Back to skill

Security audit

AnswerBox

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherently aimed at selling sealed books, but it collects shipping/contact data, performs in-chat account verification, sends payment links, and stores reusable auth tokens locally with limited disclosure.

Review this carefully before installing. It is not just a recommendation helper: it can collect delivery information, verify a phone or email code in chat, create orders, send Stripe checkout links, and keep reusable account tokens under ~/.answerbox/session.json. Use it only if you trust the AnswerBox service and are comfortable with local session-token storage and in-chat OTP/account binding.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- Never reveal or guess the title, author, ISBN, cover, or plot. Do not search the web to identify the book. The mask, the reason, and the price are the whole card.
- Never send the user to a login, signup, or account page. The only page they open is the card payment link.
- Never print access tokens, refresh tokens, or the session file. Confirm the account with `accountLabel` only.
- If `status` is `crisis`, show `reply` and every hotline, then stop. Do not recommend or sell.
- Mainland China shipping is free. Overseas shipping is ¥50 once per order. Do not invent another fee.
- The price in the response is the price. Do not invent a discount.

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The instruction to automatically attach an existing access token to backend calls extends authenticated state across conversations without any fresh user confirmation. If the local session is stale, shared, or compromised, requests may be executed under the wrong account context.

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

A correction, or "换一本" after the list runs out, stays on the same shelf. Then send prior user lines as history (last 4), the saved need, and conversationId.

Save the returned need and conversationId. If the session already has an access token, send it too. 2. Understanding, then one card. If books is empty, say reply and ask what is going on, in one sentence. Otherwise, before the first book of this reply, print need and the website link. Skip a line when that field is null or empty.

text

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The bind flow instructs the agent to authenticate users in-chat via one-time codes and then proceed directly to payment based on any stored access token. This creates a sensitive credential-handling workflow inside the chat agent, increasing phishing, account mix-up, and session-hijack risk if messages or local state are exposed.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

text

   Skip any part they already gave. Remember `region` as `CN` or `OVERSEAS` for the order.
4. **Bind, in this chat.** If the session has an access token, skip to payment. If not, do not say "注册" or "登录".
   - The delivery number is a mainland mobile (`1` then 10 digits, or already `+86`): send `channel: "phone"` to that number. Say: "验证码发到这个手机了。回我 6 位数字,订单就记在你名下。不用打开网页。"
   - Otherwise ask once: "验证码发到邮箱,还是发到一个大陆手机号?" Then send that channel.
   - If phone send fails because SMS is not configured, ask for an email and continue. Do not stop.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill says to use it when someone wants a book, a surprise, or a gift, and explicitly includes broad phrases like 惊喜, 送礼, 礼物, and 送自己. These are common everyday topics and the file does not provide exclusion conditions or tighter trigger constraints, which could cause unintended activation outside the intended purchasing flow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest frames the skill as simple book/gift recommendation, but the instructions expand it into a transactional commerce flow that collects address data, performs identity verification, and drives payment. This mismatch can mislead users and reviewers about the true scope of data handling and security exposure, reducing informed consent and oversight.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to collect delivery address and perform phone/email verification in-chat without an upfront privacy notice or explicit consent boundary. Users may reveal personally identifiable information before understanding that it will be used for ordering and account binding.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill persists session state, account labels, and authentication tokens in the user's home directory without that behavior being clearly disclosed in the manifest. Hidden local storage of sensitive auth material increases the risk of token theft, cross-skill misuse, and privacy harm on shared or compromised systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The session-file section documents storage of tokens and account data in a local file, but does not warn the user that sensitive information is being written under the home directory. On multi-user systems, synced home folders, backups, or malware-compromised hosts, this can expose reusable credentials and personal data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Collecting and storing access tokens and refresh tokens is a materially sensitive capability that exceeds what users would reasonably expect from a surprise-book recommendation skill. If those tokens are exposed, an attacker could impersonate the user to the backing service and access or manipulate orders/account state.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for people who want to buy a book, get a surprise recommendation, or choose a gift. While recommendations are aligned, this file also documents identity binding via OTP, persistent session handling, order creation, payment checkout, and detailed order retrieval including phone, address, and tracking data, which are materially broader operational capabilities than the manifest description suggests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown describes collecting and transmitting phone numbers, email addresses, recipient names, and shipping addresses through the API. It does not include any user-facing warning that the skill will send and persist personal contact and delivery information to remote services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to write access and refresh tokens into the session file creates credential-handling risk if the session store is not protected, encrypted, or scoped appropriately. Exposure of these tokens could let another party impersonate the user, place orders, view recipient details, and generate payment links.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The API documentation states that locale is only zh-CN or en-US and region is only CN or OVERSEAS. This is a natural-language locale policy constraint, but the file does not explain user opt-in or justify the limitation as a region-specific tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest frames the skill as something to use when someone wants a book recommendation, a surprise, or a gift. OTP-based account creation, token issuance, refresh flows, and session persistence are identity-management capabilities that are not mentioned in that purpose statement and are not obviously necessary for simple recommendation behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.