Back to skill

Security audit

公交地铁线路查询

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent transit-route lookup tool that sends route inputs to a cloud proxy as disclosed, with no evidence of hidden persistence, local data scraping, destructive behavior, or agent hijacking.

Install only if you are comfortable sending route details such as origin, destination, and city to the skill's cloud proxy and map provider. Avoid using highly sensitive home, workplace, or routine-location queries unless that data sharing is acceptable to you.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tainted flow: 'req' from os.environ.get (line 27, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/transit_route.py (reported line 33)May include surrounding context.

python
method="POST",
    )
    try:
        with urllib.request.urlopen(req, timeout=TIMEOUT) as r:
            data = json.loads(r.read().decode("utf-8"))
            if isinstance(data, dict) and data.get("code") == 0 and "data" in data:
                return data["data"]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill declares a network-backed route query and the static analyzer detected env/network capabilities, but the manifest does not explicitly scope or constrain what tools/capabilities are permitted. Missing tool-scope declarations weakens least-privilege controls and can allow broader-than-expected external access if the runtime or future edits introduce additional actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example invocations are broad, natural-language travel requests that closely resemble normal user conversation. This can cause over-triggering or accidental invocation of the skill in unrelated chats, which may unexpectedly send user-provided location data to the route service without clear intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that route queries go through a cloud proxy service, but it does not clearly warn users that origin, destination, and city inputs will be transmitted to a remote service. Because these inputs can reveal sensitive location patterns, the lack of just-in-time disclosure undermines informed consent and privacy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and all user-facing responses are written exclusively in Chinese, with no option for the user to choose another language or locale. This can violate language/locale policy when a skill forces a specific language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill sends user-supplied origin, destination, and city data to a third-party proxy service without any visible user notice or consent flow. Travel queries can reveal sensitive location patterns such as home, workplace, or routine movement, so undisclosed transmission to a remote service creates a real privacy risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill name, description, examples, and usage guidance are entirely in Chinese, and no language choice or opt-in is offered. Under the policy, a skill should not impose a specific language or locale unless the constraint is clearly justified or the user is given a choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script accesses PROXY_TOKEN from the environment and later includes it in an HTTP header, which constitutes sensitive credential handling. There is no visible warning, comment, or docstring informing users that the skill depends on and reads a credential from environment variables.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.