Back to skill

Security audit

intelligent driving dss智能驾驶决策支持系统

Security checks for vulnerabilities and agentic risk

Overview

The skill is not visibly malicious, but it gives high-stakes driving/legal guidance and includes under-scoped instructions for automatic document downloads and skill-file updates.

Install only if you want a China-focused automotive/legal reference skill and are prepared to manually verify its legal and safety content. Do not allow it to automatically download documents or update skill files; require explicit approval, HTTPS-only sources, staging, checksums, and review before generated reports are reused.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
core-traffic-rules/revision-draft-comparison.md:135
Finding
Unapproved External Document Retrieval and Local File Creation## Vulnerability Details **File Location**: `core-traffic-rules/revision-draft-comparison.md`, lines 135-151 **Related Locations**: `SKILL.md`, lines 23, 49, and 182 **Vulnerability Type**: Insecure automated network and filesystem operations **Risk Level**: Medium ### Complete Vulnerable Snippet The following is a faithful English rendering of the complete affected section: ```markdown ## 6. Follow-up Actions (Pending Trigger) | Action | Trigger Condition | Executor | Output | |---|---|---|---| | Obtain the full revision draft | Published by Xinhua News Agency or Xinhuanet | AI System Architect | Download the PDF to `~/downloads/drafts/` | | Conduct article-by-article comparison | Official draft text received | intelligent-driving-dss Skill | `core-traffic-rules/2026-version-comparison-report.md` | | Update the intelligent-driving module | L3/L4 provision changes confirmed | intelligent-driving-dss Skill | `nev-system-module/intelligent-driving-adaptation-recommendations.md` | | Retest regulatory-checking capability | Differences between versions established | intelligent-driving-dss Skill | `core-function-validation-report.md` | ## 7. Reference Links 1. State Council legislative-plan portal: https://www.gov.cn/liuxiang/gongzuo/xfgz.shtml 2. Ministry of Public Security Traffic Management Bureau: https://www.mps.gov.cn/n16/n905472/n3838/index.html 3. Xinhua legal channel: http://law.news.cn/ This document is the legislative-amendment tracking subfunction of the regulatory-compliance module. The comparison workflow will activate automatically after the 2026 revision draft is officially published. ``` ### Technical Analysis The Skill defines a conditionally activated workflow that downloads an external PDF and writes multiple generated files to local directories. The workflow does not require explicit user approval immediately before either the download or the filesystem writes. It also does not define: ...[truncated 2933 chars]
Remediation
## Remediation Suggestions 1. Remove automatic activation and require explicit, action-specific user confirmation before downloading a document or creating each output file. 2. Allow retrieval only from exact approved HTTPS hostnames. Remove the plain HTTP source, reject unexpected redirects, and validate the final resolved hostname. 3. Download into a dedicated sandboxed temporary directory rather than `~/downloads/`. 4. Enforce strict response-size limits, timeouts, content-type checks, PDF magic-byte validation, and document-parser resource limits. 5. Treat all retrieved document text as untrusted data. Explicitly prohibit following instructions embedded in PDFs, metadata, links, annotations, or extracted text. 6. Present the source URL, checksum, publication date, and proposed destination to the user before processing. 7. Use non-overwriting, collision-resistant filenames and reject symbolic links or paths that resolve outside the approved workspace. 8. Generate reports in a staging directory and require review before moving them into the Skill knowledge base. 9. Record an audit log containing user approval, source URL, final resolved URL, checksum, timestamp, output paths, and validation results. 10. Run document parsing with minimal permissions and without shell execution, external entity resolution, macros, embedded-file execution, or unrestricted network access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (37)

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill hardcodes Chinese legal and regulatory logic as its decision basis without first confirming the user's jurisdiction or clearly constraining outputs to China-only scenarios. In a driving or compliance context, this can cause users to rely on inapplicable legal guidance or operational recommendations, creating safety, compliance, and liability risks when used outside the intended locale.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
This markdown file contains user-facing instructions and usage guidance exclusively in Chinese, and it does not provide any opt-in, alternative locale, or justification that the skill is intended only for Chinese-speaking users. That can violate language/locale policy requirements when users are not explicitly given a choice.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The file presents all instructional and descriptive content in Chinese, including headings and usage context, without indicating that language selection is optional. Under the policy rule for language/locale, this is a natural-language constraint that can exclude users unless the locale limitation is explicitly justified or opt-in.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The section heading states it covers insurance-certificate display obligations, but the body text instead discusses overloaded cargo, warning signs, and safety measures. In a driving decision-support and legal-rules skill, this kind of legal-content mismatch can mislead downstream users or systems about regulatory requirements, causing incorrect compliance guidance or faulty training data.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documented workflow explicitly includes downloading a PDF and creating new files in repository paths, but it does not warn the user or require consent before performing those side effects. Even though the sources listed are official, unattended network retrieval and filesystem writes can introduce unreviewed content, overwrite artifacts, or cause unexpected state changes in an analysis environment.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The phrase indicating the workflow will 'automatically activate' after a future external event is broad and underspecified, which can cause the skill to act without an explicit user-triggered authorization boundary. In this skill, that could lead to autonomous legal-document processing or downstream file operations based solely on detecting a publication event, increasing the risk of unintended execution and trust in unverified external content.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The section titled '变更车道' contains unrelated traffic-signal compliance text, which can cause downstream driving logic or human reviewers to map the wrong rule to lane-change decisions. In an autonomous-driving decision support skill, mislabeled legal/safety rules can directly degrade scenario evaluation, compliance checks, and operational safety.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The section labeled '非机动车混行' actually describes over-limit cargo warning requirements for motor vehicles, creating a direct semantic mismatch in a safety-critical rule base. If consumed by planners, simulators, or compliance modules, this can suppress or misapply mixed-traffic behavior constraints involving bicycles and other non-motor vehicles.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The '摩托车使用' heading is paired with content about freight vehicle passenger restrictions, which can mislead users or systems looking for motorcycle-specific operating requirements. In a driving DSS, such rule corruption can produce incorrect legal assumptions during feature evaluation or edge-case analysis.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The '非机动车停放' section repeats motor-vehicle cargo over-limit requirements, directly conflicting with the title and likely displacing the real parking rules for non-motor vehicles. In this skill's context, omission or corruption of parking/roadside behavior rules can affect urban-scene modeling and policy validation in ways that reduce safety and legal accuracy.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The '电动自行车限速' heading contains text about non-motor-vehicle parking and learning-to-ride approvals rather than speed limits. This can cause analysts or automated components to infer that speed-control constraints are present when they are not, weakening safety assessments for e-bike interactions.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The section titled '行人过街' actually states non-motor-vehicle operating requirements, reversing the apparent subject matter of the rule. In a system intended for autonomous-driving decision support, this can distort pedestrian-crossing logic and non-motor-vehicle behavior modeling in safety-critical scenarios.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The '高速公路入口限制' section begins with speed-limit language rather than entry restrictions, creating ambiguity about what the article actually governs. In a highway-planning or ADS evaluation context, conflating access-control and speed-control rules can lead to incorrect policy enforcement or test-case assumptions.

Intent-Code Divergence

Medium
Confidence
99% confidence
Finding
The '高速公路超车' heading contains fault-stop/shoulder parking guidance instead of overtaking rules, which can misinform both users and automated consumers about permitted highway maneuver behavior. For autonomous-driving support, incorrect highway passing rules can materially affect tactical decision-making and compliance validation.

Description-Behavior Mismatch

Medium
Confidence
97% confidence
Finding
This module materially deviates from the parent skill’s stated purpose of intelligent-driving decision support and instead provides market rankings, purchase guidance, and investment-oriented content. In a safety-adjacent skill, such scope drift is dangerous because it can cause users or downstream agents to invoke unrelated, non-validated functionality under the trust umbrella of an autonomous-driving decision system.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This README forces a specific language/locale for all user-facing instructions and examples. Under the policy, a language-only presentation is a violation unless the skill offers user opt-in or clearly documents a justified region-specific constraint.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The documentation explicitly claims investment decision support despite the skill being described as an intelligent-driving decision support system. This creates unjustified authority and could mislead users into relying on unqualified financial guidance, especially when bundled with a technically sophisticated automotive skill that may appear more trustworthy than it is.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
This JSON skill data is entirely presented in Chinese strings and provides no indication that language selection is optional or constrained by a documented region-specific requirement. Under the policy rule, forcing a specific language without user opt-in is a natural-language locale violation.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The README’s instructional content and descriptions are presented in Chinese, but the file does not indicate that the skill is region-specific or provide any user opt-in or alternative language option. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Natural-Language Policy Violations

Medium
Confidence
83% confidence
Finding
Natural-language descriptions and labels in the file are entirely Chinese, but the file does not state that the skill is region-specific or that language is user-selectable. This can violate language/locale policy when a skill effectively forces one language without opt-in or documented justification.

Vague Triggers

Medium
Confidence
78% confidence
Finding
This manifest-style JSON defines the `findNearestChargingStation` capability but provides no explicit trigger phrases, scope limits, or exclusion conditions describing when it should be invoked. Because the action is location-related and uses user-provided current location, the absence of activation constraints can lead to unintended invocation from broad travel or charging-related requests.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
This markdown file contains user-facing natural-language instructions and examples exclusively in Chinese, and it does not provide any opt-in, alternative language, or justification for restricting usage to a Chinese-speaking audience. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless clearly documented as region-specific.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The module recommends very strong regenerative braking settings, including '-100%(最强)', but does not warn about drivability changes, rear-end collision risk, reduced stability on low-traction surfaces, or the need to calibrate regen behavior to vehicle dynamics and regulations. In an intelligent driving decision-support skill, operators may treat these settings as normative guidance, making omission of safety constraints more dangerous than in a purely descriptive document.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
This markdown file contains user-facing content exclusively in Chinese, while also including English section labels, suggesting it may be intended for a broader audience. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale restriction is explicitly justified.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding
Suspicious Unicode normalization or mixed-script content

Static analysis

No suspicious patterns detected.