T09 · Insecure Skill Coding Practices
- Location
SKILL.md:77- Finding
Shell Command Injection Through Unvalidated City Input
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly travel-related, but it asks for broad browser, shell, authenticated-session, and recurring-task behavior without enough safeguards.
Review before installing. Use a dedicated browser profile or low-privilege accounts, avoid enabling the documented price-monitor cron task unless it has an expiry and cancellation path, and prefer the Python weather script or encoded HTTP calls instead of shell curl. Treat scraped Xiaohongshu content and links as untrusted and confirm before any authenticated browsing or booking-related action.
SKILL.md:77Shell Command Injection Through Unvalidated City Input
references/examples.md:199Persistent Recurring Task Created Without Lifecycle Safeguards
references/prompts.md:9Indirect Prompt Injection Through Untrusted Social-Media Content
The declared description presents an end-to-end travel research and booking assistant with multiple external data-gathering capabilities. The supplied code chunk is only a report generator. It accepts already-prepared JSON inputs, formats them into a report, computes a simple budget range by adding a flight price, and saves the output. There is no network access, no scraping/searching of Xiaohongshu, no querying of Fliggy, no weather API use, and no evidence of smart caching or parallel execution. While the generated report structure is consistent with travel planning, the code does not implement most of the substantive capabilities claimed in the description.
The declared description presents a broad end-to-end travel planning skill with multi-source research, flight price querying, booking assistance, and report generation. The supplied code only implements weather forecast retrieval for a destination city using external weather APIs and output formatting. Weather fetching is one small subset of the declared functionality, but the primary purpose of this code chunk is materially narrower than the declared skill behavior. There are no signs of unrelated harmful behavior, but there is a clear description-to-code mismatch because the major advertised capabilities are absent.
The declared description promises an end-to-end trip planning skill with multiple integrated capabilities: Xiaohongshu research, flight price lookup on Fliggy, weather retrieval, and final report generation. The provided code chunk is much narrower: it is a single script for Xiaohongshu-related processing only, and even that functionality is mostly unimplemented placeholders marked TODO. The script accepts destination/keyword arguments, calls a stub search function that returns no results, calls a stub extraction function that returns an empty structure, and writes/prints JSON. There is no evidence of Fliggy access, weather APIs, booking assistance, report synthesis, smart caching, or parallel execution. This is therefore a clear description-to-behavior mismatch, primarily because the actual code implements only a partial and largely nonfunctional subset of the declared purpose.
The activation examples are broad, ordinary travel-planning phrases that closely match normal user conversation, increasing the chance the skill is invoked unintentionally. Because this skill performs automated browsing and may use logged-in travel-platform sessions, unintended invocation could trigger account-backed actions or expose personal session context without the user explicitly opting in.
These additional examples further normalize broad natural-language triggers without clear boundaries for when the automation should activate. In the context of a travel-booking assistant that searches third-party sites and may reuse browser sessions, ambiguous triggering raises the risk of unintended data access, unnecessary browsing, or accidental progression toward authenticated workflows.
The README mentions browser profile reuse and login persistence but does not adequately warn that automated browsing under an authenticated Fliggy or Xiaohongshu session can expose personal account data, saved traveler information, order history, or other sensitive session-scoped content. This is more dangerous in this skill’s context because travel platforms commonly contain PII and payment-adjacent data, and session reuse increases the chance that automation operates with more privilege than the user expects.
The README presents scripts/query_weather.py as an existing component in the current skill structure at L100, which implies weather-query functionality is already part of the skill. However, L186 lists destination weather querying as a future optimization item, contradicting the earlier documentation about current capabilities.
The skill document describes use of network access, browser automation, shell execution via curl, and caching, but it does not declare any explicit tool scope or permission boundaries. Missing scope declarations can cause the runtime or reviewer to underestimate the skill’s external access and execution capabilities, reducing user consent and security review effectiveness.
The skill description does not warn users that it will contact third-party weather and travel services, despite explicit instructions to open Xiaohongshu and Fliggy pages and issue a curl request to wttr.in. This creates a transparency and privacy risk because user-supplied itineraries, destinations, and travel dates may be transmitted off-platform without clear disclosure.
The title, instructions, examples, and output expectations are written to operate in Chinese and target Chinese travel platforms, but there is no opt-in or documented locale constraint. This creates a natural-language policy issue because the skill effectively imposes a language/locale on users without presenting a choice or clearly justifying the restriction.
The invocation examples are broad enough to match ordinary travel-planning requests, which can cause the skill to activate unexpectedly in contexts where the user did not intend third-party lookups or browser automation. Because this skill is designed to make external requests, overbroad triggering increases the chance of silent data disclosure about travel plans, dates, or destinations to outside services.
The workflow explicitly relies on persistent logged-in sessions for Xiaohongshu and Fliggy and instructs manual QR-code login, but provides no user-facing warning, consent, or account-scope limitation guidance. That creates a real privacy and account-use risk because the automation may act within a user's authenticated browser context, exposing personal account data, saved preferences, or booking history beyond what is needed for itinerary research.
The example documents a cron-based price monitoring workflow that creates ongoing behavior and user notifications, which goes beyond one-shot trip research/report generation described in the skill metadata. Even in documentation, this can normalize deployment of persistent automation without clear scope, consent, retention, or lifecycle controls, leading to surprise background actions and policy drift.
The example instructs the skill to set up daily monitoring and notify the user when a threshold is met, but it does not warn that this creates persistent background processing. Users may believe they are making a one-time query when they are actually authorizing continuous checks and outbound notifications, which is a transparency and consent failure.
This markdown file defines all prompts, field names, examples, and output conventions entirely in Chinese, including explicit output tokens such as "待补充" and Chinese schema labels. Because the skill does not offer a language choice or explain that it is intentionally limited to a Chinese-language/Xiaohongshu-specific context, it creates a natural-language locale policy concern.
The module docstring presents the skill's purpose exclusively in Chinese. This is a natural-language locale policy issue because the file forces one language for user-facing documentation without offering an opt-in or documenting a justified region-specific constraint.
The module docstring and argument help text are entirely in Chinese, and the Open-Meteo path explicitly documents city as Chinese-only input. This imposes a language/locale constraint without user opt-in or a documented justification that the tool is region-specific.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
try:
url = (
f"https://api.open-meteo.com/v1/forecast"
f"?latitude={coords['lat']}"
f"&longitude={coords['lon']}"
f"&daily=weather_code,temperature_2m_max,temperature_2m_min,precipitation_probability_max"
The module docstring is entirely in Chinese and presents the skill as Chinese-language only, with no indication that users may choose another language or locale. The policy explicitly flags language/locale constraints when they are imposed without user opt-in or justification.
The manifest describes an end-to-end travel research component that searches Xiaohongshu and extracts travel insights. In this file, both core functions are stubs marked TODOs: search_xiaohongshu never performs a search and returns an empty list, while extract_travel_info ignores input notes and returns an empty template object.
The skill extracts Xiaohongshu note content, metadata, image URLs, and outbound links, but omits any warning that it is collecting third-party content and links from an external platform. This is risky because downstream users may unknowingly ingest copyrighted or sensitive third-party material, and outbound URLs can carry tracking parameters or lead to unsafe destinations if surfaced without notice or validation.
The documentation recommends constructing direct Fliggy search-result URLs containing trip details such as departure city, arrival city, and travel dates in query parameters, but does not warn that these details may be exposed in browser history, logs, referrers, or screenshots. While the data is not highly sensitive by itself, travel itinerary information is still personal and can be leaked through routine telemetry or shared artifacts.
All user-facing examples and guidance are presented in Chinese, and there is no indication that other languages are supported or that Chinese output is optional. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is documented and justified.
The script sends the requested city to wttr.in and also contacts api.open-meteo.com, which shares user-provided query context with third parties. While network access is central to the script's purpose, there is no visible disclosure in CLI output or comments that destination data is sent to external services.
The docstring for search_xiaohongshu says it searches Xiaohongshu and returns a list of dict of guides. However, the function contains only TODO comments, prints status messages, and returns results initialized as an empty list, which contradicts the documented behavior.
No suspicious patterns detected.