Back to skill

Security audit

Sushiro Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Sushiro wait-time lookup tool, but it ships a shared upstream bearer token and includes unsafe broad API and filtering behavior that users should review before installing.

Install only if you are comfortable with an unofficial Sushiro China backend integration that sends requests using a bundled shared bearer token. Avoid using the raw command, avoid passing untrusted city or area text into filters, and prefer a version that removes the hardcoded token, allowlists endpoints, and fixes jq argument handling.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sushiro:84
Finding

jq Program Injection Through User-Controlled Store Filters

Content
View full analysis
0))' filter+=' | sort_by(-(.wait // 0))' [[ $limit -gt 0 ]] && filter+=" | .[0:$limit]" if [[ "$format" == json ]]; then echo "$data" | jq "$filter" return fi echo "$data" | jq -r "$filter | ( ``` ### Technical Analysis The `--city` and `--area` arguments are inserted directly into a dynamically constructed jq program. The values are placed between jq string delimiters without escaping and are subsequently passed to `jq` as executable filter source. An attacker can include quote characters, closing parentheses, jq operators, and a comment marker in an argument. This allows the attacker to terminate the intended string and inject an arbitrary jq expression. For example, a malicious city value shaped as: ```text x")) | env # ``` transforms the intended expression into the equivalent of: ```jq . | map(select(.nameKana == "x")) | env # ... ``` The jq `env` built-in exposes the environment inherited by the script. The comment marker suppresses the remaining generated jq expression. Although this issue does not directly provide shell command execution, it allows execution of attacker-selected jq logic and access to data available to the jq process. This is especially relevant when an AI Agent translates untrusted natural-language content into command-line filters. An attacker could place the payload in a requested city or area name and induce the Agent to invoke the vulnerable command. ### Attack Path 1. ...[truncated 1277 chars]
Remediation
View remediation
0)) ) | sort_by(-(.wait // 0)) ' ``` Additional hardening should include: 1. Validate `--limit` as a bounded non-negative integer before using it. 2. Validate `--near` as exactly two finite numeric coordinates in valid latitude and longitude ranges. 3. Keep jq source static and supply every dynamic value through `--arg`, `--argjson`, or `--slurpfile` as appropriate. 4. Add regression tests containing quotes, closing parentheses, pipes, interpolation syntax, and jq comment markers. 5. Avoid returning raw command output to an Agent response without applying secret redaction. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sushiro:16
Finding

Shared Bearer Credential Embedded in Source Code and Documentation

Content
View full analysis
(e.g. 'stores?latitude=1&longitude=1&numresults=5')" _get "$path" } ``` Consequently, exposure is not limited to the three documented routes if additional ...[truncated 1320 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file explicitly publishes a live shared Bearer token and required request headers for accessing a backend intended for a WeChat mini-program. Even if the API is described as 'public' and 'no login required', embedding reusable credentials in skill documentation facilitates unauthorized third-party use, scraping, quota abuse, and continued access until the token is rotated; the note that curl works and other clients are blocked further helps bypass intended access controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README states Claude will auto-call the skill when users ask about broad terms like '寿司郎/排队/等位', which encourages very loose invocation matching. Overly broad triggers can cause the agent to invoke this skill in unintended contexts, increasing data exposure to the external service and creating opportunities for prompt-routing manipulation or unnecessary network access.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises executable shell and network behavior but does not declare any explicit tool scope or permissions boundary. That makes it easier for an agent runtime to invoke broader capabilities than intended, reducing reviewability and increasing the chance of unauthorized outbound requests or shell misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says to use the skill when a user asks phrases like '还要等多久' or '哪家人少', which are broad everyday questions unless tightly scoped to Sushiro. Although the sentence mentions Sushiro earlier, it does not explicitly define trigger phrases, exclusions, or negative examples, so the activation boundary is ambiguous.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation explicitly states that a shared hardcoded Bearer token for an unofficial internal mini-program backend is embedded in the script. Shipping shared credentials in a skill enables credential reuse by anyone with access to the skill, may violate the upstream service's access controls or terms, and creates a fragile dependency on secret material that can be abused until rotation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script ships with a hardcoded Bearer token that is automatically sent on every request. Embedding shared credentials in distributable code enables unauthorized reuse, makes rotation difficult, and can cause the skill author or upstream service to lose control over how the token is consumed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The raw subcommand exposes a generic passthrough to arbitrary API paths under the Sushiro backend, which exceeds the skill's stated purpose of queue and store lookups. This broadens the attack surface by letting callers probe undocumented endpoints or retrieve data the wrapper did not intend to expose, using the embedded authorization token and trusted headers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The raw network access command allows arbitrary GET requests to any path under the API base while automatically attaching the Bearer token. Even though the host is fixed, this still allows misuse of authenticated access against undocumented or administrative endpoints and bypasses the safety constraints implied by the higher-level commands.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/api.md:10