Back to skill

Security audit

Parcel Station Chat

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for building a parcel-station chat app, but it under-specifies safeguards for sensitive shipment data, OCR uploads, and package-management admin functions.

Review this skill carefully before installing or using it in a real parcel station. Require authenticated admin access for all management pages and package APIs, restrict public lookup responses, protect the local database, and define clear rules for consent, provider choice, logging, retention, and deletion before enabling OCR on real waybills.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:87
Finding

Unauthenticated Package Management and Administration Interfaces

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 87-109
Vulnerability Type: Missing authentication and authorization
Risk Level: High

Evidence

The Skill directs implementers to expose a separate administration page:

text
http://localhost:3000/admin.html

It also specifies package-management endpoints without requiring authentication or role-based authorization:

text
GET  /api/packages
POST /api/packages
GET  /api/packages/:code

Although the Skill states that the management entry should not appear in the client interface, hiding a link does not prevent direct access to the administration page or its underlying APIs.

Technical Analysis

The documented architecture exposes operations for listing package records, creating package records, and retrieving records by pickup code. No authentication middleware, administrator session, authorization check, or network-access restriction is specified for these routes.

Removing the administration link from the client UI is security through obscurity. An attacker can discover the endpoints through common path enumeration, browser developer tools, documentation, or direct URL guessing. If the application is implemented according to this design and exposed beyond a trusted local machine, any caller may be treated as an administrator.

Attack Path

  1. The application is started on port 3000 and becomes reachable from another user or system.
  2. The attacker requests /admin.html directly, regardless of whether a link appears in the client UI.
  3. The attacker sends GET /api/packages requests and uses pagination or search parameters to enumerate package records.
  4. The attacker requests GET /api/packages/:code with guessed or observed pickup codes to retrieve individual records.
  5. The attacker submits unauthorized records through POST /api/packages.
  6. If downstream pickup workflows trust these records, the attacker may cr ...[truncated 802 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require authenticated administrator sessions for /admin.html and every package-management API.
  2. Enforce server-side role-based authorization; do not rely on hidden navigation elements.
  3. Separate public lookup functionality from administrative list and write operations.
  4. Return only the minimum information required for public package lookup.
  5. Add rate limiting, failed-request throttling, and monitoring for pickup-code enumeration.
  6. Use high-entropy, non-sequential lookup identifiers where operationally possible.
  7. Apply CSRF protection to browser-authenticated state-changing requests.
  8. Validate and normalize all package-creation fields on the server.
  9. Record audit events for package creation, modification, lookup, and administrator access.
  10. Bind the service to a loopback or trusted management interface by default, and require an authenticated reverse proxy with TLS for remote access.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:66
Finding

External Transmission of Sensitive Waybill Data Without Defined Privacy Controls

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 66-78 and line 130
Vulnerability Type: Insecure handling of personal and shipment data
Risk Level: Medium

Evidence

The Skill instructs the application to send waybill images to an external vision model and extract sensitive shipment fields:

json
{
  "pickup_code": "",
  "tracking_no": "",
  "recipient_name": "",
  "recipient_phone_tail": "",
  "carrier": "",
  "confidence": "low|medium|high"
}

The documented configuration and processing flow includes:

text
loadApiConfig() → SU2_API_KEY + baseUrl
callAI() → GPT-5.5
recognizeWaybill()

The Skill also indicates that an intermediary service may be used and retried after delays, but it does not define endpoint trust requirements, data-retention controls, user consent, redaction, or logging restrictions.

Technical Analysis

Waybill images commonly contain names, full telephone numbers, addresses, tracking numbers, barcodes, and pickup identifiers. The application design sends the image to a configurable external AI endpoint. Because baseUrl is configurable and no allowlist or endpoint-validation policy is specified, a misconfigured or attacker-controlled endpoint could receive the complete image and all information visible on it.

Limiting the parsed response to a phone-number suffix does not protect information already present in the uploaded image. The external provider receives the source image before structured-field minimization occurs.

The design also does not specify:

  • Explicit user notice or consent for third-party processing.
  • A trusted-provider or hostname allowlist.
  • Mandatory HTTPS and certificate validation.
  • Image and response retention limits.
  • Redaction of fields unnecessary for package lookup.
  • Restrictions against logging images, prompts, or extracted personal data.
  • Controls preventing secret-bearing configuration from being ex ...[truncated 1263 chars]
Remediation
View remediation

Remediation Suggestions

  1. Allowlist approved AI-provider hostnames and reject arbitrary runtime endpoint overrides.
  2. Require HTTPS with normal certificate and hostname validation.
  3. Inform users that images are processed by an external provider and obtain any consent required by applicable policy or law.
  4. Crop or redact addresses, full telephone numbers, barcodes, and other fields not required for the requested operation before transmission.
  5. Prefer local OCR for sensitive labels where practical.
  6. Establish contractual and technical provider-retention controls, including disabling model training and request logging where supported.
  7. Do not write source images, AI prompts, responses, API keys, or extracted personal data to ordinary application logs.
  8. Encrypt any necessary stored images or extracted records and define short deletion periods.
  9. Validate OCR output as untrusted data before storing it or presenting it to another model.
  10. Keep API credentials in a protected secret store, redact them from errors, and rotate them after suspected disclosure.
  11. Document the data flow and perform a privacy review before enabling OCR in production.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill handles package lookup, OCR of waybills, phone-tail matching, and recipient-related delivery data, which are sensitive personal and logistics records. Documenting this functionality without any privacy notice, retention policy, or operator guidance increases the risk of improper collection, disclosure, or overexposure of personal data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents an admin interface and package-management endpoints, including record creation and listing, without any mention of authentication, authorization, or safeguards against unauthorized modification. In this context, exposing package records and write operations for a courier station materially raises the risk of data tampering, package fraud, and privacy breaches if implemented as described.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The natural-language instructions and interface guidance are fully Chinese, which can amount to forcing a specific language on users without opt-in. The file does not state that the skill is intentionally limited to Chinese-speaking operators or provide an alternative language option.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The frontend guidance at L097 says not to add a "management" entry on the client, implying the system should present only the chat experience there. However, the same file explicitly documents a separate management backend URL at L107 and package-management APIs at L118-L119, which contradicts the stated frontend intent rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.