Back to skill

Security audit

金谷园饺子馆 Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its restaurant lookup and queueing purpose, but it needs review because it lets a remote API provide hidden agent instructions while also supporting real queue actions.

Install only if you are comfortable with a restaurant skill using Meituan/Dianping authorization for live queue actions and with the JinGuYuan API influencing reply policy. Do not approve booking or cancellation unless the agent restates the store, party size, table type, and action clearly; keep endpoint override environment variables unset, and avoid using authorization in shared or synced workspaces.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- 真实取号 / 本人进度 / 取消 → 本 Skill `scripts/jgy.cjs queue` + [references/queue-actions.md](references/queue-actions.md),与公开查询分离。

Ssd 1

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file explicitly instructs the agent to obey API-supplied fields like mainScenario, answerTarget, replyPolicy, and especially _agent_instruction, while also hiding _agent_instruction from the user. This creates a prompt-injection/control-channel risk where a remote API can silently steer agent behavior, override user intent, or induce unsafe actions without transparency.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README advertises real-world actions such as queue booking, progress lookup, and cancellation, but it does not prominently warn users that these operations have external effects on a live service and may create, modify, or cancel an actual queue reservation. In an agent setting, ambiguous phrasing like “帮我排个队” can lead to unintended real-world actions if the agent is insufficiently cautious, making this a genuine safety and consent issue.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill explicitly relies on Node execution, environment variables, network access, and local file output, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a least-privilege gap: a host or reviewer cannot easily constrain what the skill may access, and users may not realize the operational surface includes env, network, and filesystem behaviors.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该 markdown 文件适用 SQP-1。这里列出的推荐提问里包含“怎么排队取号?”,“帮我在金谷园排个队”,“金谷园有什么好吃的?”等较自然、宽泛的口语表达,且未说明这些只是示例而非精确触发词,也没有提供负例或限定上下文,容易与普通对话重叠。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file is natural-language guidance, and it appears to require use of Chinese throughout the skill documentation and interaction model without indicating that users may choose another language. That can constitute a locale/language policy issue under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file title and all operational instructions are written entirely in Chinese, and the workflow language is prescribed in Chinese phrases such as replying “已授权”. There is no indication that users may choose another language or that the skill is intentionally restricted to a China-specific locale for policy reasons.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file is entirely written as a Chinese-only response contract and instructs the agent to prioritize Chinese natural-language explanations, but it does not state that this skill is intentionally limited to Chinese users or provide any language/locale opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says real actions are limited to queue operations, but the bundled client also exposes identity/OAuth endpoints and a generic capability invocation surface. Even though the current CLI only whitelists some public capabilities, shipping broader account and backend access than declared expands the attack surface and creates a privilege/scope mismatch that can enable unintended account or API interactions if wiring changes or hidden commands are later exposed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code includes phone-start/phone-verify and OAuth token lifecycle functionality that is not justified by a dumpling-info and queueing skill. In this context, account-verification and token-management primitives are more sensitive than store lookup or queue status, so their presence increases the risk of credential abuse, account takeover workflows, or accidental exposure through future tool routing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill's user-facing documentation and invocation examples are entirely in Chinese, and the file does not indicate that the skill is China-only or otherwise intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without opt-in or justification is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill states that an authorization QR PNG will be written into the current workspace root and that auth state/token material is stored locally, but the install and action guidance does not prominently warn users before those artifacts are created. In shared or synced workspaces, this can expose sensitive login flow artifacts or create privacy surprises, even if the token itself is stored elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.