Back to skill

Security audit

xinjianxue-identity-cn

Security checks for vulnerabilities and agentic risk

Overview

This identity-verification skill is disclosed, but it tries to make itself a persistent, session-wide gate over files, memory, tools, and other skills.

Install only if you intentionally want this skill to gate broad agent behavior and are comfortable with persistent changes to agent instructions. Prefer a version that stores only scoped configuration, does not modify AGENTS.md/system prompts/long-term memory, does not disable unrelated tools or skills, and avoids sending long-lived keys in URL query strings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:20
Finding

Session-Wide Skill Instruction Hijacking

Content
View full analysis
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:43
Finding

Persistent Poisoning of Agent Instructions and Long-Term Memory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:126
Finding

Long-Lived Identity Key Exposed in a URL Query String

Content
View full analysis
&conv_id= ``` ### Technical Analysis The documented GET-compatible interface places `agent_key` and `conv_id` in the URL query string. Elsewhere in the same file, `agent_key` is characterized as a long-lived identity key that must be protected and must not be disclosed to third parties. Sensitive values in URLs can be captured by: - HTTP client and browser history. - Reverse-proxy and web-server access logs. - Network monitoring and observability systems. - Error reports and tracing platforms. - Debug logs and support bundles. - Referrer metadata in browser-oriented environments. TLS protects the URL while it is transmitted over the network, but it does not prevent the endpoint, client, proxies, or telemetry systems from recording the complete URL. This contradicts the Skill’s stated requirement not to expose the key. ### Attack Path 1. The agent uses the documented compatibility GET request. 2. The long-lived `agent_key` and conversation identifier are embedded in the request URL. 3. A client, reverse proxy, server, monitoring platform, or debugging system records the URL. 4. A party with access to those records retrieves the key and conversation identifier. 5. The exposed data is used to query release state or interact with the identity workflow as the affected agent, subject to server-side controls. ### Impact Assessment Exposure may disclose the long-lived identity of the bound agent and the identifier of a specific conversation. Depending on the server’s authorization and replay protections, an attacker may be able to: - Query whether the affected conversation has been released. - ...[truncated 352 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill name and all user-facing instructions are explicitly Chinese-focused ('-cn') and the document consistently assumes a Chinese-language interaction flow, but it does not offer users any language choice or opt-in. This can violate language/locale policy when applied generally, because the skill imposes one locale by default rather than letting the user choose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill activates not only on explicit user-provided verification codes, but also on subjective conditions such as the model '察觉' the speaker may not be the host or their habits differ from memory. That creates an imprecise trust boundary and can cause inconsistent enforcement, denial of normal functionality, or unintended invocation of identity-related logic based on weak heuristics.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The instruction that any 'high-risk action' should first invoke this skill is too broad because it lacks a precise invocation boundary and delegates classification to the model. In practice, this can overreach into unrelated tasks, create nondeterministic behavior across turns or platforms, and be abused as a prompt-level gate that suppresses legitimate tool use or analysis.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.