Back to skill

Security audit

kuaidi100-skill-快递100物流查询

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its courier-lookup purpose, but it can send sensitive shipment details and an API key to a third-party service with broad activation and limited privacy disclosure.

Review this before installing if you handle sensitive shipment data. Use it only when you are comfortable sending tracking numbers, phone numbers, sender and recipient addresses, and logistics history to Kuaidi100, and prefer a narrowly scoped API key that can be rotated. Avoid invoking it automatically on ambiguous messages.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
script/kuaidi100.js:29
Finding

Sensitive API credentials and personal logistics data exposed in URL query strings

Content
View full analysis

Vulnerability Details

File Location: script/kuaidi100.js, lines 29–107
Vulnerability Type: Sensitive information transmitted through URL query parameters (CWE-598)
Risk Level: Medium

Vulnerable Code

js
function makeRequest(path, params) {
    return new Promise((resolve, reject) => {
        const queryStr = querystring.stringify(params);
        const fullPath = `${BASE_PATH}${path}?${queryStr}`;
        
        const options = {
            hostname: BASE_URL,
            path: fullPath,
            method: 'GET'
        };
        
        const req = https.request(options, (res) => {
            let data = '';
            
            res.on('data', (chunk) => {
                data += chunk;
            });
            
            res.on('end', () => {
                resolve(data);
            });
        });
        
        req.on('error', (error) => {
            reject(error);
        });
        
        req.end();
    });
}

async function queryTrace(kuaidiNum, phone = null) {
    const params = {
        key: getKey(),
        kuaidiNum: kuaidiNum
    };
    
    if (phone) {
        params.phone = phone;
    }
    
    return await makeRequest('/queryTrace', params);
}

async function autoNumber(kuaidiNum) {
    const params = {
        key: getKey(),
        kuaidiNum: kuaidiNum
    };
    
    return await makeRequest('/autoNumber', params);
}

async function estimatePrice(kuaidicom, recAddr, sendAddr, weight = '1') {
    const params = {
        key: getKey(),
        kuaidicom: kuaidicom,
        recAddr: recAddr,
        sendAddr: sendAddr,
        weight: weight
    };
    
    return await makeRequest('/estimatePrice', params);
}

async function estimateTime(kuaidicom, from, to, orderTime = null, expType = null) {
    const params = {
        key: getKey(),
        kuaidicom: 
...[truncated 2721 chars]
Remediation
View remediation

Remediation Suggestions

  1. Use HTTPS POST and place sensitive request parameters in the request body if the Kuaidi100 API supports POST requests.
  2. Send the API key in an authorization header rather than in the URL if the vendor provides a header-based authentication mechanism.
  3. If the API contract requires GET parameters, configure all proxies, gateways, application servers, monitoring products, and vendor integrations to redact or omit query strings from logs.
  4. Minimize the data sent to each endpoint and avoid transmitting phone numbers, addresses, or full logistics histories unless required for the requested operation.
  5. Inform users before transmitting personal shipment information to the third-party API and apply appropriate retention and privacy controls.
  6. Use narrowly scoped API credentials where supported, monitor their usage, enforce quota alerts, and rotate any key suspected of appearing in URL logs.
  7. Add automated tests or static-analysis rules that reject credentials and sensitive personal data placed in URL query parameters.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill references access to environment variables for API credentials but does not declare any explicit tool scope or permission boundaries. This weakens least-privilege guarantees and makes it harder to audit what sensitive runtime capabilities the skill is expected to use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill says it must be triggered even for casual mentions like '我的快递到哪了' or '这个单号是什么快递', creating an overbroad activation rule. This can cause unnecessary transmission of tracking numbers, phone numbers, and address data to an external API without sufficiently clear user intent or confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation does not warn users that tracking numbers, phone numbers, and sender/recipient addresses may be sent to the third-party 快递100 API. Because these data elements are personally sensitive and linkable, the omission undermines informed consent and increases privacy and compliance risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The advertised estimateTimeWithLogistic function calls the same /estimateTime endpoint as estimateTime, while passing an extra logistic parameter. This creates a capability/implementation mismatch: callers may believe they are getting in-transit delivery estimation based on logistics history, but the request may be ignored, misprocessed, or produce incorrect results, which can mislead downstream automation or users making shipping decisions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.