Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md - 真实取号 / 本人进度 / 取消 → 本 Skill `scripts/jgy.cjs queue` + [references/queue-actions.md](references/queue-actions.md),与公开查询分离。
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its restaurant lookup and queueing purpose, but it needs review because it lets a remote API provide hidden agent instructions while also supporting real queue actions.
Install only if you are comfortable with a restaurant skill using Meituan/Dianping authorization for live queue actions and with the JinGuYuan API influencing reply policy. Do not approve booking or cancellation unless the agent restates the store, party size, table type, and action clearly; keep endpoint override environment variables unset, and avoid using authorization in shared or synced workspaces.
Referenced artifact was not completely inspected
- 真实取号 / 本人进度 / 取消 → 本 Skill `scripts/jgy.cjs queue` + [references/queue-actions.md](references/queue-actions.md),与公开查询分离。
The file explicitly instructs the agent to obey API-supplied fields like mainScenario, answerTarget, replyPolicy, and especially _agent_instruction, while also hiding _agent_instruction from the user. This creates a prompt-injection/control-channel risk where a remote API can silently steer agent behavior, override user intent, or induce unsafe actions without transparency.
The README advertises real-world actions such as queue booking, progress lookup, and cancellation, but it does not prominently warn users that these operations have external effects on a live service and may create, modify, or cancel an actual queue reservation. In an agent setting, ambiguous phrasing like “帮我排个队” can lead to unintended real-world actions if the agent is insufficiently cautious, making this a genuine safety and consent issue.
The skill explicitly relies on Node execution, environment variables, network access, and local file output, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a least-privilege gap: a host or reviewer cannot easily constrain what the skill may access, and users may not realize the operational surface includes env, network, and filesystem behaviors.
该 markdown 文件适用 SQP-1。这里列出的推荐提问里包含“怎么排队取号?”,“帮我在金谷园排个队”,“金谷园有什么好吃的?”等较自然、宽泛的口语表达,且未说明这些只是示例而非精确触发词,也没有提供负例或限定上下文,容易与普通对话重叠。
This markdown file is natural-language guidance, and it appears to require use of Chinese throughout the skill documentation and interaction model without indicating that users may choose another language. That can constitute a locale/language policy issue under the rule for forced language without user opt-in.
The file title and all operational instructions are written entirely in Chinese, and the workflow language is prescribed in Chinese phrases such as replying “已授权”. There is no indication that users may choose another language or that the skill is intentionally restricted to a China-specific locale for policy reasons.
The file is entirely written as a Chinese-only response contract and instructs the agent to prioritize Chinese natural-language explanations, but it does not state that this skill is intentionally limited to Chinese users or provide any language/locale opt-in. Under the policy, forcing a specific language without user choice is a natural-language policy violation.
The skill description says real actions are limited to queue operations, but the bundled client also exposes identity/OAuth endpoints and a generic capability invocation surface. Even though the current CLI only whitelists some public capabilities, shipping broader account and backend access than declared expands the attack surface and creates a privilege/scope mismatch that can enable unintended account or API interactions if wiring changes or hidden commands are later exposed.
The code includes phone-start/phone-verify and OAuth token lifecycle functionality that is not justified by a dumpling-info and queueing skill. In this context, account-verification and token-management primitives are more sensitive than store lookup or queue status, so their presence increases the risk of credential abuse, account takeover workflows, or accidental exposure through future tool routing.
The skill's user-facing documentation and invocation examples are entirely in Chinese, and the file does not indicate that the skill is China-only or otherwise intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without opt-in or justification is a natural-language policy concern.
The skill states that an authorization QR PNG will be written into the current workspace root and that auth state/token material is stored locally, but the install and action guidance does not prominently warn users before those artifacts are created. In shared or synced workspaces, this can expose sensitive login flow artifacts or create privacy surprises, even if the token itself is stored elsewhere.
No suspicious patterns detected.