Back to skill

Security audit

航班延误赔偿助手

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it claims, but it includes a built-in shared proxy token and automatically sends flight queries to a third-party cloud proxy.

Review before installing. The skill is not destructive and does not persist locally, but using live lookup will send flight numbers and dates to the publisher’s cloud proxy using an embedded shared token. Install only if you are comfortable with that third-party data flow and the publisher should rotate/remove the exposed token and require scoped runtime configuration.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/flight_delay_compensation.py:15
Finding

Hard-Coded Proxy Authentication Token

Content
View full analysis

Vulnerability Details

File Location: scripts/flight_delay_compensation.py, lines 15–16 and 218–225
Vulnerability Type: Hard-coded credential
Risk Level: High

Vulnerable Code

python
SCF_PROXY_URL = "https://1439498936-eqcpuaevzz.ap-guangzhou.tencentscf.com"
PROXY_TOKEN = os.environ.get("PROXY_TOKEN", "tp_8k2mX9vQ4z")

The credential is subsequently transmitted as an authentication header:

python
req = urllib.request.Request(
    SCF_PROXY_URL,
    data=body,
    headers={
        'X-Proxy-Token': PROXY_TOKEN,
        'Content-Type': 'application/json'
    },
    method='POST'
)

Technical Analysis

The source code embeds a proxy authentication token as the default value of PROXY_TOKEN. Because the project is distributed to users, anyone who can obtain the package can read and reuse this credential. Supporting an environment variable does not protect the secret because the embedded token remains active whenever that variable is absent.

The token is sent to a fixed Tencent Cloud Function endpoint in the X-Proxy-Token header. TLS protects it in transit but does not address disclosure through the source code. Effective protection depends on the proxy enforcing narrow authorization, rate limits, expiration, and per-user isolation; those server-side controls cannot be verified from this project.

Attack Path

  1. An attacker downloads or otherwise obtains the Skill package.
  2. The attacker reads scripts/flight_delay_compensation.py and extracts the proxy URL and fallback token.
  3. The attacker constructs HTTPS requests to the exposed proxy endpoint.
  4. The attacker supplies the extracted value in the X-Proxy-Token header.
  5. If the token remains valid, the attacker invokes operations allowed by the proxy, potentially outside normal Skill usage.
  6. The attacker may automate requests to consume quotas, generate service costs, or disrupt availability.

Impact Assessment

Successful exploitation grants the attacker ...[truncated 512 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed token immediately; assume it has already been disclosed.
  2. Remove the hard-coded fallback and fail securely when PROXY_TOKEN is unavailable:
python
PROXY_TOKEN = os.environ.get("PROXY_TOKEN")

if not PROXY_TOKEN:
    return {
        "code": -1,
        "message": "PROXY_TOKEN is not configured"
    }
  1. Provision credentials through a supported secret manager or protected runtime configuration rather than source files, metadata, documentation, command-line arguments, or logs.
  2. Replace the shared static credential with per-user or per-installation credentials that are scoped, revocable, and short-lived.
  3. Enforce server-side authorization for every permitted request type instead of relying only on possession of the token.
  4. Apply rate limits, quotas, anomaly detection, and cost alerts per credential and source.
  5. Restrict the proxy to the minimum required upstream operation and validate all request parameters server-side.
  6. Review proxy access logs for prior unauthorized use of the disclosed credential.
  7. Add automated secret scanning to development and release pipelines to prevent future credential commits.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tainted flow: 'req' from os.environ.get (line 218, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/flight_delay_compensation.py (reported line 233)May include surrounding context.

python
ctx.verify_mode = ssl.CERT_REQUIRED

    try:
        with urllib.request.urlopen(req, timeout=30, context=ctx) as resp:
            result = json.loads(resp.read().decode('utf-8'))
            if result.get("code") == 0:
                return result.get("data", {})

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares network and environment-variable-backed tool usage via PROXY_TOKEN and a cloud proxy, but does not define any explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it harder for the host or reviewer to constrain what external access the skill actually needs, increasing the risk of unintended data exposure or overly broad execution authority.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The display name, description, tool descriptions, examples, and usage guidance are all presented only in Chinese. This enforces a specific language for users without any stated opt-in or alternative locale support, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill description and all user-facing messages are written in Chinese, and the file presents itself as a zero-configuration helper without indicating any language selection or opt-in. That can violate language/locale policy when a skill effectively enforces one language for all users.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill embeds a default proxy token in code, enabling authenticated access to an external service without explicit operator credential setup. Hardcoded secrets are easily leaked through source distribution, logs, or reuse across deployments, and anyone obtaining the skill may be able to abuse the proxy or associated API quota.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Using a hardcoded proxy token fallback without user disclosure creates both a secret-exposure risk and undisclosed third-party access path. In this skill's context, 'zero-config' behavior makes the issue more dangerous because installations immediately gain outbound authenticated API capability, increasing the chance of unnoticed data transfer and token abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill sends user-supplied flight query parameters to a remote proxy service without runtime disclosure or consent. Although flight numbers are not highly sensitive by themselves, travel itinerary data can be personal or commercially sensitive, and undisclosed transmission to a third party increases privacy and trust risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest describes a ready-to-use skill that covers EU/UK/China/Canada/U.S./Turkey, including claim guidance and claim-letter generation. In code, cmd_claim customizes law references and amounts for EU, UK, Canada, and China, but falls back to a generic '相关航空法规' path for other jurisdictions, so U.S. and Turkey are not actually implemented with jurisdiction-specific claim generation as advertised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.