Back to skill

Security audit

xinjianxue-skill-classmate_qa-global

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed paid API integration that handles sensitive personal details, but its behavior is coherent with its stated relationship-analysis purpose and includes user confirmation and credential-handling limits.

Install only if you are comfortable sending the subject's birth details, gender, and current location to www.xinjianxue.com under your account and spending tokens per report. Do not use it for another person unless they have explicitly agreed, and store the generated license and api_key only in a credential manager or equivalent dedicated secret store.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:74
Finding

Excessive External Collection of Personal Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 74 and 200–213
Vulnerability Type: Excessive Personal Data Collection
Risk Level: Medium

Relevant excerpts:

text
Before you start: calling this service sends personal information about
the subject — date of birth (plus time, if known), gender, place of birth,
current location — to the XinJianXue API (www.xinjianxue.com) for processing;
it is used only for this one analysis and is not stored.
markdown
- There are two input tiers; **both are billed at tier b (basic) — tier a costs no extra tokens**:
  - **a (full)**: the subject's date and time of birth + gender + place of birth (country + state/region/city) + current location
  - **b (basic)**: only the subject's date of birth + gender + current location
- **Both tiers must provide**: gender, date of birth (if the user knows the time of birth, include it and the call is automatically upgraded to tier a), and the subject's current location (country + state/region/city)
- **Tier a additionally requires**: the exact hour + minute of birth, and the place of birth (country + state/region/city)
- **Multi-person analysis**: pass a `people` array, each person `{name, birth, gender, place, country}`.
- If the user has not supplied everything, the AI must ask for the missing pieces first — never call with parameters missing.

Technical Analysis

The Skill requires the agent to collect and transmit date of birth, gender, and current geographic location to an external service before producing a report. It may additionally transmit exact birth time, birthplace, and identifying names for multi-person analysis.

These attributes are linkable personal data and exceed what is inherently necessary to provide ordinary campus relationship advice. The mandatory requirement to ask for missing fields increases collection rather than applying data minimization. The Skill also permits reports about ot ...[truncated 1662 chars]

Remediation
View remediation

Remediation Suggestions

  1. Provide a local, advice-only mode that does not call an external API.
  2. Make external report generation optional rather than a prerequisite for relationship guidance.
  3. Apply strict data minimization. Do not require exact birth time, birthplace, gender, or current city unless each field has a documented and necessary purpose.
  4. Prefer coarse location data where location is genuinely required.
  5. Restrict analysis to the user unless every other data subject provides direct, explicit, and verifiable consent.
  6. Present a field-by-field disclosure before collection, including purpose, destination, retention period, deletion procedure, legal/controller identity, and a link to the provider's privacy policy.
  7. Do not claim that the server stores no data unless that guarantee is independently enforceable and auditable.
  8. Encrypt data in transit, prohibit sensitive values from logs and conversation persistence, and define deletion and incident-response procedures.
  9. Permit users to omit optional attributes without blocking access to basic relationship advice.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
Call `POST /api/xinjianxue/ai/license/verify` (include credentials if you have them; body or headers are both accepted). **The only criterion is `pass`:**

- `pass: true` → **already onboarded**: use the APIs directly, and do not ask the user for any credential.
- No credentials / `pass: false` → act on the returned `msg`; **go to Step 1 only once you have confirmed "never onboarded"**. Do not blindly re-apply (re-applying produces an extra license that nobody uses).

### Step 1: Apply for the AI business license (once only)

Static analysis

No suspicious patterns detected.