Back to skill

Security audit

xiaoyuan-calc

Security checks for vulnerabilities and agentic risk

Overview

This calculator appears functional, but it sends every calculation input to an external service and logs the raw input without clearly warning users.

Review before installing if you may calculate confidential formulas, private coursework, business data, research values, or anything sensitive. Treat calculator results as data from an external service, and avoid relying on this skill in workflows that cannot tolerate remote processing, raw input logging, or a stalled network request.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

other

Warning
Location
scripts/calc.py:20
Finding

Undisclosed Transmission of User Input to an External Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/calc.py:41
Finding

Unvalidated External API Content Is Returned Directly to the Invoking Agent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/calc.py:35
Finding

External HTTP Request Has No Connection or Read Timeout

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill manifest does not declare any tool scope or allowed-tools restrictions, yet static analysis indicates the implementation may use network capabilities. For a calculator skill, undeclared network access is unexpected and expands the attack surface by allowing hidden data exfiltration, remote prompt retrieval, or unreviewed third-party dependence without user awareness.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instruction "All inputs must use LaTeX format" effectively requires users to interact using a specialized notation convention, while the skill otherwise advertises multi-language support. This is a natural-language policy concern because the file mandates a specific input language/format without presenting it as an optional mode or offering alternatives.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as a calculator, but it transmits raw user input to a third-party remote service for computation. This creates an undisclosed data-sharing boundary: expressions may contain sensitive information, and users may reasonably expect local calculation rather than network exfiltration to an external provider.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The docstring and CLI output use Chinese text for instructions and errors, while the script does not offer users an opt-in choice for the interface language. This is a natural-language policy concern because it forces a specific language in user-facing behavior rather than letting the user select the locale.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The runtime error message, usage text, warnings, and examples are all presented only in Chinese. Because the file provides no documented justification that this is a region-specific tool and no interface-language choice, it violates the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script prints the full user-supplied calculation content to stdout before sending it upstream. If expressions include personal, educational, or otherwise sensitive data, those contents may be exposed in logs, terminal history, orchestration logs, or monitoring systems unrelated to the calculator's core function.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.