Back to skill

Security audit

旅游行李清单

Security checks for vulnerabilities and agentic risk

Overview

The skill does generate travel packing lists, but its weather mode sends destinations to a third-party proxy while another section incorrectly says no external requests occur.

Review this skill before installing if trip destinations are sensitive. The quick mode appears local-only, but the weather-enabled generate mode sends the destination to an external proxy; the publisher should correct the privacy/data-flow section and document the proxy operator, retention expectations, and any local-only choice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill documents network-capable behavior via a proxy service and a weather API, but it does not declare an explicit tool scope or permissions boundary. This weakens reviewability and least-privilege controls, making it harder for users and the platform to understand or constrain external data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill says it uses a proxy and the Amap weather API, which means destination and related travel parameters may be transmitted to an external service, but it does not clearly warn users about that disclosure. Users may provide itinerary details without realizing they are shared outside the local skill environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The privacy and data-flow section is inconsistent and omits an accurate warning about external requests, despite other sections describing API calls. Inconsistent privacy disclosures increase the chance of unintentional data exposure and prevent users from making informed decisions about sharing travel details.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document states both that it calls an external weather API through a proxy and that it does not send any external requests, which is a direct contradiction. This can mislead users and reviewers about actual data handling, undermining informed consent and accurate security assessment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The top-level description is written entirely in Chinese, and the CLI errors/help text throughout the file also assume Chinese output. This forces a specific language/locale rather than offering user choice or documenting that the skill is intentionally region/language-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends the user-supplied destination to a third-party proxy service (gaode-proxy-...fcapp.run) to resolve location and fetch weather, but there is no user-facing disclosure, consent flow, or indication that travel data leaves the local skill. Travel destinations can be sensitive personal information, and routing them through an unaudited proxy increases privacy and data-handling risk beyond the expected weather lookup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.