Back to skill

Security audit

China Id Validator

Security checks for vulnerabilities and agentic risk

Overview

This is a local Chinese ID validator/parser with a documented test-number generator and no evidence of hidden network access, persistence, or data exfiltration.

Install only if you need local validation or parsing of Chinese ID numbers. Treat real ID numbers as sensitive personal data, avoid pasting them into shared terminals or logs, and use the generate command only for clearly synthetic testing because its outputs may look realistic.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code substantially matches the declared validator/parser purpose: it validates mainland Chinese ID numbers and extracts province, birthday, gender, age, and supports 15-to-18 digit conversion. However, it also implements an undeclared capability to generate random valid ID numbers (generate command). That is a materially distinct capability beyond validation/parsing, so this should be flagged as a description-behavior mismatch, even though the main purpose otherwise aligns well.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill handles highly sensitive personal identifier data and extracts personal attributes such as birth date, sex, age, and region, but the documentation does not warn about privacy, retention, masking, or lawful handling requirements. This increases the risk that users will paste real ID numbers into logs, terminals, or shared environments, leading to exposure of regulated personal data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains user-facing strings and documentation entirely in Chinese, including the module docstring, error messages, and CLI usage text. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable issue unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script exposes an undocumented generate mode that creates syntactically valid Chinese ID numbers, which materially expands the skill from validation/parsing into fabrication of identity-like data. In a validator skill, hidden or undocumented generation capability increases misuse risk, reduces operator awareness, and can enable downstream fraud testing or evasion scenarios.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

A validator/parser skill does not need to fabricate random valid-looking national ID numbers, and doing so creates an unnecessary capability that can be repurposed for fraud, account testing, or bypassing weak identity-validation workflows. The context makes this more dangerous because the generated values include plausible province, birthdate, and checksum structure, making them useful as realistic identity artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The file presents core instructions and examples in Chinese, and the usage example requires a Chinese-language value ('男') for generation input. There is no explicit statement that the skill is region- or language-specific, nor any indication that users may choose another language or locale, which can conflict with language/locale policy expectations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description and feature list present the skill as a validator/parser with format conversion, but the usage section also exposes a generate command for creating test ID numbers. Generating IDs is a distinct capability from validation and extraction, even if intended for testing.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
64% confidence
Finding

The documentation says # 验证身份证号 and then shows python3 scripts/id_validator.py 110101199003079, while the next example uses validate with the same 15-digit value under # 提取信息. This creates ambiguous guidance about what the commands do and how validation versus extraction is actually invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.