Back to skill

Security audit

liken

Security checks for vulnerabilities and agentic risk

Overview

This recommendation skill is coherent and disclosed; it sends media titles to public lookup APIs only to verify that works exist.

Install only if you are comfortable with titles or media queries being sent to OpenLibrary, iTunes, Wikidata, and TVmaze for existence checks. Avoid using it for private or sensitive interests you do not want shared with those services.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose is an inference-heavy recommendation skill centered on deriving shared taste dimensions and producing cross-domain analogies and explanations. The supplied code, however, is narrowly scoped to verifying whether named works exist via third-party APIs and returning candidate matches. The module docstring explicitly states it 'only verifies whether a work truly exists' and 'does not do similar recommendations.' That is materially different from the advertised primary purpose. Additionally, the code makes outbound network requests to multiple public APIs despite the declared permissions being empty, which further indicates undeclared operational behavior.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The script depends on outbound network connectivity to OpenLibrary, iTunes, Wikidata, and TVmaze, but this capability is reportedly not covered by declared permissions. Even though the functionality is expected for existence checks, undeclared network access is a security issue because it bypasses least-privilege expectations and transmits user-supplied content to external services.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The script depends on outbound network connectivity to OpenLibrary, iTunes, Wikidata, and TVmaze, but this capability is reportedly not covered by declared permissions. Even though the functionality is expected for existence checks, undeclared network access is a security issue because it bypasses least-privilege expectations and transmits user-supplied content to external services.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The primary description is written as an instruction to the user entirely in Chinese and presents the trigger/output contract in Chinese without any opt-in or alternative language path. This creates a language-policy concern because the skill appears to assume a specific language/locale rather than offering user choice.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The file explicitly documents and uses multiple third-party endpoints for existence checks, meaning user-provided titles are transmitted outside the local system. In this skill context that behavior is functionally necessary, but it still creates privacy and data-handling risk because user interests, media queries, and metadata are shared with external providers.

Content

Scanner excerpt · scripts/recommend.py (reported line 10)May include surrounding context.

python
book  -> OpenLibrary   https://openlibrary.org/search.json
  music -> iTunes Search  https://itunes.apple.com/search?media=music
  movie -> Wikidata      https://www.wikidata.org/w/api.php (wbsearchentities)
  show  -> TVmaze        https://api.tvmaze.com/search/shows

已弃用(不可达,不要再调):TasteDive(Cloudflare 拦截)、Google Books(429 限流)。

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The hardcoded API base URLs confirm that the script sends requests to external services as part of normal operation. While not inherently malicious, this is a real external-transmission concern because any user input passed as a title or name leaves the trusted boundary and may be logged or profiled by those services.

Content

Scanner excerpt · scripts/recommend.py (reported line 26)May include surrounding context.

python
OPENLIBRARY = "https://openlibrary.org/search.json"
ITUNES = "https://itunes.apple.com/search"
WIKIDATA = "https://www.wikidata.org/w/api.php"
TVMAZE = "https://api.tvmaze.com/search/shows"


def _opener():

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Wikidata request hard-codes "language": "en", which imposes an English-only locale for movie searches. This is a natural-language locale policy issue because the script does not offer user opt-in or explain why English is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.