Back to skill

Security audit

Trip Coupon 出行优惠券隐藏券-支持滴滴出行、携程礼包(机票、酒店、门票)

Security checks for vulnerabilities and agentic risk

Overview

This skill fetches disclosed travel coupon links and QR codes from a third-party API; the main risk is that users should verify those external redemption destinations before opening them.

Install only if you are comfortable using a third-party coupon API and opening coupon links or QR codes from external domains. Verify the destination before redeeming, especially in WeChat, and treat the unrelated takeout-coupon reference file as documentation clutter rather than the core trip-coupon workflow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_coupons.py:39
Finding

Unvalidated Remote Coupon Destinations Are Presented to Users

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description does not clearly warn that it will contact a third-party API and present redemption URLs and QR codes hosted on external domains. Without an upfront disclosure, users may not realize their request triggers external network access and that following the returned links can send them to unvetted third-party destinations, creating phishing, tracking, and trust risks.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to match generic travel-saving or booking-related requests that are not clearly asking to redeem third-party coupons. This can cause unintended invocation of a networked skill that fetches and promotes external links/QR codes, increasing the chance of surprising users and routing them to third-party destinations without clear prior intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Multiple lines instruct that coupon links should be opened in WeChat or redeemed by scanning in WeChat, which effectively imposes a specific platform/locale usage pattern. The document does not clearly frame this as an optional preference with alternatives or justify it as a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all instructions, field descriptions, and usage details exclusively in Chinese. Under the policy rule for natural-language violations, forcing a single language without user opt-in or a documented regional justification can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The heading uses Chinese text ("外卖优惠券") without any indication that the skill supports multiple languages or that the user opted into a Chinese locale. This can violate language/locale policy when a skill appears to assume a specific language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The docstring and printed message include the Chinese phrase "外卖优惠券" as the skill/topic label, but the file provides no indication that language selection is optional or region-specific. Under the policy, language constraints should be opt-in or clearly justified; otherwise they can constitute a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The top-level docstring is entirely in Chinese and presents the skill as a fixed Chinese-language tool, with no indication that other languages/locales are supported or that the user can opt in to Chinese. The policy for this audit flags language/locale constraints when a skill forces a specific language without user choice or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.