Back to skill

Security audit

亲子出行助手

Security checks for vulnerabilities and agentic risk

Overview

This family travel skill is purpose-aligned and disclosed, but users should know it sends travel queries to external proxy services.

Install only if you are comfortable sending destination, city, attraction keywords, and related family travel parameters to the listed proxy-backed travel and weather services. Avoid entering unnecessary personal details, and verify ticket policies with official providers before purchase.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tainted flow: 'req' from os.environ.get (line 28, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/family.py (reported line 29)May include surrounding context.

python
"""发送POST请求"""
    payload = json.dumps(data).encode("utf-8")
    req = urllib.request.Request(url, data=payload, headers=HEADERS)
    with urllib.request.urlopen(req, timeout=20) as resp:
        return json.loads(resp.read().decode("utf-8"))

Tainted flow: 'req' from os.environ.get (line 28, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/family.py (reported line 37)May include surrounding context.

python
"""调用高德代理API"""
    data = json.dumps({"api": api, "params": params}).encode("utf-8")
    req = urllib.request.Request(GAODE_PROXY, data=data, headers={"Content-Type": "application/json"})
    with urllib.request.urlopen(req, timeout=15) as resp:
        return json.loads(resp.read().decode("utf-8"))

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares a proxy token environment and describes outbound calls to proxy-backed travel and weather APIs, but it does not define any explicit tool scope such as permissions or allowed-tools. That creates unnecessary ambiguity about what external actions the skill may perform and weakens least-privilege controls, increasing the chance of unintended network or environment access if the runtime or future revisions add executable logic.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-facing descriptions, command help, errors, and output text are all hard-coded in Chinese, which effectively forces a specific language/locale. The file does not provide any mechanism for language selection or indicate that the locale restriction is optional or region-specific by user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

User-supplied city names, attraction keywords, and related travel queries are transmitted to external proxy services without any visible disclosure, consent, or minimization. In a family travel assistant, these inputs can reveal location intent and child-related travel planning, creating a meaningful privacy risk even if not a direct code-execution flaw.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The code reads PROXY_TOKEN from the environment and includes it in outbound request headers, but there is no visible user-facing notice that the skill depends on and uses an environment-provided credential. This is a sensitive operation under the rule because it accesses credentials without disclosure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.