Back to skill

Security audit

苏宁帮客预约服务

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to book a real Suning service appointment, but it can activate from generic repair complaints and sends phone numbers and fault details to a production endpoint with limited user-facing privacy disclosure.

Review this skill before installing. It should only be used when you explicitly want to book Suning Bangke service, and the agent should tell you exactly what phone number and fault description will be sent to Suning before submitting anything. Avoid running the sample curl command with real personal data in visible command-line arguments or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:45
Finding

Personally Identifiable Information Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 45–48
Vulnerability Type: Plaintext sensitive data in process arguments
Risk Level: Medium

bash
curl -X POST "https://asapps.suning.com/asapps/mcp/serviceReserveNew" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "phone=13812345678" \
  --data-urlencode "serviceDescription=[fault description]"

The final parameter above represents the non-English example fault description in the source while preserving its security-relevant placement as a command-line argument.

Technical Analysis

The documented command places a user's phone number and appliance fault description directly in curl command-line arguments. Although HTTPS protects the request in transit and POST keeps these values out of the URL query string, neither control prevents local disclosure through process inspection, command-execution auditing, terminal capture, shell history, or orchestration logs.

Any implementation that substitutes real user information into this command may expose that information for the lifetime of the process or retain it in local records. The document's claim that POST avoids sensitive-data logging is incomplete because POST only changes where the HTTP data is placed; it does not protect command-line arguments or prevent the receiving service from logging request bodies.

Attack Path

  1. A user provides a phone number and fault description to the Skill.
  2. The Agent confirms the information and substitutes it into the documented curl command.
  3. The command executes with both values present in its process argument vector.
  4. A local user, process monitor, command-auditing service, terminal recorder, shell-history mechanism, or execution platform captures the arguments.
  5. The observer retrieves the user's phone number and potentially sensitive household-service information.

Exploitation requires access to local process metadata or re ...[truncated 713 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not place phone numbers, fault descriptions, or other personal data directly in command-line arguments.
  • Submit the encoded request body through standard input where supported, or use an application HTTP client that keeps sensitive values in memory rather than in the process argument vector.
  • If temporary files are unavoidable, create them with owner-only permissions, use unpredictable filenames, prevent symbolic-link attacks, and delete them immediately after use.
  • Disable or avoid shell-history recording for commands handling personal information.
  • Redact phone numbers and service descriptions from Agent traces, terminal output, process-execution logs, error messages, and observability systems.
  • Validate phone-number format and constrain the maximum length of the fault description before submission.
  • Continue requiring explicit user confirmation before transmission.
  • Update the security documentation to clarify that HTTPS and POST protect transport and URL placement, but do not prevent local process metadata or server-side request-body logging.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation phrases are broad enough to trigger on generic repair-related conversation such as '空调坏了' or '电器坏了', even when the user did not explicitly ask to use Suning's service. This can cause unintended collection of phone numbers and routing of user data into a third-party booking flow without sufficiently clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to collect a phone number and fault description, but it does not clearly disclose before collection/submission that this information will be sent to a third-party production endpoint. This undermines informed consent and creates privacy risk because users may believe they are only chatting locally with the assistant.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This skill directs the agent to transmit user-provided phone numbers and fault descriptions to an external production service. While the business purpose appears legitimate, external transmission of PII is still security-relevant and becomes dangerous if done without strict validation, user consent, and clear disclosure.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

执行命令示例:

bash
curl -X POST "https://asapps.suning.com/asapps/mcp/serviceReserveNew" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "phone=13812345678" \
  --data-urlencode "serviceDescription=空调坏了"

Vague Triggers

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description states the skill supports appointment ordering based on a phone number and fault description, but it does not define clear activation boundaries, eligible contexts, or trigger constraints. In an agent ecosystem, vague scope can cause the skill to be invoked too broadly for user requests involving contact details or repair issues, increasing the chance of unintended data handling or unauthorized actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.