Back to skill

Security audit

旅行记账助手

Security checks for vulnerabilities and agentic risk

Overview

This is a local travel expense tracker with no network or credential behavior; the main issues are feature and language limitations, not security abuse.

Install this only if a Chinese-language, local-file travel expense tracker is acceptable. Do not expect shared AA splitting despite the short description; data is stored locally in JSON files and exchange rates are fixed reference values, not live rates.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

整体上,代码与“旅行消费记录、多币种换算、分类统计、预算管理”的描述基本一致:它支持录入支出、按预设汇率换算成人民币、按类别/日期/币种汇总,并进行预算检查。因此主要功能大体匹配。 但描述中明确提到“AA记账轻松分摊”,这是一个具体且重要的能力;而代码里没有任何与多人记账、成员管理、份额分配、均摊或结算相关的实现,仅是单人/单账本式的支出记录与统计。所以存在描述与实际能力不一致之处。除此之外,代码未表现出明显越权或无关的额外高风险能力。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s title and all user-facing messages are written exclusively in Chinese, which imposes a specific language on users without any opt-in or alternative locale handling. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.