Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md 2. Run `bun scripts/holiday.ts --help` in this skill directory.
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Chinese holiday lookup tool that sends date queries to a disclosed public API.
Install this if you are comfortable with holiday queries being sent to timor.tech. The skill does not need an API key and does not show signs of persistence or local data access.
Referenced artifact was not completely inspected
2. Run `bun scripts/holiday.ts --help` in this skill directory.
The skill invokes a network-backed script and external API, but the manifest does not declare any tool scope or allowed-tools boundaries. This creates a least-privilege and transparency problem: the runtime may permit broader capabilities than users or reviewers expect, and external requests can expose queried dates or user-derived inputs to a third party.
The skill advertises trigger words such as "上班", "放假", and a catch-all pattern of any "[日期] 是否放假/上班" input. These phrases are broad everyday expressions and the file does not provide exclusion conditions or narrower context, which could cause unintended invocation outside a clearly bounded holiday-query context.
This code constructs a URL with caller-supplied query parameters and sends it over the network via fetch, which can transmit user or system data to an external service. In this file there is no confirmation prompt, print/log statement, or comment/docstring disclosing that outbound network transmission occurs.
No suspicious patterns detected.