Back to skill

Security audit

12306 Train Query

Security checks for vulnerabilities and agentic risk

Overview

This train-query skill appears benign, with a supply-chain caution about its unpinned README install command.

Install from a source and revision you trust, preferably with a pinned installer version and reviewed commit. Expect the skill to contact 12306 web endpoints, create a station cache for up to 7 days, and write HTML output files when using the default mode. It does not require an API key or local credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:8
Finding

Unpinned Package Execution in Documented Installation Command

Content
View full analysis

Vulnerability Details

File Location: README.md, line 8
Vulnerability Type: Unpinned third-party installer and mutable Skill source
Risk Level: Medium

Vulnerable Code

bash
npx skills add kirorab/12306-skill

Technical Analysis

The documented installation command invokes the skills npm package through npx without specifying an exact package version or verifying package integrity. Depending on the local npm environment, npx may retrieve and execute the latest available version of that package.

The referenced kirorab/12306-skill source is also not pinned to a reviewed commit hash. Consequently, both the installer and the installed Skill may change after this audit. This creates a supply-chain trust boundary in which newly published or compromised upstream content can execute during installation without being identical to the audited code.

The audited runtime scripts themselves did not contain command execution, persistence, credential access, obfuscation, or malicious payload retrieval. The risk is specifically associated with the installation procedure documented in the README.

Attack Path

  1. An attacker compromises the npm account or publishing pipeline associated with the unpinned skills package, or compromises the referenced Skill repository.
  2. The attacker publishes a malicious package version or modifies the repository contents to include installation-time or runtime code execution.
  3. A user follows the documented npx skills add kirorab/12306-skill command.
  4. npx downloads and executes the currently resolved installer package, which may differ from the version originally reviewed.
  5. The installer retrieves the mutable Skill source and executes or installs attacker-controlled content.
  6. The malicious code runs with the privileges of the user performing the installation.

Impact Assessment

Successful exploitation can provide arbitrary code execution under the installing user's account. The acces ...[truncated 394 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin the installer package to an exact, reviewed version rather than allowing npx to resolve the latest release:
    bash
    npx --yes skills@<reviewed-exact-version> add kirorab/12306-skill
    
  2. Pin the Skill source to a reviewed commit hash or immutable release tag instead of a mutable repository reference.
  3. Publish and verify cryptographic checksums or signatures for the installer and Skill artifact.
  4. Use a lockfile or an equivalent reproducible dependency mechanism wherever the installation workflow supports one.
  5. Run installation with a non-privileged account in an isolated environment.
  6. Review newly resolved installer and Skill versions before upgrading rather than relying on implicit latest-version resolution.
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill invokes Node scripts that query the official 12306 API, which implies network access, but the manifest does not declare any tool scope such as permissions or allowed-tools. This creates an under-specified trust boundary: an agent or runtime may allow broader execution/network behavior than users or policy expect, reducing transparency and weakening sandbox enforcement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated HTML explicitly sets lang="zh-CN" and uses toLocaleString('zh-CN', { timeZone: 'Asia/Shanghai' }), which forces a specific language/locale in the output. The file does not offer any user choice or opt-in for locale selection, matching the policy-violation criterion for locale constraints.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.