Back to skill

Security audit

VIN 查询车辆信息-精准版(AI付) - 聚合数据

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed paid VIN lookup skill that sends the VIN to a fixed vehicle-data API and uses Alipay for payment.

Before installing, understand that each lookup is paid, the VIN will be sent to Juhe over HTTPS for the query, and payment depends on Alipay wallet/payment skills. Avoid using it if you do not want a third-party vehicle-data provider to receive the VIN.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The confirmation flow instructs users to reply with specific Chinese phrases such as「确认」「好的」「可以」「继续」「同意」「下一步」or「取消」to proceed or stop. This imposes a language-specific interaction pattern without explicit user opt-in or an alternative language path, which is a natural-language policy issue.

Static analysis

No suspicious patterns detected.