Back to skill

Security audit

Kura Sushi Booking (E-Pai-Ke)

Security checks for vulnerabilities and agentic risk

Overview

This restaurant-booking skill is mostly purpose-aligned, but it handles saved login credentials and can confirm reservation cancellations without an explicit user approval step.

Install only if you are comfortable with an agent using your E-Pai-Ke account. Keep credentials out of plain notes where possible, avoid screenshots or logs during login, and require the agent to confirm the exact reservation details with you before booking or cancelling anything.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs storing account credentials in a notes file and then injecting them into the login page via browser-side JavaScript, but it provides no safeguards about secret handling, scope limitation, or confirmation before use. In an agent setting, this increases the chance of credential exposure through logs, screenshots, prompt context, or misuse of saved secrets during automated browsing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill gives direct instructions for canceling an existing reservation, including clicking the final confirmation, without requiring an explicit destructive-action warning or user confirmation gate. In an automation context, this can lead to accidental or unauthorized cancellation of real bookings, causing service disruption or loss of reservations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The natural-language instructions and UI references are entirely in Traditional Chinese and do not indicate that another language can be used or that the locale is optional. The policy asks to flag language or locale constraints when a specific language is effectively forced without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.