Back to skill

Security audit

cn-holiday

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese holiday lookup tool that sends date queries to a disclosed public API.

Install this if you are comfortable with holiday queries being sent to timor.tech. The skill does not need an API key and does not show signs of persistence or local data access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
2. Run `bun scripts/holiday.ts --help` in this skill directory.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill invokes a network-backed script and external API, but the manifest does not declare any tool scope or allowed-tools boundaries. This creates a least-privilege and transparency problem: the runtime may permit broader capabilities than users or reviewers expect, and external requests can expose queried dates or user-derived inputs to a third party.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises trigger words such as "上班", "放假", and a catch-all pattern of any "[日期] 是否放假/上班" input. These phrases are broad everyday expressions and the file does not provide exclusion conditions or narrower context, which could cause unintended invocation outside a clearly bounded holiday-query context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code constructs a URL with caller-supplied query parameters and sends it over the network via fetch, which can transmit user or system data to an external service. In this file there is no confirmation prompt, print/log statement, or comment/docstring disclosing that outbound network transmission occurs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.