Back to skill

Security audit

chelaile-bus (公交实时到站)

Security checks for vulnerabilities and agentic risk

Overview

This bus-query skill is mostly purpose-aligned, but it runs an unpinned external npm MCP server with local user privileges, which users should review before installing.

Install only if you are comfortable running the `chelaile-mcp-server` npm package via `npx`. Prefer pinning a reviewed exact version, using native scoped MCP registration where available, and understanding that route, stop, city, and coordinate-related query data will be sent to the transit service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes MCP and shell-like capabilities but does not declare any explicit tool scope such as allowed tools or permissions. That creates an avoidable least-privilege gap: a host agent may permit broader tool execution than the skill actually needs, increasing the blast radius if the skill is misused or later modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description and all user-facing guidance are written exclusively in Chinese, and the skill does not indicate that users may interact in other languages or choose their preferred locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is clearly documented and justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs spawning npx chelaile-mcp-server without pinning a specific package version. Unpinned remote package execution is a supply-chain risk: a malicious or compromised future release could run arbitrary code in the agent environment when the skill or helper script is used.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The installation command again relies on npx chelaile-mcp-server without an exact version, repeating the same supply-chain exposure in setup instructions. Because this is presented as a standard configuration path, it materially raises the chance that operators will execute unreviewed code from the package registry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill launches a third-party MCP server process without clearly warning the user that external code will be downloaded and executed. This weakens informed consent and increases the chance that users unknowingly run unreviewed code, which is especially relevant here because the package is started automatically during a routine bus query workflow.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
89% confidence
Finding

The script unconditionally executes an external package via npx -y chelaile-mcp-server, which causes retrieval and execution of code outside the local trust boundary. Even though shell=True is not used and command injection is not present, this still creates a software supply-chain execution risk: a compromised package, typosquatted dependency, or malicious transitive dependency would run with the user's privileges.

Content

Scanner excerpt · scripts/query-bus.py (reported line 18)May include surrounding context.

python
class MCPClient:
    def __init__(self):
        self.proc = subprocess.Popen(
            SERVER_CMD, stdin=subprocess.PIPE, stdout=subprocess.PIPE,
            stderr=subprocess.DEVNULL, text=True, bufsize=1)
        self._id = 0

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The script sends user-provided route and stop queries, along with station coordinates returned by the backend workflow, to a network-backed MCP service without explicit disclosure. While this is expected for real-time transit queries, the absence of notice about outbound data transmission can expose user interests, location-related context, and usage metadata to external services without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.