Back to skill

Security audit

Parcel Coupon 快递优惠券-支持顺丰、中通、圆通、韵达、申通、菜鸟、同城配送,件件优惠

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches courier coupon links and QR codes from a public API, with no local persistence or credential use, but users should treat the returned links as third-party content.

Install only if you want Chinese-language courier coupon results and are comfortable opening third-party coupon links or QR codes, especially in WeChat. Verify destinations before redeeming offers and avoid entering sensitive information on unexpected pages.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_coupons.py:41
Finding

Unvalidated Remote Coupon Links and Instructions Are Presented as Trusted Content

Content
View full analysis
Remediation
View remediation
2048: raise ValueError("Invalid URL value") parsed = urlparse(value) host = (parsed.hostname or "").lower().rstrip(".") if parsed.scheme != "https": raise ValueEr ...[truncated 405 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The skill instructs users to open the redemption flow in WeChat without presenting this as an optional platform constraint or explaining any regional dependency. This can pressure users into a specific external ecosystem and redirect them to a third-party environment without informed choice, which is risky when the skill also distributes direct links and QR codes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The response field guidance repeatedly prescribes WeChat-based opening and QR scanning as the expected redemption path, but does not capture user preference, consent, or necessity for that platform. Because the skill returns raw external URLs and QR-code images, this platform-specific steering increases the likelihood of funneling users into opaque third-party flows they may not expect.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The trigger conditions are broad enough to match ordinary shipping-related queries such as 'I want to send a package' or 'how can I ship cheaply,' which can cause the skill to activate outside a clearly scoped coupon-request context. This creates a misrouting and promotion risk: users may be steered to an external coupon/redemption flow when they were seeking neutral shipping help, increasing the chance of unsolicited link exposure and unwanted third-party traffic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The core handling rules require the agent to present API-supplied links and QR codes unchanged while also directing users to use them in WeChat. This combination is more dangerous than a simple compatibility note because it removes any opportunity for safety mediation, link normalization, or warning, and can be abused if the upstream API ever returns malicious, deceptive, or tracking-heavy destinations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The entire skill documentation, including headings, field descriptions, and user-facing guidance, is written only in Chinese with no indication that another language is supported or that Chinese is a required locale. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code's docstrings, CLI description, error messages, and formatted output are all in Chinese, and there is no indication that the user can opt into another language. The policy explicitly flags language or locale constraints when a skill forces a specific language without user choice or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The heading uses Chinese text ("外卖优惠券") in an otherwise English reference document, which suggests a language/locale choice without any visible opt-in or explanation. This can conflict with organizational language policy when a skill appears to impose a locale-specific presentation by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The docstring and printed message use Chinese text ('外卖优惠券') with no indication that the skill is region-specific or that users can choose their language/locale. This can violate language/locale policy when a skill implicitly assumes a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.