Back to skill

Security audit

Date Utils

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese/Asia-Shanghai date utility with no evidence of hidden access, persistence, credential use, network calls, or destructive behavior.

Install this only if you want Chinese output and Asia/Shanghai date boundaries. For local U.S. dates, deadlines, logs, or policy-sensitive timing, prefer a configurable timezone utility or verify the timezone explicitly before relying on results.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description and the entire skill documentation are written in Chinese and include examples/output conventions such as Chinese date formatting and a fixed Asia/Shanghai timezone, but the file does not offer a language or locale choice. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the regional constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises itself as the 'only reliable source' for current time/date decisions, but all 'now' operations are forced to Asia/Shanghai rather than reflecting user or system context. This can silently produce incorrect dates, weekdays, week ranges, and timestamps for users in other regions, causing downstream logic or policy decisions to be made against the wrong day or time boundary.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation claims the tool is based on Python datetime and the system clock, but the implementation hardcodes UTC+8 context for all current-time calculations. That mismatch is dangerous because callers may trust the tool for authoritative 'current date' answers while unknowingly receiving a time interpretation detached from the host or user environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file documentation explicitly fixes the timezone to Asia/Shanghai, and the implementation consistently uses Chinese weekday labels and a hard-coded UTC+8 timezone. This creates a locale-specific behavior that is imposed on all users without offering a language or locale choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.