concern if organizational policy requires language choice rather than forcing one language by default.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.