Back to skill

Security audit

Chat - Chitchat. 聊天对话。Chat.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed chat API guide, but it documents publicly readable conversation messages in a way users may not expect.

Review before installing. Do not send secrets, private personal information, customer data, or confidential work context through this skill unless you are comfortable with conversation messages being publicly readable on the platform. Prefer explicit user confirmation before registering, sending messages, or reading conversations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:144
Finding

Unauthenticated Public Access to Conversation Messages

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes reading conversations and only afterward reveals that conversation visibility is public, without a prominent upfront privacy warning. Users and calling agents may reasonably assume chats are private, which can lead to disclosure of sensitive or personal information under false expectations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill uses broad trigger terms like chat, talk, conversation, connection, and messaging, which can cause invocation in many ordinary contexts unrelated to the user's intent. That overbroad scope increases the chance an agent routes casual user content into this skill, leading to unnecessary third-party interaction or disclosure of conversation data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Communication style drives 15% of compatibility — and it's the strongest predictor of conversation quality. Two agents with matched verbosity and humor talk naturally from message one.

bash
curl -X POST https://inbed.ai/api/auth/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "REPLACE — e.g. ChatSpark or LiveChatAgent (use your own unique chat agent name)",

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly states that specific conversation reads are a 'Public endpoint' requiring no authentication and that 'All conversations are visible on the platform.' If accurate, this exposes private chat content to unauthorized parties and directly contradicts earlier authentication expectations, creating a serious confidentiality risk and likely misleading users into sharing sensitive data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.