Back to skill

Security audit

Parcel Station Route Qr

Security checks for vulnerabilities and agentic risk

Overview

The skill describes parcel-station QR and route features, but it also ships an unrelated Notion sync script that can read local credentials and read or write Notion data.

Review this package before installing. Remove or clearly separate the Notion sync script unless you explicitly want it, and do not run it unless you understand which Notion token and database it will use. Consider adding QR payload confirmation, pinning npm dependencies, and storing generated TLS keys with restrictive permissions outside the source tree.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/notion-sync.js:8
Finding

Undeclared Access to Local Notion Credentials and Database Records

Content
View full analysis
{ const opts = { hostname: 'api.notion.com', path: urlPath, method: method, headers: { 'Authorization': 'Bearer ' + API_KEY, 'Notion-Version': '2025-09-03', 'Content-Type': 'application/json' } }; const req = https.request(opts, (res) => { let data = ''; res.on('data', c => data += c); res.on('end', () => { try { resolve(JSON.parse(data)); } catch (e) { reject(new Error('Parse error: ' + data.substring(0, 200))); } }); }); req.on('error', reject); if (body) req.write(JSON.stringify(body)); req.end(); }); } ``` ```javascript const result = await notion('POST', '/v1/pages', { parent: { database_id: DB_ID }, properties: { 'Name': { title: [{ text: { content: title || today() + ' 记录' } }] }, '日期': { date: { start: today() } }, '类型': { select: { name: type || '每日记录' } }, '内容': { rich_text: [{ text: { content: content || '' } }] }, '标签': { multi_select: (tags || '').split(',').filter(Boolean).map(t => ({ name: t.trim() })) }, '状态': { select: { name: status || '待同步' } } } }); ``` ```javascript const result = await notion('POST', '/v1/data_sources/' + DS_ID + '/query', { sorts: [{ property: '日期', direction: 'descending' }], pag ...[truncated 2080 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:75
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
references/gen-cert.js:23
Finding

Generated TLS Private Key Uses Default Filesystem Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about end-user chatbot features: shelf route guidance and QR code scanning. The supplied code does not implement either capability. Instead, it generates a self-signed certificate using the selfsigned library and writes certificate/key files to disk. While HTTPS setup could be a supporting infrastructure detail for a broader system, this specific code chunk’s purpose is materially different from the declared feature description and introduces undeclared security/credential-generation and file-writing behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill should provide parcel-station chatbot features for shelf navigation and QR code scanning. The supplied code does none of that. Instead, it implements a command-line Notion synchronization utility that reads API keys and database IDs from local files, sends HTTPS requests to api.notion.com, creates database pages, and queries/list recent records. This is a materially different primary purpose and introduces undeclared external-service and filesystem access unrelated to the stated chatbot functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This file is a standalone Notion synchronization CLI that is unrelated to the stated skill purpose of parcel-station route guidance and QR scanning. In skill packages, unrelated code that reads local secrets and moves data to external services materially increases supply-chain risk because it can exfiltrate user or developer data under the guise of an unrelated feature.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script reads credential files from the local profile and uses them to call the Notion API, despite no clear relationship to the advertised skill behavior. This creates an unjustified channel for accessing secrets and transmitting data off-host, which is especially dangerous in an agent skill context where users would not expect local credential harvesting or outbound synchronization.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The QR workflow explicitly says scanned content is automatically sent after decoding, without requiring confirmation or warning the user. QR payloads can contain unexpected text, URLs, commands, or sensitive identifiers, so auto-submission can cause accidental disclosure, unintended actions, or prompt/command injection into the chatbot flow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest describes a skill that adds shelf route guidance and QR code scanning to a parcel station chatbot. This file instead generates a self-signed HTTPS certificate and writes a private key to disk, which is infrastructure/setup behavior not reflected in the stated skill purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code silently reads sensitive API configuration from files in the user's profile directory without any disclosure or consent flow. Even if intended for convenience, undisclosed secret access violates user expectations and can facilitate covert use of existing credentials in a broader malicious or compromised skill chain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The wrapper sends user-provided titles and content to the Notion API without any explicit warning that data will leave the local environment. Lack of transparency around outbound transmission can cause unintended disclosure of sensitive operational notes, logs, or personal information entered into the tool.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The today() function hard-codes Asia/Shanghai time when generating dates, which imposes a locale-specific behavior regardless of the user's environment or preferences. This is a natural-language policy concern because the tool forces a specific locale setting without offering a choice or clearly documenting a justified regional constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's instructional content is presented in Chinese, which effectively forces a specific language for users reading the skill documentation. Under the policy, language constraints should either be optional or clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This JavaScript file contains natural-language content only in Chinese, including the file header comment, organization name, and console output. Under the policy, forcing a specific language without user opt-in or a documented region-specific justification is a locale-policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.