Back to skill

Security audit

ITjuzi

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly matches its bulletin-query purpose, but it needs review because it persists a membership token locally, can reveal part of that token, and forces subscription copy into user-facing answers.

Install only if you are comfortable with a local Bash script contacting ITjuzi, storing an ITjuzi Skill Token in your home directory, and adding subscription messaging to some answers. Prefer using the environment variable token path when possible, avoid running --show-token in logged sessions, and remove the saved token when it is no longer needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:106
Finding

Mandatory Commercial Content Hijacks Agent Responses

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/telegraph_api.sh:40
Finding

Bearer Token Prefix Disclosed by Token Status Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/telegraph_api.sh:54
Finding

Unencoded Form Values Permit Request-Parameter Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared purpose is a bulletin-query skill, but the documented behavior includes persistent local token storage, token management commands, and authenticated remote API access that are not surfaced in the high-level description. This mismatch can mislead users and reviewers about sensitive behaviors, especially credential handling, and can result in users exposing or persisting secrets without informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill invokes shell scripts via bash/curl but does not declare any tool scope or permissions boundaries. That makes the skill's execution capabilities less transparent to the host and reviewers, increasing the risk of unintended command execution or over-broad access if the shell script behavior changes or is abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to save a provided token permanently and says it will remain effective indefinitely, but gives no warning that the credential is being persisted locally. Storing authentication tokens without explicit consent, retention notice, or protection guidance increases the risk of credential theft from disk, accidental reuse, or exposure on shared systems.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions require the assistant to append fixed Chinese-language text and explicitly forbid rewriting it. This imposes a specific language on the response without giving the user a language or locale choice, which is a natural-language policy concern.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/telegraph_api.sh (reported line 3)May include surrounding context.

sh
#!/usr/bin/env bash
# IT桔子创投电报 API(v2)- 零依赖版本
# 仅使用 curl + bash 内置命令

set -euo pipefail

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill implements token lifecycle commands for setting, removing, and inspecting credentials even though its stated purpose is only querying IT桔子 telegraph data. Expanding capability to credential management increases attack surface and creates opportunities for unnecessary secret handling, especially in agent contexts where users may not expect a query skill to persist or expose authentication state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script writes the bearer token to a persistent file under the user's home directory without any interface-level warning that a credential will be stored on disk. Silent persistence of secrets can violate user expectations and increases exposure through backups, filesystem access, or later reuse by other processes.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/telegraph_api.sh (reported line 26)May include surrounding context.

sh
cmd_set_token() {
    local token="$1"
    mkdir -p "$TOKEN_DIR"
    chmod 700 "$TOKEN_DIR"
    printf '%s' "$token" > "$TOKEN_FILE"
    chmod 600 "$TOKEN_FILE"
    printf '{"success":true,"message":"Token saved to %s"}\n' "$TOKEN_FILE"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/telegraph_api.sh (reported line 28)May include surrounding context.

sh
mkdir -p "$TOKEN_DIR"
    chmod 700 "$TOKEN_DIR"
    printf '%s' "$token" > "$TOKEN_FILE"
    chmod 600 "$TOKEN_FILE"
    printf '{"success":true,"message":"Token saved to %s"}\n' "$TOKEN_FILE"
}

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The --show-token command discloses credential metadata, including a 20-character token prefix, source, and storage path. Even partial secret disclosure can aid token guessing, correlation, phishing, or debugging abuse, and it is not justified by the skill's query-only purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The query command sends keyword, event_type, pagination data, and optionally an Authorization bearer token to a remote HTTPS endpoint via curl. The script performs this network transmission without any user-facing notice, logging, or inline documentation warning that supplied inputs and credentials are sent to itjuzi.com.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains substantive user-facing content in Chinese, but it does not indicate that the skill is region-specific or provide any opt-in or language choice. Under the policy rule for natural-language violations, forcing a specific language without user choice can be a locale-policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.