Back to skill

Security audit

身份证信息查询(AI付版) - 聚合数据

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and disclosed, but it asks users to install a mutable payment package with automatic confirmation while also handling sensitive national ID data.

Review this before installing if you are not comfortable with a skill that processes full Chinese ID numbers through Juhe and uses Alipay payment. The main issue to resolve is the payment install command: prefer a pinned, reviewed package version without automatic confirmation, and make sure users explicitly approve both the third-party ID query and payment flow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:40
Finding

Unpinned Dependency Installation with Suppressed Confirmation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 40
Vulnerability Type: Unsafe execution of a mutable third-party package release
Risk Level: Medium

Vulnerable Code Snippet:

shell
npx -y @alipay/agent-payment@latest install

Technical Analysis

The skill instructs the agent to invoke an npm package using the mutable latest distribution tag. The npx command can download and execute package code, including package entry points and lifecycle scripts. Because no exact version, integrity hash, or lockfile is specified, the code executed during a future installation may differ from the package version available when this audit was performed.

The -y option automatically accepts installation prompts, reducing the opportunity for the user or operator to inspect the resolved package version and approve execution. If the package publisher account, npm package, or relevant supply-chain infrastructure is compromised, an attacker could publish a malicious release under the same package name and make it resolve through latest.

This is an insecure dependency-execution pattern. The reviewed repository does not itself contain a malicious payload, and successful exploitation depends on compromise or malicious modification of the external package supply chain.

Attack Path

  1. An attacker compromises the @alipay/agent-payment package, its publisher account, or another part of its distribution chain.
  2. The attacker publishes a malicious release and assigns it to the mutable latest tag.
  3. The payment dependency is absent when the skill is used.
  4. The agent follows the documented command and invokes npx with automatic confirmation enabled.
  5. npx retrieves the attacker-controlled package release.
  6. Malicious package code or lifecycle scripts execute with the privileges of the account running the agent.

Impact Assessment

Successful exploitation could result in arbitrary code ex ...[truncated 640 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with a reviewed and immutable exact package version.
  2. Use a lockfile and verify package integrity through a trusted checksum or package-lock integrity value.
  3. Remove -y so installation requires explicit, informed operator approval.
  4. Display the exact package name, resolved version, registry, and requested action before installation.
  5. Configure npm to use an approved registry and enforce dependency allowlisting where possible.
  6. Disable lifecycle scripts during installation when they are not required, such as by using --ignore-scripts.
  7. Perform installation in a sandbox or least-privileged container with restricted filesystem access, credentials, and network connectivity.
  8. Prefer a preinstalled, independently reviewed payment integration rather than downloading executable dependencies during skill operation.
  9. Establish a controlled update process that reviews and tests each dependency release before changing the pinned version.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file is entirely prescriptive in Chinese and defines a fixed Chinese rendering format for the skill output, with no indication that users may choose another language or locale. Under the policy rule, forcing a specific language without opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs users to run npx -y @alipay/agent-payment@latest install, which fetches and executes the newest package version at runtime without pinning to a known-good release. This creates a supply-chain risk: if the package or one of its dependencies is compromised, users may execute attacker-controlled code during installation with little opportunity for review.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill transmits a full national ID number (cardno) to an external third-party service at apis.juhe.cn. Even though this is the intended business flow and the document describes minimization controls, the data is still highly sensitive personal information, so external transmission materially increases privacy, regulatory, and breach exposure if the third party, transport configuration, or surrounding logging/monitoring pipeline is compromised.

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

向用户展示待查询的参数(脱敏后展示),严格遵守请求约束,向以下 URL 发起请求:

text
curl https://apis.juhe.cn/a2a/query \
  -d '{"resourceId":"38","data":{"cardno":"<用户输入的身份证号>"}}' \
  -H "Content-Type: application/json"

Static analysis

No suspicious patterns detected.