Back to skill

Security audit

zxk-money-maker

Security checks for vulnerabilities and agentic risk

Overview

This job-listing skill should be reviewed because it broadly triggers on work or money requests and sends the full user message to an external test API.

Install only if you are comfortable having job-search or earning-money requests sent to this external 快结荐 test API. Avoid entering resumes, phone numbers, precise addresses, identity details, or private employment information unless the publisher adds clear consent, data minimization, and privacy documentation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:2
Finding

Broad Skill Routing and Untrusted Remote Output Reproduction

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/call-wx-skill.py:11
Finding

Unconsented Transmission of Complete User Messages to a Third-Party Test API

Content
View full analysis
dict: """Call the wx skill API with the given content.""" payload = { "content": content } data = json.dumps(payload).encode("utf-8") req = urllib.request.Request( API_URL, data=data, headers={ "Content-Type": "application/json" }, method="POST" ) ``` ### Technical Analysis The implementation places the complete user-provided message into the `content` field and transmits it to an external host. No data-minimization, redaction, field extraction, consent check, or warning is performed before transmission. Employment-related messages frequently contain privacy-sensitive information, including names, telephone numbers, email addresses, residential locations, work history, availability, salary expectations, résumé content, or identity-related details. The broad automatic routing instructions make it plausible that users could disclose this information without realizing their entire message will be sent outside the agent environment. The destination hostname is explicitly identified as a test API. The audited project does not document the service operator, retention policy, access controls, processing purpose, geographic storage location, deletion mechanism, or privacy guarantees. HTTPS protects data in transit but does not address collection, retention, secondary use, or access by the endpoint operator. ### Attack Path 1. A user asks for employment assistance and includes personal details, contact information, location data, or résumé content. 2. The skill's broad routing rule automatically selects the third-party service. ...[truncated 1053 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly sends the user's message content to an external backend API without any user-facing disclosure or consent step. Users may include sensitive personal, employment, financial, or location details in job-seeking prompts, so silent transmission to a third party creates a clear privacy and data-sharing vulnerability.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs use of a networked backend API but does not declare any explicit tool scope or permissions boundary. This creates a governance and review gap: the agent may invoke external network access without clear policy constraints, making data exfiltration and unintended outbound requests harder to audit and control.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match ordinary requests about work, money, or help, which can cause the skill to activate in contexts the user did not intend. Because the skill forwards user content to a third-party API, accidental invocation also becomes accidental data disclosure to an external service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill is presented entirely in Chinese and oriented to a Chinese platform without offering any language choice or opt-in behavior. Because the instructions and routing are language-specific with no explicit user selection, this may violate language/locale policy requirements for offering choice unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The routing rules use underspecified examples such as '赚钱' and '求职' that are semantically broad and likely to over-trigger. In this skill's context, over-triggering is more dangerous because the workflow mandates transmitting the user's raw message to a backend API, so ambiguity directly increases privacy and consent risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends arbitrary user-provided content directly to an external API endpoint with no disclosure, consent check, redaction, or minimization. In a job-seeking skill, users may submit sensitive personal or employment-related information, so silent transmission to a remote service creates a real privacy and data-handling risk even if the network call is the skill's intended function.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.