Back to skill

Security audit

景点门票比价

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed attraction ticket comparison tool that sends user travel queries to declared proxy services and does not show hidden persistence, destructive behavior, or unrelated data access.

Install only if you are comfortable sending attraction searches, city names, and the PROXY_TOKEN authentication value to the listed Tencent SCF proxy services for Meituan/Tuniu ticket lookup. Avoid entering personal details beyond the travel query needed for price comparison.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tainted flow: 'req' from os.environ.get (line 90, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/compare.py (reported line 94)May include surrounding context.

python
last_error = None
    for attempt in range(MAX_RETRIES + 1):
        try:
            with urllib.request.urlopen(req, timeout=timeout) as resp:
                result = json.loads(resp.read().decode("utf-8"))
                return result if result is not None else {}
        except Exception as e:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares network and environment-backed operation via primaryEnv: PROXY_TOKEN and multiple external API/proxy data flows, but it does not define an explicit tool/permission scope such as allowed tools or permissions. This creates overbroad capability risk: the runtime may permit network or secret-backed access beyond what is minimally necessary, reducing auditability and increasing the blast radius if the skill is modified or abused.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest fields, examples, trigger conditions, and operational instructions are all presented only in Chinese. This effectively forces a specific language experience for users without any stated language selection, fallback, or opt-in, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The code accesses PROXY_TOKEN from the environment and includes it in the X-Proxy-Token header for outbound requests. This is a credential-handling behavior, but the script provides no user-facing indication that a secret is expected, used, and sent to external endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends user-supplied attraction names and city queries to third-party SCF endpoints, but the code contains no notice, consent flow, or data-minimization step. In this skill context, the data is not highly sensitive by default, but it can still reveal travel interests, location intent, or personal plans to external operators without transparency.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

User-facing documentation, CLI descriptions, and output-oriented text are entirely in Chinese, which effectively forces a specific language experience. The file does not offer locale selection or indicate that the language constraint is optional or region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.