Back to skill

Security audit

网贷援助律师

Security checks for vulnerabilities and agentic risk

Overview

The skill runs locally, but it asks for sensitive debt and income details and then pushes users toward an external assistance channel without enough privacy or independence disclosure.

Review before installing. Use it only if you are comfortable entering debt amount, interest rate, overdue days, platform name, and monthly income into a local CLI. The inspected code does not send that information over the network, but the report promotes an external service; do not share personal financial, identity, contact, or repayment details with that outside channel unless you independently trust it and understand its privacy policy.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
netloan-aid.js:372
Finding

Mandatory Promotional Redirection in Skill Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:53-58, SKILL.md:77-83, and netloan-aid.js:372-383
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

The Skill declares an external consultation funnel as part of its expected output and directs financially vulnerable users to an author-controlled email address and website. The executable also appends promotional content to every generated report, regardless of whether the user requested external assistance.

Complete Code Snippets

SKILL.md:53-58:

markdown
| Module | Description |
|------|------|
| Compliance analysis | Determines whether the interest rate exceeds the legal limit |
| Repayment plans | Extension, installments, reduction, or lump-sum repayment |
| Feasibility assessment | Estimated success probability for each plan |
| Negotiation templates | Suggested language for communicating with the platform |
| Advanced services | Professional customization through a consultation entry point |

The original source presents the above table in Chinese and makes the consultation entry point one of the declared output modules.

SKILL.md:77-83:

markdown
## About the Author

This tool is developed and maintained by Public-Welfare Red Scarf.

If you need a professionally customized repayment plan:
- Email: clear.wd@qq.com
- Free-plan website: https://loan-aid-test-3g6whqku662d13c8.webapps.tcloudbase.com/

The original source contains the same contact details and statements in Chinese.

netloan-aid.js:372-383:

js
// Promotional guidance
console.log('');
sayTitle('🔗 Need more help?');
say(C.bold + C.green + `  📌 The plans above were generated using public regulations and are for reference only.`, C.green);
say(C.bold + C.green + `  📌 If you want to learn more:`, C.green);
sayLine(`    ✓ Minimum repayment plans for different platforms`, C.white);
sayLine(`    ✓ Privacy-preserving 
...[truncated 2803 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the “advanced services” or consultation entry point from the Skill's declared output modules.
  2. Remove the unconditional promotional footer from printReport().
  3. If project contact information must remain, place it in a clearly separated and optional documentation section rather than generated user reports.
  4. Clearly state that any external service is independent, optional, and outside the local tool's privacy guarantees.
  5. Do not encourage users to submit loan, income, identity, contact, or repayment information to an external service without a published privacy policy and explicit informed consent.
  6. Avoid claims about a “professional database,” privacy protection, or improved repayment outcomes unless they are verifiable and accurately scoped.
  7. Add automated tests confirming that normal report generation contains only requested repayment analysis and does not include unsolicited external-service promotion.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents the skill name, usage guidance, and substantive instructions entirely in Chinese, with no indication that users may choose another language. Under the policy, language constraints should be opt-in or clearly justified as region-specific; this README does neither.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation phrase "直接告诉 AI:'我要用网贷援助'" is broad and conversational, which can cause the skill to trigger unintentionally during ordinary discussion about debt, loans, or seeking help. In a high-sensitivity financial/legal-adjacent context, accidental activation could lead users to disclose personal financial details or receive unrequested guidance that appears authoritative.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill title and all user-facing prompts are written only in Chinese, and the implementation does not provide any option for users to select another language or locale. This is a natural-language policy concern because it imposes a specific language on all users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill description and usage instructions are entirely in Chinese and the example invocation assumes Chinese-language interaction, but the file does not indicate that language choice is optional or region-specific by design. This can violate language/locale policy expectations when a skill implicitly requires one language without explicit opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

文件头部功能说明写明“收集用户贷款信息(不收集隐私)”,但后续交互明确询问“你的月收入”,并将其保存到 userInfo.monthly_income 中。月收入属于个人敏感财务信息,因此该说明与实际行为存在直接矛盾。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The package description is entirely in Chinese and presents the skill as a Chinese-language assistant, with no indication that users can choose another language or locale. This can be a language/locale policy concern under the natural-language policy rules when no opt-in or documented regional constraint is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.