Back to skill

Security audit

powpowcity Map Editor

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed city-map editing skill with expected local file edits and optional network sharing/geocoding, with no hidden persistence or deceptive behavior found.

Install only if you are comfortable with a Node.js CLI that edits files in your working directory and may contact mapping/sharing services when those commands are used. Treat `share --short` as uploading the city snapshot, use `--gallery` only for maps you want publicly listed, and consider pinning Playwright if you need reproducible optional screenshot/simulation setup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · cli/lib/vendor/lz-string.js (reported line 191)May include surrounding context.

js
context_enlargeIn = Math.pow(2, context_numBits);
            context_numBits++;
          }
          delete context_dictionaryToCreate[context_w];
        } else {
          value = context_dictionary[context_w];
          for (i=0 ; i<context_numBits ; i++) {

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · cli/lib/vendor/lz-string.js (reported line 276)May include surrounding context.

js
context_enlargeIn = Math.pow(2, context_numBits);
            context_numBits++;
          }
          delete context_dictionaryToCreate[context_w];
        } else {
          value = context_dictionary[context_w];
          for (i=0 ; i<context_numBits ; i++) {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documents use of environment variables such as BAIDU_MAP_AK, POWPOWCITY_API_BASE, and POWPOWCITY_ANON_KEY, but it does not declare an explicit tool scope or permissions boundary. In an agent setting, undeclared environment access can cause overbroad secret exposure or make the agent use sensitive host configuration without clear authorization.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The main skill instructions and trigger guidance are written entirely in Chinese, including the directive about when to use the skill. This creates a language/locale constraint in the skill’s natural-language interface without documenting user choice or a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The instructions tell users to run 'npx playwright' without pinning a specific version. This creates a supply-chain risk because the resolved package version can change over time, potentially introducing malicious or incompatible code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

This line again directs use of 'npx playwright' without a pinned version, exposing the same package-resolution and supply-chain risk. Repeated unpinned install guidance increases the chance that agents or users will execute non-reproducible dependency installation from the network.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · cli/lib/baidu.mjs (reported line 8)May include surrounding context.

js
import { pathToFileURL } from 'node:url';

const GEOCODE_URL = 'https://api.map.baidu.com/geocoding/v3/';

const PI = Math.PI;
const X_PI = (PI * 3000.0) / 180.0;

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The money formatter hard-codes 'en-US', which forces US-style number formatting in user-visible output regardless of the user's locale or preferences. This is a natural-language/locale policy concern because the tool does not offer any opt-in or configuration for alternative locales.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Nominatim request hard-codes Accept-Language: 'en', which forces a specific language for results regardless of user preference or environment. This is a natural-language policy concern because the skill does not offer any language choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file formats currency and population/job counts using toLocaleString('en-US'), which forces a specific locale in user-visible output. The policy allows locale constraints only when users are given a choice or when the restriction is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
cli/lib/shortlink.mjs:137