Back to skill

Security audit

China Highway Route

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent China highway route-planning skill with expected location, vehicle-region, API, and policy-cache behavior, but users should understand those data flows before use.

Before installing, be comfortable sharing route addresses or coordinates with Amap and providing the vehicle plate region needed for local toll and restriction rules. Prefer storing the Amap key in an environment variable, not in source code, and avoid entering a full plate number unless needed for a specific restriction query.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:216
Finding

Unsafe API Key Storage and Transmission Guidance

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 216-233
Vulnerability Type: API key exposure through source-code embedding and URL query parameters
Risk Level: Low

Vulnerable Snippet

The following is an English rendering of the audited documentation:

markdown
https://restapi.amap.com/v3/geocode/geo?address={address}&key={API_KEY}

https://restapi.amap.com/v3/direction/driving?origin={longitude,latitude}&destination={longitude,latitude}&key={API_KEY}

https://restapi.amap.com/v3/direction/driving?origin={origin}&destination={destination}&waypoints={waypoints}&key={API_KEY}

To configure the Amap API key:
- Environment variable: `AMAP_WEBSERVICE_KEY`
- Or use it directly in code

Technical Analysis

The Skill documentation explicitly permits placing the Amap API key directly in application code. Secrets embedded in source code can be disclosed through source repositories, packaged Skill artifacts, backups, debugging output, or accidental file sharing.

The documented API requests also transmit the key as a URL query parameter. Although this is part of the external API's documented request format, complete URLs may be captured by application logs, proxy logs, monitoring systems, browser history, or diagnostic traces. Any component recording an unredacted request URL could therefore expose the key.

No actual API key was found in the audited project, so exploitation depends on a user following the unsafe configuration guidance or logging complete request URLs.

Attack Path

  1. An operator follows the documentation and embeds an Amap API key directly in code, or deploys requests with unredacted URL logging.
  2. The source file, packaged Skill, repository history, application log, proxy log, or diagnostic trace becomes accessible to another party.
  3. The other party extracts the API key from the source or the key query parameter.
  4. The exposed key is used ...[truncated 752 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the recommendation to place the API key directly in source code.
  2. Require the key to be supplied through AMAP_WEBSERVICE_KEY or a managed secret store.
  3. Ensure that source files, configuration templates, examples, and cached data never contain real keys.
  4. Configure application, proxy, and monitoring systems to redact the key query parameter before storing request URLs.
  5. Disable verbose HTTP logging in production unless sensitive query parameters are reliably filtered.
  6. Apply the narrowest available API, service, source-address, domain, quota, and usage restrictions to the key.
  7. Add documented procedures for key revocation and rotation.
  8. Add secret scanning to repository and release workflows to detect accidentally committed Amap keys.
  9. If a key has previously been embedded in source or written to logs, rotate it and remove it from repository history and retained logs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill expands from toll-saving route planning into destination restriction and plate-number checks, increasing data use and external-query scope beyond the narrow stated purpose. This kind of scope creep raises privacy and transparency risks because users may not expect destination compliance profiling when asking for a route.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Broad trigger phrases such as generic route or fee questions can cause the skill to activate in ordinary conversations where the user did not intend this specific workflow. In this skill, misfires are more concerning because activation can lead to collection of plate information and transmission of location/address data to third-party APIs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly requires collecting vehicle plate/city information and uses it for restriction checks and policy eligibility, which introduces personal-data handling beyond minimal route planning. Plate/city data can be sensitive when linked to travel plans, and the document does not define minimization, retention limits, or user consent for any storage or reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs writing a local cache file but does not clearly disclose to the user that data will be persisted on disk. Undisclosed local persistence undermines informed consent and can expose policy lookups, usage patterns, or future expanded cached content to other processes or users with access to the shared workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented use of Amap geocoding and routing APIs implies sending user-provided addresses, origin/destination, and possibly waypoint data to a third party without clear notice. Because this skill handles real-world travel plans and plate-related context, third-party transmission can reveal sensitive movement patterns and should be transparently disclosed and minimized.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The documented cache writes policy data to a shared workspace path, creating local persistence not obvious from the main skill description. Even if the example shows policy text rather than direct identifiers, shared-path persistence can expose usage patterns, enable cross-session data leakage, and become riskier if future implementations also cache user-specific inputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JSON file contains natural-language policy content exclusively in Chinese, including keys and policy strings, but does not indicate that the skill is region-specific or that users can opt into this locale. Under the language/locale policy rule, forcing a specific language without user choice or documented justification can be a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.