Back to skill

Security audit

Bing CN Search

Security checks for vulnerabilities and agentic risk

Overview

This Bing CN search skill is purpose-aligned, but users should be aware it installs unpinned npm software and may trigger web searches on broad Chinese terms.

Install only if you are comfortable running unpinned npm packages and registering a persistent MCP server. Prefer pinning reviewed package versions, avoiding elevated privileges, and using the skill only for explicit current-information searches where Bing CN results are appropriate.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party npm Packages Are Installed and Executed

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger list is broad and includes common conversational terms like '搜索', '最新', and '网上', which can cause the skill to activate in many contexts beyond explicit web-search requests. This can lead to unintended tool use, unnecessary external queries, and retrieval of untrusted internet content when the user did not clearly request it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill hardcodes use of Bing CN and frames the search experience around a single Chinese-language/locale context without user choice. This can bias results by region or language, potentially returning incomplete or jurisdiction-specific information that is unsuitable for the user's actual needs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation guidance describes examples of when to trigger but does not define clear boundaries for when not to trigger, leaving room for inconsistent or over-eager activation. In an agent setting, ambiguous dispatch rules increase the chance of external search being used for ordinary queries that should be answered locally or with clarification.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
90% confidence
Finding

The trigger term '新闻' is extremely short and commonly appears in normal conversation, making accidental activation likely. Even low-friction unintended activation matters here because the skill performs external searches and may introduce untrusted content into the response flow.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
92% confidence
Finding

The trigger term '最新' is too generic to safely indicate a desire for web search, since users may use it in many contexts unrelated to internet lookup. This raises the risk of the skill activating on ambiguous requests and unnecessarily querying external sources.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
95% confidence
Finding

The trigger '搜索' is a common verb that may appear in instructions, examples, or metadiscussion, so matching it alone is overly permissive. That can cause the skill to hijack unrelated turns and invoke external search when the user did not intend a web lookup.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
89% confidence
Finding

The trigger '网上' is broad and frequently used in casual discussion, not only in search requests. Its inclusion makes activation prone to false positives, increasing unnecessary exposure to external content and inconsistent agent behavior.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
87% confidence
Finding

The trigger '时事' is short and semantically broad, so it can match topical discussion without a request to perform search. In this skill's context, that can still lead to unintended network access and presentation of potentially unreliable search summaries.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
87% confidence
Finding

The term '热点' is commonly used in everyday conversation and does not unambiguously signal a web-search action. As a standalone trigger it increases accidental activation and can pull in external information without sufficient user intent.

Content

No source excerpt is available for this finding.

Overly Broad Trigger

Low
Category
Trigger Abuse
Confidence
88% confidence
Finding

The trigger '热搜' is short and may appear in references to social trends without constituting a request to search. Because the skill uses external web tooling, this ambiguity can cause unnecessary tool invocation and lower trust in agent routing behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.