Back to skill

Security audit

DiDi Ride SKILL

Security checks for vulnerabilities and agentic risk

Overview

This ride-hailing skill is coherent with its DiDi purpose, but it asks for persistent credentials and can create real ride orders and background tasks with too little final user control.

Review before installing. Only use this if you are comfortable giving the skill a DiDi MCP key, letting it persist that key, storing ride preferences locally, and allowing it to create ride orders and scheduled background tasks. Prefer a secure key setup path, rotate any key pasted into chat or logs, and require explicit confirmation before any ride is dispatched or scheduled.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:237
Finding

Shell Command Injection Through Unsafe Cron Command Construction

Content
View full analysis
" \ --session isolated \ --message "执行定时打车:起点「」,终点「」,车型「」。请完整执行打车流程:地址解析 → 价格预估(获取最新 traceId)→ 创建订单。订单创建成功后,输出订单信息并提示用户可发送「查询订单」了解订单状态,同时创建 5 分钟后自动回查 cron(模板见 SKILL.md 第 3.8 节「发单后自动回查」)。" \ --announce \ --channel \ --to "" ``` The same pattern is used for automatic order checks: ```bash openclaw cron add \ --name "didi-ride-skill:check:" \ --at "5m" \ --session isolated \ --message "查询滴滴订单状态:订单号 。调用 taxi_query_order 查询并输出当前状态。如果司机已接单,输出司机姓名、车型、车牌、电话及预计到达时间;如果仍在匹配中,提示用户耐心等待。" \ --announce \ --channel \ --to "" ``` ### Technical Analysis The instructions require placeholders such as `FROM_NAME`, `TO_NAME`, `VEHICLE`, `ORDER_ID`, `CHANNEL_NAME`, and `CHAT_ID` to be replaced with actual values before executing a shell command. Several of these values can originate from user input, external API results, or session metadata. The values are interpolated directly into shell syntax without an allowlist or shell-safe argument encoding. Double quotes do not make a command safe when the Agent constructs the final command text by inserting attacker-controlled shell metacharacters. For example, if a location is inserted as `Station $(attacker_command)`, the generated command contains active command-substitution syntax that the shell can evaluate. Characters such as command substitutions, backticks, embedded quotes, newlines, redirection operators, and argument separators may therefore alter the intended command. The scheduled task message can also be modified to inject unintended instructions into the ...[truncated 1387 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
README.en.md:132
Finding

MCP Credential Exposure Through URLs, Process Arguments, and Terminal Output

Content
View full analysis
--args '{"key":"value"}' ``` ### Technical Analysis The MCP key is embedded in the URL query string. The complete URL is then supplied to `mcporter` as a process argument. Secrets in URLs can be exposed through: - Process listings and process-monitoring utilities. - Shell tracing and terminal-session capture. - Debug output, crash reports, and diagnostic logs. - Proxy, gateway, and HTTP access logs that retain query strings. - Command histories if the expanded URL is copied or executed directly. The README also instructs users to run `echo $DIDI_MCP_KEY`, which prints the complete secret to the terminal. This can expose it through screen sharing, transcript capture, CI logs, or shell-session recording. Although HTTPS protects the URL in transit from passive network observers, it does not prevent local process inspection or logging by endpoints that receive or record the request URL. ### Attack Path 1. The user configures `DIDI_MCP_KEY` and invokes the documented command. 2. The shell expands the secret into the MCP URL. 3. The resulting URL is passed in the `mcporter` process argument list and may be recorded by local monitoring or diagnostics. 4. Alternatively, the user follows the verification inst ...[truncated 937 chars]
Remediation
View remediation
``` 3. Ensure the client accepts the credential through a protected environment variable, file descriptor, or credential store without placing it in the process argument list. 4. Replace `echo $DIDI_MCP_KEY` with a presence-only check that does not reveal the value: ```bash if [ -n "${DIDI_MCP_KEY:-}" ]; then echo "DIDI_MCP_KEY is configured" else echo "DIDI_MCP_KEY is not configured" fi ``` 5. Configure HTTP servers, proxies, gateways, and observability platforms to redact query parameters until URL-based authentication is removed. 6. Rotate any key that may have appeared in terminal transcripts or logs. 7. Add secret-scanning and logging tests to verify that the credential never appears in command output, process arguments, or request logs. ]]>

T08 · Insecure Dependencies

Warning
Location
references/setup.md:7
Finding

Unpinned Global Installation of a Third-Party Dependency

Content
View full analysis
Remediation
View remediation
``` 2. Record and verify the expected package integrity hash. 3. Document the verified npm publisher, repository, and release provenance. 4. Prefer a project-local dependency with a committed lockfile instead of a global installation. 5. Install with lifecycle scripts disabled where compatible: ```bash npm install --ignore-scripts --save-exact mcporter@ ``` 6. If lifecycle scripts are required, audit them before installation and execute installation in a restricted environment. 7. Use package signing or provenance verification when supported by the distribution channel. 8. Regularly scan the pinned release and update only after reviewing and testing the new version. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (35)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README states that a future ride request will be automatically initiated at the scheduled time, which is a deferred real-world transaction with financial and physical-world consequences. Without a prominent warning and explicit confirmation at scheduling time, users may unintentionally authorize autonomous order placement they do not expect later.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger policy is extremely broad and marked with always-on behavior, causing the skill to activate for ordinary travel-related language even when the user may not intend to use DiDi. In a transportation skill, this increases the chance of unnecessary data collection, unintended third-party tool use, and accidental order-related actions being routed through an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly tells users to paste their MCP Key into chat, which exposes a credential through the conversation channel and then persists it for later use. Credentials shared in chat may be retained in logs, transcripts, or downstream systems, making compromise more likely if the chat environment is not treated as a secret-management channel.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
| `SKILL.md` | 触发、主流程、硬性门禁、查询订单规则、预约出行规则 | 每次触发必读 |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
| `references/workflow.md` | 分阶段详细流程与命令范式 | 需要实现细节时读 |

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · references/error_handling.md (reported line 55)May include surrounding context.

  1. 自检环境变量是否注入:

    bash
    printenv DIDI_MCP_KEY >/dev/null && echo env_ok || echo env_missing
    
  2. 若 env_ok:把 URL 拼接改回 SKILL.md §3.2 第 4 条的固定写法,不要再尝试从 config 提取 Key:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The reservation flow schedules an isolated cron job that will later execute the full ride-ordering workflow, including creating a real taxi order, but the documentation does not require a strong warning that this is a deferred autonomous action. In a transportation skill, this is especially sensitive because it can commit the user to a real booking, potential charges, and location disclosure at a later time without a fresh confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README tells users to paste their MCP KEY directly into chat, which risks exposing a secret to the model, chat history, logs, telemetry, screenshots, or other downstream processors. Credentials provided through conversational text are harder to scope, rotate, and protect than environment or config-based secret handling.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The workflow states that no confirmation is needed when the system believes the user specified a precise match, allowing the assistant to autonomously proceed toward a real-world booking flow. In a transportation skill, address precision does not eliminate the need for consent because booking still has external consequences and may expose location or cause charges.

Content

Scanner excerpt · README.en.md (reported line 193)May include surrounding context.

md
│  Step 2: Confirm origin/destination                             │
│  - Confirm with user when address was inferred or multiple      │
│    candidates were returned                                     │
│  - No confirmation needed when user specified a precise match   │
└──────────────────────────┬──────────────────────────────────────┘
                           │
                           ▼

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README describes automatic cron-based follow-up checks and push notifications after ride creation, which expands behavior beyond a simple on-demand transportation invocation into persistent background activity. That creates an unexpected capability for continued monitoring and unsolicited actions, especially because the document does not clearly bound consent, retention, or task lifecycle.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README documents automatic scheduled checks and pushed notifications without clearly warning that the skill may create background tasks and continue monitoring an order after the initial request. This undermines informed consent and can surprise users with ongoing processing of location/order data beyond the live session.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The confirmation policy says instant rides can be dispatched without confirmation and scheduled rides can be created directly, despite these being real-world transactions that may incur charges or trigger driver dispatch. An assistant acting on a natural-language request without explicit final consent increases the risk of accidental bookings, financial loss, and unwanted location disclosure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
98% confidence
Finding

The policy explicitly permits instant ride dispatch with no confirmation and scheduled ride creation directly, which is autonomous decision-making tied to a physical-world, chargeable action. In this context, the skill is more dangerous because it controls transportation orders, timing, and associated personal location data, so mistaken or manipulated prompts can cause immediate real-world harm or expense.

Content

Scanner excerpt · README.en.md (reported line 247)May include surrounding context.

md
| Action | Confirmation |
|--------|-------------|
| Instant ride | No confirmation needed — dispatches using user-specified or preferred vehicle type |
| Scheduled ride | Creates cron task directly; dispatches at scheduled time |
| Cancel order | Show order details → wait for explicit user confirmation |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The quick-start flow tells users to paste their MCP key into chat without warning that it is a credential or explaining storage and logging risks. Secrets shared in chat may be retained in conversation history, telemetry, screenshots, or copied into persistent config, making accidental disclosure more likely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example normalizes sharing a secret API/MCP key in plain conversation, which can lead users to expose credentials in an insecure channel. In a skill that can place ride-related requests and access account-linked services, compromised credentials could enable misuse of travel APIs or unauthorized account actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README advertises automatic cron task creation and delayed order-status polling/push behavior, which introduces autonomous background actions not clearly scoped to an immediate user-request/response travel tool. Background execution increases the risk of actions occurring after the user disengages and can surprise users with ongoing processing or notifications.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README instructs users to provide an MCP key directly in chat and states that the AI will persist it automatically. Persisting a credential is a sensitive data handling behavior that extends beyond the core transportation workflow and increases the chance of secret exposure through logs, prompt history, or local configuration files.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Telling users to submit the MCP key in chat so the AI can store it persistently is an unsafe secret-handling pattern. It combines credential disclosure with persistence, increasing the attack surface through chat retention, local plaintext storage, and unintended reuse by the skill or platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation says the skill will automatically create a delayed follow-up task and later push notifications, but it does not present this as a separate consented background action. Users may not realize that the system will continue operating on their behalf after the initial request, which can create privacy and autonomy concerns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description is written as a mandatory China-city travel skill and defines triggers and behavior entirely in Chinese, but it does not state that the locale restriction is intentional or give users a language/locale choice. This can violate language/locale policy when a skill effectively forces one language without opt-in or justification.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to solicit a user credential from chat and then persist it into configuration and environment variables, creating a risky secret-handling pattern. While persistence itself can be legitimate, using chat as the collection channel and normalizing automated secret reuse increases exposure through chat logs, shell history, process inspection, or accidental reuse in unrelated contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill stores personal preferences and a phone number in a local markdown file for future reuse without presenting a clear user-facing retention, sensitivity, or deletion notice. In the context of a ride-booking skill, this creates privacy risk because addresses like home/work and a phone number are persistent identifiers that can expose movement patterns and identity if the file is accessed or synced.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs the agent to collect and reuse a phone number from a preference file, which is personal data tied to future ride orders. In this context, combining a phone number with saved locations and ride behavior can materially increase privacy harm if retained without strong consent, protection, and lifecycle controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes state-changing ride-order functions and sensitive driver-location/order-query capabilities without requiring explicit user confirmation, authorization checks, or any warning about privacy and real-world consequences. In a transportation skill, these APIs can trigger unwanted bookings, cancellations, or reveal live location and driver details if an agent invokes them too freely or on the wrong account context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entire document is written in Chinese and includes fixed Chinese output text for users, but it does not indicate that the skill is China-specific or that users may choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.