Back to skill

Security audit

校园百事

Security checks for vulnerabilities and agentic risk

Overview

The skill is a campus forum assistant, but it directs agents to collect and store users' forum passwords in plaintext and makes inconsistent privacy claims.

Review before installing. Do not send passwords to this skill or allow it to store them in a JSON file. A safer version should use the forum's own login or a scoped token, store no reusable passwords, clearly explain what account and school data is retained, and disclose image processing and deletion options.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:75
Finding

Persistent Collection and Plaintext Storage of User Credentials

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:75-86, SKILL.md:94-103, SKILL.md:133-170; data/accounts.json:2
Vulnerability Type: Plaintext credential collection, persistence, and reuse
Risk Level: High

Vulnerable Configuration Snippets

The following is an English rendering of the credential-storage directives in SKILL.md:75-86:

text
Credentials supplied by users must be remembered persistently:

Once a user sends a registered account and password, I must immediately
save them persistently. They must not be kept only in the conversation.

Storage location: data/accounts.json
Format:
{
  "username": {
    "username": "value",
    "password": "value",
    "school": "school name"
  }
}

Before every post or submission, read this file. If credentials exist,
automatically log in with them.

The authenticated school lookup in SKILL.md:94-103 transmits the reusable password directly:

json
{
  "username": "username",
  "password": "password"
}

The registration workflow in SKILL.md:133-170 also instructs the agent to collect and retain sensitive registration data:

text
Ask the user for the desired username, email address, and password.
Call the registration endpoint with the school, region, username,
email address, and password.
After successful registration, write the account information to
data/accounts.json for persistent storage.

The account database description at data/accounts.json:2 confirms that plaintext credentials are intended to be written to the project workspace:

json
{
  "_description": "Forum user account database. After a user gives the agent a registered account and password, the agent must immediately write them to this file for persistent storage, keyed by username. Before posting or submitting, read this file to determine whether the user is registered.",
  "accounts": {}
}

Technical Analysis

The skill explicitly requires users to disclose reusable forum passwords through th ...[truncated 3291 chars]

Remediation
View remediation

Remediation Suggestions

  1. Stop requesting passwords in conversation

    • Remove all instructions requiring users to send passwords to the agent.
    • Direct users to the first-party HTTPS registration and login interface.
    • Warn users not to disclose passwords, recovery codes, or session cookies to the agent.
  2. Replace passwords with delegated authorization

    • Implement OAuth, a device authorization flow, or another first-party authorization mechanism.
    • Issue narrowly scoped tokens for required actions such as creating posts.
    • Ensure tokens are revocable, time-limited, audience-restricted, and bound to the minimum required permissions.
  3. Do not store authentication secrets in project files

    • Remove the password field from data/accounts.json.
    • Store only non-sensitive identifiers needed to associate a user with a school or forum account.
    • If a delegated token must be retained, use an operating-system secret manager or managed vault rather than a JSON file.
  4. Protect any unavoidable tokens

    • Encrypt secrets at rest using keys stored separately from the project.
    • Enforce restrictive filesystem permissions and per-user isolation.
    • Prevent secrets from entering logs, prompts, error messages, backups, telemetry, and memory summaries.
    • Implement expiration, rotation, revocation, and deletion controls.
  5. Minimize registration data handling

    • Perform password entry only on the first-party registration site.
    • Do not proxy registration passwords through the agent.
    • Retain school affiliation and email data only where necessary and with clear disclosure.
  6. Correct privacy claims

    • Distinguish between anonymous public display and internal identity collection.
    • Clearly document what data is collected, where it is stored, why it is needed, how long it is retained, and how users can delete it.
  7. Remove previously stored credentials safely

    • Search existing deployments, logs, hi ...[truncated 248 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

The skill explicitly tells the assistant to solicit, retain, and reuse user passwords in persistent storage, and to rely on those credentials for future actions. This is a severe anti-pattern: chat is not an անվտանգ credential channel, plaintext persistence greatly enlarges the blast radius of compromise, and automated reuse enables silent impersonation and account takeover.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill instructs the assistant to collect and persist user passwords in a local file without any meaningful warning, consent flow, or secure handling requirements. Requesting credentials in chat and storing them for reuse creates a direct credential-compromise risk and enables account takeover if the assistant, logs, or storage are exposed.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The fallback flow instructs users who self-register on the website to send their account and password back to the assistant, normalizing credential sharing over chat. This significantly increases phishing-like risk and trains users into unsafe behavior, while giving the assistant the means to impersonate users and access their forum accounts.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill promises anonymous submissions and says it does not collect or display submitter identity, yet elsewhere requires account-based posting and persistent storage of usernames, passwords, emails, and school bindings. This is a material mismatch between claimed privacy properties and actual data handling, which can mislead users into sharing sensitive credentials under false assumptions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states that anonymous submissions do not collect submitter identity, but the operational instructions explicitly require collecting and persisting usernames, emails, passwords, and school bindings. This contradiction creates deceptive data practices and increases the risk of credential theft, privacy harm, and unauthorized account use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file explicitly instructs the AI to collect and persist user forum usernames and passwords, which is far outside the stated purpose of a campus information assistant. Storing credentials in plaintext for later reuse creates a direct risk of credential theft, unauthorized access, and cross-account compromise if users reuse passwords elsewhere.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill’s described role is a campus survival guide, but the file adds credential collection and retention behavior unrelated to that scope. This mismatch is dangerous because it normalizes unnecessary secret handling and increases the chance of phishing-like behavior and improper data retention.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction says that once a user sends account credentials, the AI must immediately write them to persistent storage, with no consent guardrails, security controls, or limitation of use. Broad mandatory persistence of secrets is inherently unsafe and makes accidental collection, insider misuse, and later exfiltration far more likely.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

This is a direct instruction to persistently store user-provided account passwords in a file for future use. Plaintext password retention by an AI skill is highly dangerous because any file disclosure, logging issue, or downstream access to the skill data would expose live credentials and enable account takeover.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad everyday terms such as food, dorm, nearby, query, and report, which can cause the skill to activate in conversations that were not intended for it. Overbroad invocation expands the chance that the skill will start prompting for school, account, or password data in irrelevant contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill requires persistent binding of a user's school and related account data without a user-facing disclosure of retention, purpose, or deletion controls. Even if school affiliation seems low sensitivity, linking it to forum identity and behavior can create privacy risks, especially for students sharing complaints, reports, or controversial posts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

Describing the skill as open-ended and '万能' weakens scope boundaries and encourages it to treat nearly any campus-related input as within scope. In this skill, that increases the likelihood of unbounded handling of sensitive content, broad content collection, and accidental invocation of risky posting or reporting flows.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The maintenance rule states that all user-facing prompts, errors, and copy must be in Chinese only. This is a language policy constraint applied globally, but the document does not provide user opt-in or a clear region-specific justification for refusing other languages.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document instructs the assistant to use a hidden image-recognition service and hidden indexing layer ('image_index') that users cannot inspect, while presenting the skill as a campus information assistant. This creates a privacy and transparency risk because user-uploaded images may be analyzed and repurposed for AI responses without clear user notice, consent, or data-governance constraints.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown explicitly directs use of a backend cache/index that 'users cannot see' and says the AI may query it for descriptions of uploaded images. In the context of a campus guide, this hidden data source exceeds normal user expectations and can expose inferred or sensitive content from images without transparency or an opportunity for users to opt out.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents hidden image-analysis indexing and retrieval but provides no warning to end users that uploaded images may be automatically processed into descriptions and stored for later AI use. This omission is dangerous because images can contain personal, contextual, or sensitive information, and silent secondary processing undermines informed consent and privacy compliance.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

The natural-language instruction is written solely in Chinese and provides no indication that users may interact in other languages or select a preferred locale. Under the stated policy, forced language behavior without opt-in can be a policy issue when no choice or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.