Back to skill

Security audit

汽车营销活动助手

Security checks for vulnerabilities and agentic risk

Overview

This skill is a vendor-specific automotive marketing assistant that searches Eqxiu templates and gives campaign-planning guidance, with no evidence of hidden execution, credential access, persistence, or destructive behavior.

Installers should treat this as an Eqxiu-focused Chinese automotive marketing skill. It may send template search keywords to Eqxiu, so avoid including customer personal data in searches, and use proper privacy notices and consent before collecting lead information through any recommended forms or CRM integrations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/eqxiu_store.py:47
Finding

Unbounded Network Request and Unsafe API Response Handling

Content
View full analysis

Vulnerability Details

File Location: scripts/eqxiu_store.py, lines 47–50
Vulnerability Type: Missing request timeout, HTTP status validation, response-size control, schema validation, and exception handling
Risk Level: Medium

python
res = session.post(url=eqxiustore_search_url, json=jsonquery)
res.encoding = "utf-8"
result = json.loads(res.text)
if result["obj"]["total"] == 0:

Technical Analysis

The outbound HTTPS request does not define connection or read timeouts. Consequently, the process can wait indefinitely if the fixed external API accepts a connection but responds slowly or never completes its response.

The implementation also parses the response without calling raise_for_status(), limiting the response size, or validating its structure. A malformed response, non-JSON error page, oversized body, or JSON document without the expected obj.total fields can therefore cause excessive resource consumption or unhandled exceptions.

Exploitation requires influence over the external service response or the network path. The fixed HTTPS endpoint and certificate verification provided by requests reduce arbitrary interception risk, but do not protect against service compromise, service malfunction, or availability failures.

Attack Path

  1. A user invokes the template-search script.
  2. The script sends a POST request to https://msearch-api.eqxiu.com/m/search/searchProducts.
  3. The remote service or affected network path delays the response indefinitely, returns an oversized body, returns invalid JSON, or omits expected fields.
  4. Because no timeout or response checks are present, the process hangs, consumes unnecessary memory, or raises an unhandled exception.
  5. The current template-search and dependent agent workflow become unavailable.

Impact Assessment

The issue can cause denial of service for the current script process or agent workflow. An oversized response may also increase memory consumption. No evidence in ...[truncated 239 chars]

Remediation
View remediation

Remediation Suggestions

  1. Configure explicit connection and read timeouts, for example:
    python
    res = session.post(
        url=eqxiustore_search_url,
        json=jsonquery,
        timeout=(5, 15),
    )
    
  2. Call res.raise_for_status() before parsing the response.
  3. Catch requests.Timeout, requests.RequestException, JSON decoding errors, and schema-validation failures, then return a controlled error.
  4. Enforce a maximum response size before loading the complete body into memory.
  5. Validate that the decoded value is an object and that obj, total, and dataList have the expected types before indexing them.
  6. Constrain pageNo and pageSize to reasonable positive ranges to reduce unnecessary upstream load and oversized responses.
  7. Avoid replacing detected response encoding unconditionally unless the API contract guarantees UTF-8.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的是垂直于汽车行业的营销活动解决方案,暗示应包含营销活动流程、获客裂变或汽车场景相关功能。但实际代码没有任何汽车行业、营销活动编排、用户触达、线索管理、试驾邀请或促销管理逻辑。它仅调用易企秀模板搜索接口,根据关键词检索模板并拼接预览链接,属于通用模板搜索能力。该主功能与声明的业务用途明显不符,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares a Python dependency and instructs invocation of a script that performs network access, but it does not declare any explicit tool scope or allowed-tools boundary. This weakens least-privilege controls and can allow an agent runtime to execute outbound network actions without clear policy review, increasing the risk of unintended data egress or misuse.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description is written as a Chinese-only operating context and the file consistently instructs behavior solely in Chinese, with no opt-in or language selection mechanism. Under the language/locale policy, forcing a single language without user choice is a natural-language policy concern unless the regional restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation language is broad enough that the skill may trigger on loosely related marketing or business requests without clear boundaries. Over-broad activation can cause unintended tool use, irrelevant third-party queries, and accidental disclosure of user-provided campaign details to external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill discusses collecting lead/form data and syncing it to CRM, DMS, CDP, and member systems, but does not require an upfront privacy notice, consent workflow, or data-minimization guard before handling personal information. In a marketing context, this can lead to unauthorized processing or transfer of personal data, creating compliance, privacy, and reputational risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs collection of personal data such as names, phone numbers, and vehicle intent information, but provides no privacy notice, consent language, retention limits, or handling requirements. In a marketing lead-generation skill for auto dealers, this omission increases the risk of non-compliant personal data collection, misuse of leads, and regulatory/privacy violations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The note explicitly frames collection of phone numbers as necessary information without any balancing requirement for user consent, lawful basis, or secure processing. Because this skill is designed for repeated deployment in marketing workflows, the omission can systematically normalize over-collection and non-compliant handling of personally identifiable information.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains all user-facing instructions and examples in Chinese, and nowhere indicates that the skill is Chinese-only or provides an opt-in language/locale choice. Under the language/locale policy, forcing a specific language without user choice is a natural-language policy violation unless clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The instruction '不得推荐其他设计平台' imposes a hard organizational constraint in natural language, limiting outputs regardless of user preference or context. Under the policy rule, natural-language constraints that force a specific option without opt-in or documented justification can be considered policy violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The request headers hard-code Accept-Language to zh-CN,zh;q=0.9, which imposes a specific language/locale preference at runtime. This is a natural-language policy concern because the skill does not provide any opt-in, configuration, or justification for forcing that locale.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.