Back to skill

Security audit

xpeng-monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent XPeng data monitor, but it asks users for a third-party account password and automatically stores reusable login cookies in a local plaintext file.

Review before installing. Use the China delivery features without account credentials where possible. For Europe data, do not provide a password you reuse elsewhere, and be aware the skill may save eu-evs.com session cookies locally in plaintext for later reuse.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/xpeng_eu_daily.js:256
Finding

Account Password Exposed Through Agent Conversation and Process Arguments

Content
View full analysis
--password `. 4. After successful login, the session is automatically saved in `.eu-session.json`. ``` The script directly reads these secrets from its process arguments at `scripts/xpeng_eu_daily.js:256-273`: ```javascript function parseArgs() { const args = process.argv.slice(2); let year = String(new Date().getFullYear()); let email = null; let password = null; let report = false; for (let i = 0; i < args.length; i++) { if (args[i] === '--email' && i + 1 < args.length) { email = args[++i]; } else if (args[i] === '--password' && i + 1 < args.length) { password = args[++i]; } else if (args[i] === '--report') { report = true; } else if (!args[i].startsWith('--')) { year = args[i]; } } return { year: parseInt(year, 10), email, password, report }; } ``` ### Technical Analysis The workflow requires the user to disclose a reusable account password in the agent conversation. It then transports that password to the Node.js process through `process.argv`. Secrets passed through these channels may be exposed by: - Agent conversation history and orchestration logs. - Tool-call and execution telemetry. - Shell history if a comman ...[truncated 1822 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/xpeng_eu_daily.js:55
Finding

Reusable Authentication Cookies Stored in an Unprotected Plaintext File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill is a monitoring tool focused on two specific datasets: China delivery cycles and Europe BEV sales/registration metrics. However, the supplied code only calls a navigationBar API to enumerate XPeng car series names and codes. That may be a supporting utility for a larger system, but within this code chunk there is no logic for delivery-cycle monitoring, European sales/registration aggregation, time-series comparison, or market-specific analytics. So the actual behavior in this chunk does not accurately represent the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description emphasizes monitoring business metrics: China delivery wait times and Europe BEV registration/delivery volumes with comparisons. The supplied code does not retrieve, calculate, or expose any such metrics. Instead, it downloads an XPeng configurator webpage and extracts model version identifiers and names. While vehicle version data could be a supporting component for a broader delivery-monitoring system, this chunk on its own performs a different function and does not implement the declared monitoring capabilities. Therefore this code chunk does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code’s behavior is narrowly focused on querying XPeng configurator endpoints for delivery/wait-time data in weeks. It does not implement any Europe market sales, registration, delivery-volume, market-share, daily updates, or 12-month comparison functionality described in the skill declaration. The code does align with the China delivery-cycle portion of the description, including per-version and batch retrieval, but the declared overall purpose presents the skill as a broader cross-market monitoring tool with Europe support that is absent from this chunk. Therefore this chunk does not accurately represent the full declared description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to solicit a user's eu-evs.com email and password for a third-party site, even though the overall task is read-only market monitoring. This creates a credential-harvesting pattern and normalizes users disclosing passwords to an LLM-driven agent, which is dangerous even if the stated purpose is login automation.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill builds an explicit natural-language flow for collecting third-party credentials and passing them into a script, which is a classic secret-handling anti-pattern. This is especially risky because the task context is market-data lookup, so users are being trained to reveal passwords for a low-trust, non-essential purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill expands from data retrieval into authenticated login and persistent session storage on a third-party service, increasing the security boundary far beyond a simple monitoring skill. Persistent session handling can expose account access if the local session file is read, reused, or mishandled by other tools or users on the same environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill requests credentials in natural language without strong warnings about disclosure risk, storage, downstream handling, or the persistence of session artifacts. In context, this makes the credential collection flow more dangerous because users may assume the request is routine and safe for a non-sensitive analytics task.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script goes beyond passive monitoring by performing authenticated login to a third-party site and reusing persisted session state. In an agent skill context, this expands the trust boundary: the skill can solicit credentials, establish an authenticated session, and continue accessing data later without renewed user consent, which creates unnecessary account-handling risk for a monitoring/query tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Accepting raw email/password arguments and converting them into a saved third-party authenticated session is a meaningful security risk, especially in an agent environment where command arguments may be logged, exposed in process listings, or mishandled by surrounding tooling. The capability is broader than the stated monitoring purpose and creates a path for credential exposure and unauthorized reuse of authenticated access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script silently writes session cookies to a local file, which can enable unintended persistence of authenticated access. On shared systems or agent hosts, another process or user may read that file and reuse the session, resulting in unauthorized access to the third-party account without needing the original credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The operational instructions, prompts, and required user interactions are overwhelmingly specified in Chinese, including the mandated credential prompt and output behavior, with no explicit statement that the agent should match or ask for the user's preferred language. This creates a locale/language policy concern because the skill does not offer opt-in or choice despite being bilingual in parts of the description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file’s natural-language documentation specifies Chinese output and presents the interface in Chinese only, while also emitting a fixed output format. Under the policy, forcing a specific language without user opt-in can be a locale/language policy violation when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code sends the provided carVersionCode to remote Xiaopeng API endpoints, but aside from implementation comments there is no explicit user-facing warning, confirmation, or privacy disclosure that input values will be transmitted over the network. Under the code-file criteria, network calls that transmit user or system data should have some visible disclosure unless clearly warned elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

In both bulk and single-version Case 2 flows, the script performs HTTPS requests using the user-provided carSeriesCode, but the file does not visibly warn that these identifiers are sent to an external service. The current comments describe usage and outputs, not the network behavior or any privacy implication.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language comments and usage guidance are presented entirely in Chinese, including operational instructions intended for users or agents. There is no indication of language choice, opt-in, or a documented region-specific justification, which can conflict with language/locale policy requirements.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:234