Back to skill

Security audit

上海迪士尼游园助手

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Shanghai Disney planning helper, with a disclosed cloud lookup for park hours and no evidence of hidden local persistence or destructive behavior.

Install only if you are comfortable with the park-hours feature contacting a cloud proxy for Gaode data. Treat queue times and prices as estimates, and the publisher should rotate/remove the embedded proxy token and rely on managed secrets instead.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/shanghai_disney.py:14
Finding

Hardcoded Proxy Authentication Token

Content
View full analysis

Vulnerability Details

File Location: scripts/shanghai_disney.py, lines 14–15 and 101–107
Vulnerability Type: Hardcoded secret in distributable source code
Risk Level: Medium

Vulnerable Code

python
GAODE_PROXY_URL = "https://1439498936-bl10af74fl.ap-guangzhou.tencentscf.com"
GAODE_PROXY_TOKEN = os.environ.get("PROXY_TOKEN", "tp_8k2mX9vQ4z")

The embedded credential is subsequently sent as an authentication header:

python
def _call_gaode_proxy(api_type, params):
    body = json.dumps(
        {"type": api_type, "params": params},
        ensure_ascii=False,
        separators=(",", ":")
    ).encode("utf-8")
    req = urllib.request.Request(GAODE_PROXY_URL, data=body, method="POST")
    req.add_header("Content-Type", "application/json")
    req.add_header("X-Proxy-Token", GAODE_PROXY_TOKEN)
    try:
        with urllib.request.urlopen(req, timeout=15) as resp:
            data = json.loads(resp.read().decode("utf-8"))

Technical Analysis

The script uses an environment variable when available but falls back to a static proxy authentication token embedded directly in the distributed source. Because every recipient of the Skill can inspect the script, the fallback value cannot be treated as confidential.

An attacker can extract both the fixed Tencent Cloud Function endpoint and the token, then issue requests independently of the Skill. The exact operations exposed depend on the proxy's server-side authorization and request validation, which are not included in the audited project. The confirmed exposure therefore enables credential reuse; broader proxy compromise cannot be established from the available code.

Attack Path

  1. Download or inspect the published Skill package.
  2. Open scripts/shanghai_disney.py.
  3. Extract the proxy endpoint from line 14 and the fallback token from line 15.
  4. Construct an HTTPS POST request to the endpoint.
  5. Place the extracted value in the X-Proxy-Token header.
  6. Submit requests ...[truncated 636 chars]
Remediation
View remediation

Remediation Suggestions

  1. Immediately revoke and rotate the exposed proxy token.
  2. Remove the hardcoded fallback and fail safely when PROXY_TOKEN is absent:
python
GAODE_PROXY_TOKEN = os.environ.get("PROXY_TOKEN")
if not GAODE_PROXY_TOKEN:
    raise RuntimeError("PROXY_TOKEN is required")
  1. Inject the token through the runtime's approved secret-management mechanism rather than source code, package metadata, logs, or command-line arguments.
  2. Prefer short-lived, narrowly scoped credentials over a permanent shared token.
  3. Enforce server-side authorization for every supported proxy operation; do not rely solely on possession of one static header.
  4. Apply strict allowlisting and schema validation to the proxy's type and params fields.
  5. Add per-client rate limits, quotas, anomaly detection, and credential-reuse monitoring.
  6. Avoid logging authentication headers and redact secrets from diagnostic output.
  7. Review access logs for unauthorized use of the exposed token before rotation.
  8. Add automated secret scanning to the release pipeline to prevent future credential publication.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Most of the code aligns well with the declared Disney-assistant purpose: it contains 7 tool functions covering queue estimates, routing, show info, dining, and ticket pricing, and supports different visitor styles. However, there are notable mismatches. First, the description does not mention querying park operating hours, yet one full tool (tool_disney_schedule) is dedicated to营业时间查询. Second, the code performs external network access through a Gaode proxy (_call_gaode_proxy, _fetch_schedule), while declared permissions are empty; this is a material resource-access mismatch. Third, multiple outputs advertise or imply additional capabilities unrelated to the declared scope—checking train tickets, flights, nearby hotels, and Shanghai food recommendations—even though those capabilities are not implemented in this chunk and are not part of the declared description. These additions are not merely implementation details, so this should be flagged as a mismatch overall.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/shanghai_disney.py (reported line 23)May include surrounding context.

python
0
PARK_CENTER_LNG = 121.6570

# ==================== 31 Attractions ====================
ATTRACTIONS = [
    {"id": "1eb2a711-ab84-4bbf-b351-ce2668861cd5", "name_cn": "喷气背包飞行器", "area": "明日世界", "lat": 31.1425, "lng": 121.6595, "height_min_cm": 112, "thrill_level": 3, "age_min": 4, "duration_min": 2, "tags": ["刺激", "旋转", "室外"], "popularity": 4, "is_indoor": False, "description": "喷气背包带你飞越明日世界上空", "good_for_kids": False, "good_for_teens": True, "good_for_elderly": False},
    {"id": "1bdf8715-64fd-4353-a1ad-5fe9b1591973", "name_cn": "疯狂动物城:热力追踪", "area": "疯狂动物城", "lat": 31.1405, "lng": 121.6545, "height_min_cm": 81, "thrill_level": 3, "age_min": 0, "duration_min": 5, "tags": ["刺激", "室内", "电影IP"], "popularity": 5, "is_indoor": True, "description": "坐上警车和朱迪尼克一起追捕坏人", "good_for_kids": True, "good_for_teens": True, "good_for_elderly": True},
    {"id": "d0e8c1

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill declares network and environment-variable capabilities via a proxied tool using PROXY_TOKEN, but it does not define an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes it harder for reviewers and platforms to verify what external access the skill is intended to have, increasing the risk of unintended data exposure or capability creep.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and all user-facing outputs are fixed in Chinese, which imposes a specific language/locale on users without any visible opt-in or fallback. Under the policy, forcing a specific language is a natural-language policy violation unless the tool explicitly offers a language choice or clearly documents a justified regional constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill sends data to an external proxy service via HTTP request headers/body without any user-facing notice, consent, or trust boundary explanation. Even though the current call path only sends a fixed POI ID, the helper is generic and establishes undisclosed outbound data flow to a third-party endpoint, which can expose user-derived parameters if reused or expanded.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest describes a Shanghai Disney park assistant focused on queue estimates, route planning, shows, dining, and ticket prices. However, the tool outputs additionally direct users to query train tickets, flights, nearby hotels, and Shanghai food recommendations, which expands into broader travel concierge functionality beyond the declared park-guide scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown and manifest content consistently presents the skill name, description, examples, and usage instructions only in Chinese. Under the policy rule, forcing a specific language without user opt-in can be a natural-language policy violation unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The script reads a potentially sensitive credential from the environment using PROXY_TOKEN, but there is no nearby comment, docstring, or user-facing notice explaining that credentials are being consumed for outbound service access. For safety review purposes, sensitive environment access should include some form of disclosure unless already clearly documented elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.