Back to skill

Security audit

旅行美食助手

Security checks for vulnerabilities and agentic risk

Overview

This travel food skill is coherent and disclosed: it searches restaurant and local food information through a proxy-backed map service, without hidden persistence or destructive behavior.

Install only if you are comfortable sending travel locations, dining preferences, and restaurant search terms to the skill's proxy and downstream map POI service. The proxy token should be scoped specifically for this service, not reused for unrelated accounts or infrastructure.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tainted flow: 'req' from os.environ.get (line 204, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/food_guide.py (reported line 213)May include surrounding context.

python
},
            method="POST"
        )
        with urllib.request.urlopen(req, timeout=20) as resp:
            result = json.loads(resp.read().decode("utf-8"))
            # SCF代理返回 {"code":0,"data":{高德原始响应}}
            if isinstance(result, dict) and "data" in result and "code" in result:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares access to an environment token (primaryEnv: PROXY_TOKEN) and describes outbound calls to a proxy and map POI service, but it does not constrain tool usage with an explicit permission or allowed-tools policy. This creates unnecessary privilege ambiguity: future changes or runtime behavior could permit broader tool or network access than intended, increasing the risk of unauthorized external requests or misuse of sensitive environment-backed capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description and all example interactions are entirely in Chinese, and there is no statement that users may choose another language or that the skill is limited to Chinese-speaking users. Under the policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user-supplied location and search preferences to a third-party proxy service, which creates a privacy exposure because sensitive travel intent, place names, and dining preferences leave the local environment without explicit user notice or consent. The risk is elevated by the use of a custom SCF proxy rather than a clearly identified first-party API endpoint, increasing uncertainty about data handling, logging, and retention.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The primary description string identifies the tool in Chinese only, and the script's user-facing errors and output labels are also written exclusively in Chinese. This imposes a locale/language choice without offering the user an alternative or opt-in, which matches the language-policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.