Back to skill

Security audit

China Phone

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Chinese phone-number region and carrier lookup, with the main privacy consideration that queried numbers are sent to named public lookup services.

Install only if you are comfortable sending queried Chinese phone numbers to the listed public 360 and Taobao lookup services. Avoid using it for numbers you do not have permission to check, and use the offline prefix fallback when you do not want an external lookup.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
emoji: "📱"
    requires:
      bins:
        - curl
        - python3
---

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 11)May include surrounding context.

md
emoji: "📱"
    requires:
      bins:
        - curl
        - python3
---

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

示例:

bash
curl -s "https://cx.shouji.360.cn/phonearea.php?number=13812345678" | python3 -c '
import sys, json
obj = json.load(sys.stdin)
data = obj.get("data") or {}

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends phone numbers to third-party public services but does not clearly warn users before doing so. Phone numbers are personal data, so silent transmission to external endpoints creates a privacy and consent risk even if the endpoints are legitimate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger examples are broad enough that the skill may activate on ordinary discussion about phone numbers or carriers, causing unintended handling of user phone numbers. In this skill, accidental activation matters because the workflow sends numbers to external public endpoints, creating avoidable privacy exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction "始终输出自然中文" forces a specific output language regardless of user preference. This is a natural-language locale policy concern because the skill does not offer opt-in or choice for users who may want English or bilingual results.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.