Back to skill

Security audit

Obtain Coupons All In One 全平台优惠券助手-外卖、快递、出行、电影票一站式获取

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed coupon-fetching helper that contacts listed coupon APIs and displays returned links, codes, and QR images, with no evidence of hidden persistence or local data access.

Install only if you are comfortable with coupon-related requests being sent to agskills.moontai.top and with receiving third-party coupon links or QR images. Verify destinations before opening links or scanning QR codes, and do not treat API-returned guidance as trusted agent instructions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_coupons.py:175
Finding

Untrusted Remote Coupon Content Is Relayed Without Validation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation describes calling multiple third-party coupon APIs but does not clearly warn users that their request context may be sent to external services. This creates a transparency and consent problem: users may unknowingly have their queries or derived parameters transmitted off-platform, which is especially risky when the skill is broadly triggered.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to open links or scan QR codes in WeChat by default, without first confirming user preference or explaining the trust implications of following third-party links in another app. This can steer users into a specific external ecosystem and reduce informed consent around opening potentially opaque redirect links or QR targets.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are broad enough to match ordinary coupon-related requests, which can cause the skill to activate in contexts where the user did not clearly intend to use this third-party coupon service. Because the skill performs network access to external coupon APIs and returns third-party links/QR codes, overbroad triggering increases the chance of unintentional data sharing and unsolicited redirection to external resources.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

自然语言内容多次写明“建议用微信打开”或“使用微信扫描二维码”,但没有提供等效替代方式、用户选择说明,容易构成对特定平台/环境的默认强制倾向。根据该规则,若技能强制或默认特定语言/locale/平台而无用户 opt-in,应视为政策风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring presents the skill entirely in Chinese and describes it as a general-purpose coupon tool, with no indication that Chinese is optional or that the skill is region-specific. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The user-facing description is written entirely in Chinese, which indicates a language-specific skill presentation without any documented opt-in or alternative locale support. Under the policy, forcing a specific language without user choice is a natural-language locale violation unless it is clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

该文件从标题到说明全部使用中文,未提供语言选项、双语说明或明确限定其仅面向中文用户。按照该规则,若技能在自然语言层面强制特定语言且无用户选择,可能构成语言/locale 政策问题。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

该 markdown 文件属于 SQP-2 适用范围。文档在多处指导用户点击 coupon_url 或扫描二维码领取优惠券,但没有任何用户可见的隐私或外部跳转提示;这类行为可能将用户带到第三方页面并触发数据收集,因此应有基本警示。

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

“使用建议”部分反复建议在微信中打开链接或扫码使用,但整份技能文档没有集中说明这些操作会离开当前环境、访问第三方站点,且可能触发跟踪、登录或数据提交。对 markdown 技能描述而言,这是缺失用户警示。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The heading names the skill entirely in Chinese ("全平台优惠券助手") with no indication that users may choose another language or locale. This can constitute a language/locale policy issue because the documentation presents a fixed language context without documenting user choice or a justified regional scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The docstring and printed output hard-code the skill name in Chinese ("全平台优惠券助手") with no indication that the user can choose another language or that the locale is intentionally region-specific. This is a natural-language policy concern because the file presents a fixed language choice rather than offering opt-in or documenting the constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.