Back to skill

Security audit

CineScope XHS

Security checks for vulnerabilities and agentic risk

Overview

This movie review skill is coherent and disclosed, but users should know it sends movie-related searches to external services and may generate an HTML chart that loads Chart.js from a CDN.

Install this only if you are comfortable with movie titles and related query terms being sent to external search providers such as Tavily and Bocha. Prefer the Markdown or ASCII chart output in sensitive environments, and avoid opening generated HTML reports with JavaScript enabled unless you trust the rendering context and CDN dependency.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:272
Finding

Runtime Loading of Third-Party JavaScript Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 272
Vulnerability Type: Unverified remote JavaScript dependency
Risk Level: Medium

Vulnerable Code

html
<script src="https://cdnjs.cloudflare.com/ajax/libs/Chart.js/4.4.1/chart.umd.js"></script>

Technical Analysis

The HTML report template instructs compatible rendering platforms to retrieve and execute Chart.js from a third-party CDN at runtime. Although the dependency URL pins version 4.4.1, the script element does not specify a Subresource Integrity hash. The effective executable content therefore depends on the response supplied by the external CDN when the report is opened, rather than solely on content reviewed within the Skill package.

This behavior is not necessary for the core movie-review functionality. The Skill already defines non-executable Markdown and ASCII visualization alternatives. Runtime JavaScript should consequently be treated as an optional capability requiring additional safeguards.

The issue depends on the destination platform permitting generated HTML to execute JavaScript and allowing outbound access to the CDN. Platforms that sanitize script elements or use the text-only visualization options are not directly affected.

Attack Path

  1. An agent follows the HTML visualization instructions and produces a report containing the remote script element.
  2. A user opens the report in a renderer that permits JavaScript execution and outbound CDN requests.
  3. The renderer requests chart.umd.js from the external CDN.
  4. An attacker who has compromised the CDN artifact, delivery infrastructure, or another trusted delivery component supplies modified JavaScript.
  5. Because no integrity hash is present, the renderer accepts and executes the modified response.
  6. The payload operates with the privileges available to JavaScript in that rendering context.

Impact Assessment

Successful exploitation could permit a ...[truncated 836 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer the Skill's Markdown bar chart or ASCII visualization, which provides the required reporting capability without executing remote code.

  2. If an interactive chart is required, bundle a reviewed Chart.js file locally and serve it from a trusted, version-controlled location.

  3. If CDN loading must remain supported, add a verified Subresource Integrity hash and an appropriate CORS mode:

    html
    <script
      src="https://cdnjs.cloudflare.com/ajax/libs/Chart.js/4.4.1/chart.umd.js"
      integrity="sha384-REPLACE_WITH_VERIFIED_HASH"
      crossorigin="anonymous"></script>
    

    The placeholder must be replaced with a hash independently verified against the exact approved artifact.

  4. Apply a restrictive Content Security Policy that allows scripts only from explicitly approved sources and disallows unsafe inline execution where feasible.

  5. Render generated reports in a sandboxed, origin-isolated context without access to host credentials, privileged APIs, or sensitive same-origin storage.

  6. Document the external request and obtain user approval before enabling executable HTML visualizations.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is configured to trigger on very broad movie-related conversation, including casual mention of a film name with a question tone, and even says it 'must' be used. Overbroad auto-invocation can cause unintended tool use and external lookups without clear user intent, increasing privacy exposure and the chance of unnecessary outbound requests.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description is written as a Chinese-only capability statement and the file consistently instructs outputs in Chinese, but it does not say the skill is optional only for Chinese-language users or provide any language-selection mechanism. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy issue.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

md
**调用策略:**
1. 优先使用 `tavily-search` 进行主检索(支持 `--deep` 深度搜索)
2. 如 Tavily API 异常/无结果,降级使用 `博查 API`(Endpoint: `https://api.bocha.cn/v1/web-search`)
3. 需要获取具体页面内容时,使用 `tavily-search extract` 或 `web_fetch`

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 490)May include surrounding context.

md
**调用策略:**
1. 优先使用 `tavily-search` 进行主检索(支持 `--deep` 深度搜索)
2. 如 Tavily API 异常/无结果,降级使用 `博查 API`(Endpoint: `https://api.bocha.cn/v1/web-search`)
3. 需要获取具体页面内容时,使用 `tavily-search extract` 或 `web_fetch`

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 491)May include surrounding context.

md
**调用策略:**
1. 优先使用 `tavily-search` 进行主检索(支持 `--deep` 深度搜索)
2. 如 Tavily API 异常/无结果,降级使用 `博查 API`(Endpoint: `https://api.bocha.cn/v1/web-search`)
3. 需要获取具体页面内容时,使用 `tavily-search extract` 或 `web_fetch`

---

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This skill instructs the agent to send user-derived movie queries to a third-party API using an authorization token. Any automatic transmission of user input to external services creates data exposure risk, especially because the skill also encourages broad triggering, which makes unintended outbound sharing more likely.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
# 博查 API 备用搜索
# (当 Tavily API 异常时使用)
# API 文档:https://open.bochaai.com/
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ${BOCHA_API_KEY}" \
  -d '{"query":"夜王 电影 豆瓣评分"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This skill instructs the agent to send user-derived movie queries to a third-party API using an authorization token. Any automatic transmission of user input to external services creates data exposure risk, especially because the skill also encourages broad triggering, which makes unintended outbound sharing more likely.

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
# 博查 API 备用搜索
# (当 Tavily API 异常时使用)
# API 文档:https://open.bochaai.com/
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer ${BOCHA_API_KEY}" \
  -d '{"query":"夜王 电影 豆瓣评分"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The configuration section includes executable examples that transmit queries and documents to external Bocha endpoints with a bearer token. Even as documentation, this normalizes sending potentially user-supplied content off-platform and could expose sensitive prompts or content if reused without guardrails.

Content

Scanner excerpt · SKILL.md (reported line 471)May include surrounding context.

bash
# Web Search API
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"夜王 电影 豆瓣评分"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The configuration section includes executable examples that transmit queries and documents to external Bocha endpoints with a bearer token. Even as documentation, this normalizes sending potentially user-supplied content off-platform and could expose sensitive prompts or content if reused without guardrails.

Content

Scanner excerpt · SKILL.md (reported line 471)May include surrounding context.

bash
# Web Search API
curl -X POST "https://api.bocha.cn/v1/web-search" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"夜王 电影 豆瓣评分"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The reranker example sends a query plus an arbitrary document array to a third-party endpoint, which increases exposure because larger chunks of content may be transmitted externally. If user-provided notes, chat excerpts, or internal text are included, this can leak more sensitive material than a simple search query.

Content

Scanner excerpt · SKILL.md (reported line 477)May include surrounding context.

md
-d '{"query":"夜王 电影 豆瓣评分"}'

# Reranker API(可选,用于语义排序)
curl -X POST "https://api.bocha.cn/v1/rerank" \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $BOCHA_API_KEY" \
  -d '{"query":"夜王 影评","documents":["文档 1","文档 2"]}'

Static analysis

No suspicious patterns detected.