T08 · Insecure Dependencies
- Location
SKILL.md:177- Finding
Unpinned Global Third-Party Package Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This movie-recommendation skill mostly matches its stated purpose, but it asks the agent to install global browser tooling and run a lingering local web server from a shared temp folder, so it needs review before installation.
Review before installing. Use the skill only in a restricted environment, avoid running the global agent-browser install from the skill, and do not use the chart screenshot workflow unless it is changed to serve only a private temporary directory bound to localhost with guaranteed cleanup. Expect movie, city, location, and preference queries to be sent to external search or movie-data providers.
SKILL.md:177Unpinned Global Third-Party Package Installation
SKILL.md:531Shared Temporary Directory Exposed Through a Persistent Network Server
The declared purpose is movie recommendation, but the skill also instructs local file creation, browser/server orchestration, and ancillary data collection not reflected in the description. This mismatch undermines informed consent and review, because operators may approve a low-risk content skill that actually performs higher-risk actions.
The manifest description says the skill provides '附近影院排片' (nearby cinema showtimes), which implies location-aware theater or schedule retrieval. In code, the implemented behavior is limited to fetching Rotten Tomatoes movie listings and Variety box-office data; there is no location input, theater lookup, or showtime retrieval anywhere in the file.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 测试博查 API
curl -X POST "https://api.bocha.cn/v1/web-search" \
-H "Authorization: Bearer $BOCHA_API_KEY" \
-d '{"query":"猫眼电影 上海 今日排片"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 测试博查 API
curl -X POST "https://api.bocha.cn/v1/web-search" \
-H "Authorization: Bearer $BOCHA_API_KEY" \
-d '{"query":"猫眼电影 上海 今日排片"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 测试博查 API
curl -X POST "https://api.bocha.cn/v1/web-search" \
-H "Authorization: Bearer $BOCHA_API_KEY" \
-d '{"query":"猫眼电影 上海 今日排片"}'
The manual trigger phrases are broad conversational requests such as asking what movies are good to watch, which can overlap with normal user speech and cause the skill to activate unintentionally. In an agent environment, this increases the chance of unexpected external fetching, scheduled recommendations, or context switching without clear user intent, even though the skill itself appears low-risk in function.
The skill requests or demonstrates network access and local file writing but does not declare an explicit tool/permission scope. That makes the effective capability set ambiguous and increases the chance that an agent executes higher-risk actions than reviewers or users expect.
The manifest description and the entire instruction set are written as a China-specific movie recommendation workflow, but there is no natural-language statement offering output language choice or clarifying that the skill is intentionally limited to Chinese-speaking users. Under the locale policy, forcing a specific language without opt-in can be a policy violation unless clearly justified.
The activation examples include broad natural phrases like “帮我选一部电影” and “今天想去看电影,” which are common conversational requests and not narrowly scoped skill invocations. The description also says the skill triggers on '等问题', without negative examples or boundary conditions, making activation scope ambiguous.
The hardcoded external domain reference reinforces that the skill is designed to exfiltrate query content to a nonlocal service. While not malicious on its face, repeated direct endpoint usage without declared scope or privacy controls increases data-handling risk.
# 1. 实时排片(优先使用博查 API)
curl -X POST "https://api.bocha.cn/v1/web-search" \
-H "Authorization: Bearer $BOCHA_API_KEY" \
-d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'
The hardcoded external domain reference reinforces that the skill is designed to exfiltrate query content to a nonlocal service. While not malicious on its face, repeated direct endpoint usage without declared scope or privacy controls increases data-handling risk.
# 1. 实时排片(优先使用博查 API)
curl -X POST "https://api.bocha.cn/v1/web-search" \
-H "Authorization: Bearer $BOCHA_API_KEY" \
-d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'
This additional external endpoint use expands the same privacy and governance concern to box-office lookups. The risk is moderate because it broadens outbound data paths and normalizes direct API calls from a content-oriented skill.
-d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'
# 2. 票房数据(博查 API)
curl -X POST "https://api.bocha.cn/v1/web-search" \
-H "Authorization: Bearer $BOCHA_API_KEY" \
-d '{"query":"猫眼专业版 实时票房 [日期]"}'
The skill instructs package installation and browser dependency setup for a task that should only require fetching and formatting movie data. Allowing installation commands expands the attack surface dramatically by enabling arbitrary code acquisition and system modification in the runtime environment.
The repeated direct bocha.cn reference at this location confirms third-party transmission as an operational dependency. In combination with broad triggers and execution instructions, the skill context makes this more dangerous because more conversations may cause unreviewed outbound requests.
curl -X POST "https://api.bocha.cn/v1/web-search" \
-H "Authorization: Bearer $BOCHA_API_KEY" \
-d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'
The repeated direct bocha.cn reference at this location confirms third-party transmission as an operational dependency. In combination with broad triggers and execution instructions, the skill context makes this more dangerous because more conversations may cause unreviewed outbound requests.
curl -X POST "https://api.bocha.cn/v1/web-search" \
-H "Authorization: Bearer $BOCHA_API_KEY" \
-d '{"query":"猫眼电影 [城市] [片名] 今日排片 场次 [日期]"}'
The skill directs starting a local HTTP server and issuing shell commands solely to render charts. Even if framed as visualization, spawning services and executing shell commands is outside the minimally necessary scope for recommendation output and can be abused for persistence, data exposure, or arbitrary local content serving.
The skill includes background execution, sleep-based process coordination, screenshots, and message sending for chart generation. This combination materially exceeds a simple data-retrieval skill and creates a reusable execution pattern for running and hiding auxiliary processes.
Using nohup and background execution creates persistence beyond the immediate action, leaving a local HTTP server running after the task. Persistent processes increase the risk of unintended exposure of temporary files, port conflicts, and a foothold for later misuse within the session.
write path=/tmp/nowplaying-chart.html content="<html>..."
# 2. 启动 HTTP 服务器(后台)
exec command="cd /tmp && nohup python3 -m http.server 8888 > /tmp/http.log 2>&1 &" background=true
# 3. 等待服务器启动
exec command="sleep 2"
The repeated server/shell orchestration for radar-chart generation confirms that broad execution capability is embedded as a standard part of the skill. Repetition increases risk because it normalizes privileged operations and provides multiple opportunities for misuse or later prompt-injection-driven expansion.
This is a second persistence pattern for the radar-chart workflow, again leaving a background HTTP server active. Repeated persistence instructions show that lingering processes are part of the intended design rather than an accidental artifact, which materially elevates operational risk.
write path=/tmp/nowplaying-charts.html content="<html>..."
# 2. 启动 HTTP 服务器(后台)
exec command="cd /tmp && nohup python3 -m http.server 8888 > /tmp/http.log 2>&1 &" background=true
# 3. 等待服务器启动
exec command="sleep 2"
The manifest advertises '多维度评分' (multi-dimensional ratings), suggesting multiple rating sources or rating facets. The code only parses one numeric percentage from Rotten Tomatoes and does not aggregate or present additional rating dimensions such as audience score, critic count, IMDb, Metacritic, or other factors.
The stated purpose is current theatrical recommendations, ratings, and nearby cinema schedules. Fetching and summarizing Variety box-office news is a distinct media-news capability that is not necessary to provide now-playing recommendations or theater listings, making it an unjustified expansion of scope.
The skill description is entirely presented in Chinese and does not indicate that users may choose another language or locale. Under the language/locale policy, a fixed language should be optional or clearly justified as region-specific.
No suspicious patterns detected.