Back to skill

Security audit

高德打车

Security checks for vulnerabilities and agentic risk

Overview

This maps and taxi skill is mostly purpose-aligned, but it sends sensitive location data through an external proxy using an embedded shared token and exposes more map functions than it clearly advertises.

Review before installing. The skill will send addresses, coordinates, POI searches, route requests, and possible IP-location requests to an external Gaode proxy. The embedded shared proxy token should be treated as exposed, and the publisher should remove it, pin or allowlist the proxy host, fix the environment variable mismatch, and clearly document every enabled map function and privacy behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gaode_taxi.py:11
Finding

Hard-Coded Shared Proxy Credential

Content
View full analysis

Vulnerability Details

File Location: scripts/gaode_taxi.py, lines 11–12 and 19
Vulnerability Type: Hard-coded reusable credential
Risk Level: Medium

Vulnerable Code

python
PROXY_URL = os.environ.get("GAODE_PROXY_URL", "https://1439498936-bl10af74fl.ap-guangzhou.tencentscf.com")
PROXY_TOKEN = os.environ.get("GAODE_PROXY_TOKEN", "tp_8k2mX9vQ4z")

The credential is subsequently attached to outbound requests:

python
req.add_header("X-Proxy-Token", PROXY_TOKEN)

Technical Analysis

The source code contains a reusable proxy token as the default value of GAODE_PROXY_TOKEN. Anyone with access to the distributed skill package can extract this credential without executing the code.

When GAODE_PROXY_TOKEN is not set, every proxy request uses the exposed fallback token. Because GAODE_PROXY_URL is independently configurable, an attacker who can control the process environment can redirect requests to an attacker-controlled HTTPS endpoint and receive the token through the X-Proxy-Token header.

There is also a configuration mismatch: SKILL.md declares PROXY_TOKEN as the primary environment variable, while the script reads GAODE_PROXY_TOKEN. Deployments following the documentation may therefore continue using the embedded fallback credential.

Attack Path

  1. Obtain or inspect the published skill package.
  2. Read scripts/gaode_taxi.py and extract the fallback proxy token.
  3. Reproduce the script's HTTP request format and submit authenticated requests directly to the configured proxy.
  4. Abuse any proxy operations and quota authorized by the shared token.
  5. Alternatively, where control over the execution environment exists, set GAODE_PROXY_URL to an attacker-controlled endpoint.
  6. Invoke any tool that calls _post; the script sends the fallback token to that endpoint in the X-Proxy-Token header.

Impact Assessment

The exposed credential may permit unauthorized use of the map proxy and its supported oper ...[truncated 475 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the hard-coded fallback token and require the credential to be supplied through a secure secret-management mechanism.
  2. Fail closed during startup when the required credential is absent rather than silently using a shared default.
  3. Rotate and revoke the exposed token because publication in source code must be treated as credential compromise.
  4. Align the documented environment variable with the implementation, preferably using GAODE_PROXY_TOKEN consistently.
  5. Issue separate, short-lived, narrowly scoped credentials per deployment or user instead of distributing one shared token.
  6. Restrict the token server-side by allowed operations, rate limits, quotas, expiration, and other applicable request attributes.
  7. Validate or pin the proxy destination against an explicit allowlist so environment manipulation cannot redirect the authorization header to an arbitrary host.
  8. Add automated secret scanning to the release process and block publication when credentials or token-like values are detected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (10)

Tainted flow: 'req' from os.environ.get (line 19, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
93% confidence
Finding

The request destination is controlled by GAODE_PROXY_URL from the environment, and the code automatically sends both user-supplied map/location data and the proxy token to that URL. If the environment is tampered with or misconfigured, this becomes an exfiltration channel to an attacker-controlled endpoint and can leak sensitive travel, address, and token data.

Content

Scanner excerpt · scripts/gaode_taxi.py (reported line 23)May include surrounding context.

python
req.add_header("Content-Type", "application/json")
    req.add_header("X-Proxy-Token", PROXY_TOKEN)
    try:
        with urllib.request.urlopen(req, timeout=30) as resp:
            data = json.loads(resp.read().decode("utf-8"))
            if data.get("code") == 0:
                return data.get("data", {})

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description understates the actual behavior by omitting additional capabilities such as geocoding-related functions, navigation URI generation, and use of an external proxy with an authentication token. Behavior/description mismatch is dangerous because users may consent to a simple taxi skill while the implementation can process broader location data and invoke additional remote functionality they were not clearly told about.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill declares network and environment-backed behavior via an external proxy token, but it does not define any explicit tool scope or permission boundaries. This weakens least-privilege controls and makes it harder for users or the platform to understand what external access the skill may use, increasing the chance of unintended data access or transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill handles sensitive location-related queries and states that requests are sent to a proxy, but it does not present a clear upfront warning that map searches and IP-based location data are transmitted to an external service. This creates a privacy risk because users may unknowingly disclose current or intended locations to third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill notes that omitting the origin will use IP positioning, but it does not give an explicit warning before that behavior occurs. Automatic IP-based location detection can reveal approximate user location without sufficiently informed consent, which is especially sensitive in a travel and taxi context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a taxi-focused Gaode skill with driving/transit/walking/cycling route planning, IP location, nearby search, and POI search. This file additionally exposes administrative district queries, weather lookup, distance measurement, static map generation, coordinate conversion, and app navigation URI generation, which are not reflected in the manifest description and materially broaden the skill's behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module title, descriptions, and all user-facing messages are exclusively in Chinese, with no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code forwards user-provided addresses, coordinates, route endpoints, IPs, and other location queries to a remote proxy service without any visible consent, disclosure, or minimization. In a mapping/taxi skill this data is highly privacy-sensitive because it can reveal home/work locations, movement patterns, and destination intent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

A map/taxi invocation skill obviously needs network access to mapping services, but consulting environment variables for proxy configuration and authentication token is an additional capability not mentioned in the manifest. This is a form of configuration/secret access that expands the operational context beyond the user-facing geographic functions described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The script reads a proxy token from the environment and also embeds a default token value, then uses it for authenticated outbound requests. There is no visible notice to users that credential material is being consumed for external API access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.