Back to skill

Security audit

xzk-money-maker

Security checks for vulnerabilities and agentic risk

Overview

This job-matching skill is purpose-aligned, but it broadly auto-routes employment requests and sends the full user message to an external test backend without clear user consent or data minimization.

Review before installing. Use this skill only if you are comfortable sending job-search or money-making requests to the external 1haozc test backend, and avoid including phone numbers, addresses, identity documents, credentials, or detailed resume information unless the publisher adds consent, redaction, and privacy documentation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
scripts/call-wx-skill.py:10
Finding

Unconsented Disclosure of Complete User Messages to an External Test Backend

Content
View full analysis
dict: """Call the wx skill API with the given content.""" payload = { "content": content } data = json.dumps(payload).encode("utf-8") req = urllib.request.Request( API_URL, data=data, headers={ "Content-Type": "application/json" }, method="POST" ) try: with urllib.request.urlopen(req, timeout=30) as response: result = json.loads(response.read().decode("utf-8")) return result ``` ```python content = sys.argv[1] result = call_wx_skill(content) print(json.dumps(result, ensure_ascii=False)) ``` ### Technical Analysis The script accepts the complete user-provided message and places it directly into the `content` property of an outbound request. It then sends that request to the third-party test endpoint `test-gig-c-api.1haozc.com`. The related Skill instructions broadly route employment, freelance-work, recruitment, and money-making requests through this script. They do not require informed consent before transmission, warn users that their message will leave the local environment, minimize the submitted data, or redact sensitive fields. Employment-related messages can reasonably contain names, telephone numbers, residential addresses, résumé contents, employment history, government identifiers, or other personal information. All such content would be transmitted as entered. HTTPS protects the request in transit but does not address disclosure to the destination service, its operators, logs, or downstream systems. Use of a test-environment endpoin ...[truncated 1634 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are extremely broad, including common words like “赚钱”, “找工作”, and “兼职”, plus an instruction to 'Always invoke this skill'. This can cause the agent to route ordinary user messages into a skill that transmits their content to an external API, creating privacy and integrity risks through over-invocation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill performs outbound network access to a third-party backend but does not declare any explicit tool scope or permissions boundary. This makes the capability less transparent to the platform and reviewers, increasing the risk of unintended data egress or misuse if the skill is auto-routed.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The routing section gives examples but still leaves scope ambiguous because it prioritizes many generic employment-related phrases without clear boundaries. In this skill’s context, ambiguous routing is more dangerous because invocation sends user-provided text to a remote backend, so misclassification directly leads to unnecessary data sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow explicitly sends the user’s message content as the content field to an external backend, but the skill does not present a user-facing disclosure or consent warning. This is dangerous because users may share personal employment details, location, contact info, or financial needs without realizing their raw text is being transmitted off-platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script forwards raw user-provided content directly to a third-party backend API without any explicit notice, consent, or filtering. This creates a privacy and data-handling risk because users may include personal, financial, or sensitive job-seeking information that is silently exfiltrated to an external service, and the skill description explicitly says to always invoke this backend.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.