Back to skill

Security audit

Life Query

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but users should understand that its lookups send query details to external services and its docs use unpinned install/update commands.

Install only if you are comfortable sending parcel numbers, city names, currency inputs, and province queries to the disclosed external services. For better privacy, configure your own Kuaidi100 credentials to avoid the free parcel proxy, and prefer a pinned ClawHub installer/update version instead of copying @latest commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:33
Finding

Unpinned npm Package Execution During Installation and Updates

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a constrained daily-life query assistant, but the documented interface includes bash {baseDir}/scripts/run.sh call <接口名> and even list, implying the agent can enumerate and invoke locally available shell-backed interfaces beyond the narrowly described user functions. If run.sh accepts arbitrary interface names, this expands capability from fixed queries to generic local script execution, which can expose unintended functionality or privileged operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill is presented as a constrained daily-life query assistant, but the documented interface includes bash {baseDir}/scripts/run.sh call <接口名> and even list, implying the agent can enumerate and invoke locally available shell-backed interfaces beyond the narrowly described user functions. If run.sh accepts arbitrary interface names, this expands capability from fixed queries to generic local script execution, which can expose unintended functionality or privileged operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a constrained daily-life query assistant, but the documented interface includes bash {baseDir}/scripts/run.sh call <接口名> and even list, implying the agent can enumerate and invoke locally available shell-backed interfaces beyond the narrowly described user functions. If run.sh accepts arbitrary interface names, this expands capability from fixed queries to generic local script execution, which can expose unintended functionality or privileged operations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill is a shell script that executes shell commands such as curl, python3, md5sum/awk, but this capability is not covered by declared permissions. Missing shell permission declarations create a governance gap: reviewers and users cannot accurately assess what execution powers the skill has.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill is a shell script that executes shell commands such as curl, python3, md5sum/awk, but this capability is not covered by declared permissions. Missing shell permission declarations create a governance gap: reviewers and users cannot accurately assess what execution powers the skill has.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/exchange-rate.sh (reported line 40)May include surrounding context.

sh
[[ -n "$AMOUNT" ]] && PARAMS="${PARAMS}&amount=${AMOUNT}"
[[ -n "$PARAMS" ]] && URL="${URL}?${PARAMS:1}"

RESP=$(curl -sf "$URL")

if [[ "$FORMAT" == "table" ]]; then
  echo "$RESP" | python3 -c "

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/oil-price.sh (reported line 45)May include surrounding context.

sh
CURL_ARGS+=(--data-urlencode "filter=(CITYNAME=\"${CITY}\")")
fi

RESP=$(curl "${CURL_ARGS[@]}")

# 检查返回
SUCCESS=$(echo "$RESP" | python3 -c "import json,sys;print(json.load(sys.stdin).get('success',False))")

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'file_read' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The script makes outbound network requests with curl to wttr.in, but the finding indicates this capability is not declared in the skill's permissions. Undeclared network access is a real security issue because it bypasses expected trust and review boundaries, even though the destination and purpose here appear aligned with the weather functionality rather than malicious exfiltration.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The README instructs users to run npx clawhub@latest install life-query, which fetches and executes the latest published package version at install time. This creates a supply-chain risk: if the package is compromised or a breaking/malicious release is published, users may execute unreviewed code automatically. In the context of an install command, this is more dangerous because readers are likely to copy-paste it directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The README instructs users to run npx clawhub@latest install life-query, which fetches and executes the latest published package version at install time without pinning to a known-good release. If the upstream package is compromised, typosquatted, or publishes a malicious update, users can execute attacker-controlled code simply by following the documentation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad everyday phrases such as weather, fuel, and conversion-related wording that can cause the skill to activate in loosely related conversations. Over-broad routing can send user data to external services unnecessarily or invoke shell-backed tooling when the user did not intend to use this skill, increasing privacy and misuse risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest and operating instructions are written entirely in Chinese and include Chinese-only example phrasing and parameter guidance, without stating that other languages are supported or that Chinese is optional. This can be read as a language constraint without user opt-in, which may violate locale or language-choice policy.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The update instruction uses npx clawhub@latest, which fetches and executes the latest published package version at runtime without pinning. This creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious release is published, users may execute unreviewed code when following the documented update command.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file metadata and all user-facing error/suggestion strings are written in Chinese, with no indication that the user can select another language. This constitutes a natural-language locale constraint that is neither optional nor explicitly justified as region-specific compliance behavior.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/courier-track.sh (reported line 37)May include surrounding context.

sh
SIGN=$(printf '%s' "${PARAM}${KEY}${CUSTOMER}" | md5sum | awk '{print toupper($1)}' 2>/dev/null \
      || printf '%s' "${PARAM}${KEY}${CUSTOMER}" | md5 -q | tr '[:lower:]' '[:upper:]')

  RESP=$(curl -sf --max-time 15 -X POST \
    -d "customer=${CUSTOMER}&sign=${SIGN}&param=${PARAM}" \
    "https://poll.kuaidi100.com/poll/query.do" 2>/dev/null) || {
    echo '{"status":"error","error_type":"api_unavailable","service":"kuaidi100.com","suggestion":"快递100 API 请求失败,请检查网络或凭证是否正确。"}' >&2

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

When first-party credentials are absent, the script silently sends users' tracking numbers and optional carrier codes to api.fenxianglife.com, a third-party proxy not disclosed in the skill metadata. Tracking numbers can reveal purchase activity, sender/recipient relationships, and shipment status, so undisclosed sharing is a privacy and data-governance issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This POST sends user shipment data to a third-party proxy service. In the context of a life-information skill, outbound network access is expected, but using an undisclosed proxy materially increases privacy risk because users may believe the query goes only to the courier service.

Content

Scanner excerpt · scripts/courier-track.sh (reported line 90)May include surrounding context.

sh
print(json.dumps(d))
" "$TRACKING_NUMBER" "${CARRIER_CODE:-}")

  RESP=$(curl -sf --max-time 15 -X POST \
    -H "Content-Type: application/json" \
    -d "$BODY" \
    "https://api.fenxianglife.com/fenxiang-ai-brain/skill/courier/track" 2>/dev/null) || {

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script transmits tracking data to a third-party proxy at execution time without an explicit notice or consent prompt. Because shipment identifiers are user data and may be sensitive in context, silent forwarding undermines informed consent and can violate privacy expectations or platform policy.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The hardcoded fenxianglife.com endpoint confirms shipment data is sent to an additional service outside the named courier provider path. That makes the skill more dangerous than a normal tracking integration because it introduces an extra data processor that is not obvious from the description.

Content

Scanner excerpt · scripts/courier-track.sh (reported line 93)May include surrounding context.

sh
RESP=$(curl -sf --max-time 15 -X POST \
    -H "Content-Type: application/json" \
    -d "$BODY" \
    "https://api.fenxianglife.com/fenxiang-ai-brain/skill/courier/track" 2>/dev/null) || {
    echo '{"status":"error","error_type":"api_unavailable","service":"fenxianglife.com","suggestion":"快递查询服务暂时不可用,请稍后重试。如有自有快递100凭证,可设置 KUAIDI100_KEY 和 KUAIDI100_CUSTOMER 环境变量直连。"}' >&2
    exit 1
  }

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/oil-price.sh (reported line 37)May include surrounding context.

sh
--data-urlencode "pageSize=${PAGE_SIZE}"
  --data-urlencode "pageNumber=${PAGE_NUMBER}"
  --data-urlencode "source=WEB"
  -H "Referer: https://data.eastmoney.com/cjsj/oil_default.html"
  -H "User-Agent: Mozilla/5.0"
)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The show command exposes the full contents of any .sh file in the script directory based solely on a user-supplied name. If additional helper, internal, or accidentally bundled scripts exist there, a user can read source code and embedded secrets or implementation details unrelated to the skill's declared life-query purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The call command executes any .sh file present in the directory with user-controlled arguments, creating a generic execution dispatcher rather than a narrowly scoped life-information query tool. If an unexpected or unsafe script is present, this expands the skill's effective capabilities and could enable unintended actions beyond the declared permissions and user expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script description and multiple user-facing outputs are written exclusively in Chinese, and the skill provides no option for users to select another language. This creates a language/locale policy issue because the skill implicitly forces one language without user opt-in or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README advertises parcel tracking and weather lookup features that transmit user-provided tracking numbers and city/location queries to third-party services, but it does not clearly warn users that their inputs will leave the local environment. While this is not code execution, it is a privacy/transparency issue because sensitive logistics identifiers or location-related queries may be shared with external providers without informed consent. The skill context increases relevance because these features are core functionality and likely to be used with real personal data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.