Back to skill

Security audit

携程积分助手

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs local Ctrip points tracking, but its documentation claims cookie-based account updates, cron monitoring, and Feishu notifications without enough scoping or safety guidance.

Review this skill before installing if you expect automatic monitoring or Feishu notifications. Do not provide a Ctrip Cookie unless you are comfortable treating it like a password, and verify any cron job and notification destination yourself. Avoid running the publish command unless you trust the current clawhub package version or can pin it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:82
Finding

Execution of an Unpinned Package Through npx

Content
View full analysis
Remediation
View remediation
publish ``` 2. Record and review package provenance, release signatures, and registry metadata before recommending the command. 3. Prefer installing dependencies through a committed lockfile and using a clean installation mechanism that verifies locked integrity hashes. 4. Use `npx --no-install` after installing a reviewed, pinned dependency locally so the publishing command cannot silently retrieve a new package. 5. Run publishing tools in a restricted environment with minimal credentials and filesystem access. 6. Periodically review and deliberately update the pinned version rather than relying on a mutable distribution tag. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The skill advertises automatic monitoring and Feishu push notifications but does not explicitly disclose that points, redemption interests, or account-related shopping metadata may be transmitted off-device to a third-party messaging service. This weakens informed consent and can expose personal activity patterns or account-associated information through notifications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill states that account updates require a Cookie and identifies a local cookie file path, but it does not clearly warn users that this is authentication material that can grant account access if exposed. In a points/account-management context, handling session cookies without explicit safety guidance increases the risk of credential misuse, accidental sharing, or insecure storage.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The documentation instructs users to run npx clawhub@latest publish, which pulls and executes the latest package version at runtime rather than a pinned, reviewed release. If the upstream package is compromised or a breaking/malicious version is published, users could execute untrusted code on their system during publishing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring presents the skill's purpose only in Chinese, and the rest of the user-facing interface follows the same pattern. For a general-purpose skill, forcing one language without user opt-in or documented justification is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The CLI help text and command feedback are all emitted in Chinese, with no mechanism for the user to choose another language. This imposes a fixed locale on all users and is not documented as a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill name, description, and all example invocations are presented only in Chinese, which implicitly constrains interaction language without stating that this is optional or region-specific. Under the policy, locale or language restrictions should be opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.