Back to skill

Security audit

签证智能指南

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Chinese-language visa guide with a bounded local script, but users should verify live policy results because it may pull general Google snippets rather than official-only sources.

Install only if you are comfortable with a Chinese-language visa helper that may send destination-based policy queries to Google for latest updates. Use it for planning checklists, but verify visa requirements and recent changes against official embassy, consulate, or immigration websites before booking or traveling.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises network-backed behavior and explicitly describes a data flow through an agent service to external data-source APIs, but it does not declare any tool scope, permissions, or allowed-tools restrictions. This creates an overbroad execution model where the runtime may permit unintended network access or make review and policy enforcement harder, increasing the risk of data exfiltration or unauthorized external requests if the implementation changes or is compromised.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module description and all user-facing guidance are written exclusively in Chinese and scoped specifically to '中国公民', with no indication that users can choose another language or locale. This creates a natural-language locale constraint without documented opt-in or justification in the skill interface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The policy lookup makes outbound requests to Google but does not give a user-facing warning before doing so. Even though the request does not include obvious secrets beyond the queried destination, silent external calls create transparency and privacy concerns and may surprise users in environments that expect offline or local-only processing.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Scraping generic Google result HTML for visa-policy guidance is unsafe because search-result snippets are not authoritative, are easy to misinterpret, and may reflect SEO spam, stale content, or attacker-controlled pages. In a visa-advice context, bad guidance can directly cause travel disruption, denied boarding, or immigration noncompliance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill advertises visa lookup and policy updates, but its update path performs live network requests to Google without constraining results to authoritative government sources. This expands the skill's data flow and trust boundary, creating risk of inaccurate or manipulated policy information being surfaced from arbitrary search snippets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.