Back to skill

Security audit

返利宝

Security checks for vulnerabilities and agentic risk

Overview

This rebate assistant is not clearly malicious, but it should be reviewed because it can access account data and submit withdrawal requests with broad routing, verbatim output rules, and local sensitive-state storage.

Install only if you trust the rebate backend and hardcoded WeChat/public-account URLs. Be aware that the skill can store OpenID, shopping requests, balances, and pending withdrawal data locally, can use your configured model API key for search-intent parsing, and can submit a withdrawal after an amount is prepared and the user replies with a confirmation phrase.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:20
Finding

Forced Promotional Output and Agent Response Hijacking

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common.js:185
Finding

Sensitive Account and User State Stored Without Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill appears to recognize broader classes of account-status, binding, rebate-detail, and withdrawal-intent messages than the narrow examples disclosed. Broader-than-declared intent handling can trigger sensitive account or financial flows unexpectedly, especially in conversational systems where ambiguous messages may be misclassified into privileged actions.

Content

No source excerpt is available for this finding.

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/common.js (reported line 550)May include surrounding context.

js
if (!state.requests || !state.requests[machineCode]) {
        return;
    }
    delete state.requests[machineCode];
    saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/common.js (reported line 599)May include surrounding context.

js
if (!state.requests || !state.requests[machineCode]) {
        return;
    }
    delete state.requests[machineCode];
    saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · scripts/common.js (reported line 613)May include surrounding context.

js
if (!state.requests || !state.requests[machineCode]) {
        return;
    }
    delete state.requests[machineCode];
    saveJsonFile(exports.PENDING_AUTH_REQUEST_PATH, state);
}
function loadPendingWithdrawState() {

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can submit real withdrawal requests via applyWithdraw(openId, amount) after only conversational flow state and a pending request check. Because this is a real financial action outside the narrow declared purpose of authorization/tutorial, link rebate, and search, it increases the chance of unauthorized or unexpected money movement if the intent classification, local state, or calling context is abused.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/recognizePreciseProductSearch.js (reported line 786)May include surrounding context.

js
if (modelValue && ruleValue) {
        if (preferSpecific) {
            if (GENERIC_ONLY_TERMS.has(modelValue) && !GENERIC_ONLY_TERMS.has(ruleValue)) {
                return ruleValue;
            }
            if (ruleValue.length > modelValue.length && ruleValue.includes(modelValue)) {
                return ruleValue;

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/recognizePreciseProductSearch.js (reported line 789)May include surrounding context.

js
if (modelValue && ruleValue) {
        if (preferSpecific) {
            if (GENERIC_ONLY_TERMS.has(modelValue) && !GENERIC_ONLY_TERMS.has(ruleValue)) {
                return ruleValue;
            }
            if (ruleValue.length > modelValue.length && ruleValue.includes(modelValue)) {
                return ruleValue;

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares executable scripts with shell, network, and environment access, but the manifest/documentation does not define an explicit tool scope such as allowed-tools or permissions. That makes the effective capability boundary opaque to reviewers and increases the risk of unintended command execution, data access, or outbound requests if the runtime grants broad defaults.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Using broad everyday trigger terms like “教程” and “账户余额” can cause accidental activation of the rebate skill or sensitive account flows from messages that were not intended for this skill. In a system that can expose account information or initiate withdrawal preparation, overbroad triggers increase the chance of unintended data access or action routing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description and examples are written as if the skill operates only in Chinese, and the document provides no opt-in or alternative language handling. A skill that effectively forces a specific language without user choice can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The routing rule 'no link + shopping intent => S03' is vague and may over-capture normal conversation into product-search behavior. While lower risk than financial-action misrouting, ambiguous routing can still send unintended user text to downstream search or external APIs, creating privacy and consent concerns.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file contains natural-language user-facing strings in Chinese, and similar Chinese-only messages appear throughout the module. This forces a specific language/locale without any visible opt-in or fallback, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest says the skill only works in three user scenarios: S01 authorization/tutorial, S02 link rebate, and S03 product search, with S03 limited to extracting search info and returning results. This file implements explicit pending-withdraw request creation, loading, expiry, and clearing, which is a distinct提现 transaction workflow rather than merely tutorial or search support.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This utility file loads global model-provider configuration, including base URL and API key, and can make arbitrary chat completion requests. For a rebate assistant whose stated purpose is authorization, rebate-link handling, and product search, access to unrelated workspace-wide LLM credentials expands the skill's privileges and creates a pathway for secret use or exfiltration if any caller can influence prompts or trigger these functions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code reads a configured model API key and uses it in an outbound HTTP Authorization header, which is a sensitive-credential access plus network transmission path. In this file there is no confirmation prompt, user-facing log/print, or comment/docstring warning that the skill will use stored credentials to contact an external model endpoint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

User-facing strings throughout the file are written exclusively in Chinese, including tutorials, prompts, and status messages. This enforces a specific language experience without any visible opt-in, fallback, or documented regional justification in the file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill implements additional sensitive capabilities—account balance lookup, rebate detail retrieval, and withdrawal handling—that are not clearly declared in the stated three-scenario scope. This creates a scope/permission mismatch: users, reviewers, or policy gates may believe the skill only provides tutorial, link conversion, and product search, while the code can trigger financial-account workflows and expose account-linked data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The withdrawal is executed after a generic '确认提现' confirmation, but the user-facing flow does not present a strong warning that this is a real financial operation, may be irreversible once submitted, and will transfer funds based on previously stored state. In chat-driven systems, terse confirmations are error-prone and can be triggered accidentally or via confusing context, increasing the risk of unintended withdrawals.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The embedded system prompt is entirely in Chinese and instructs the model in a fixed language/locale, with no indication that the user can choose another language. This can violate language/locale policy when the skill is expected to adapt to user preference unless the restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.