Back to skill

Security audit

xinjianxue-skill-job_change-global

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed paid API advisor that needs user consent before sending personal details and using stored service credentials.

Install only if you are comfortable sharing birth date, gender, birth/current location, and a one-time authorization code with this XinJianXue workflow, and understand that later report calls use stored credentials and may consume account tokens.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as a narrow job-change advisor, but the implementation and service description expand into broad personality, relationship, and behavioral analysis using highly sensitive personal data such as birth details and location. This mismatch undermines informed consent and creates a data-minimization and scope-creep risk: users may authorize a career advisory tool without realizing it performs substantially broader profiling.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
Call `POST /api/xinjianxue/ai/license/verify` (include credentials if you have them; body or headers are both accepted). **The only criterion is `pass`:**

- `pass: true` → **already onboarded**: use the APIs directly, and do not ask the user for any credential.
- No credentials / `pass: false` → act on the returned `msg`; **go to Step 1 only once you have confirmed "never onboarded"**. Do not blindly re-apply (re-applying produces an extra license that nobody uses).

### Step 1: Apply for the AI business license (once only)

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest positions the skill as an advisor for stay-or-leave and offer decisions. Exposing a GET /api/xinjianxue/dev/bill capability to retrieve token billing details is an account-management function rather than a direct requirement of providing job-change analysis.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.