Back to skill

Security audit

xinjianxue-skill-roommate-global

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed roommate-advice API integration that asks for consent before analysis and does not include executable code or hidden persistence.

Before installing, understand that using this skill sends birth, gender, and location details to XinJianXue and can consume account tokens. Only provide the one-time authorization code when you intended to bind this AI to your account, and ensure credentials are stored in an OS keychain, credential manager, or other agreed secure location.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
## 🎯 This Advisor's Positioning (Roommate Relations Advisor)

**In one line**: Do not judge whose living habits are right; deal only with negotiating boundaries.

**Questions handled most often**:
- My roommate is too loud — how do I bring it up?
Confidence
85% confidence
Finding
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
## 🎯 This Advisor's Positioning (Roommate Relations Advisor)

**In one line**: Do not judge whose living habits are right; deal only with negotiating boundaries.

**Questions handled most often**:
- My roommate is too loud — how do I bring it up?
Confidence
85% confidence
Finding
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Anti-Refusal Statement

High
Category
Anti-Refusal
Content
- **Self-check**: Do not judge living habits as right or wrong, better or worse — deal only with negotiating boundaries
Confidence
85% confidence
Finding
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
Call `POST /api/xinjianxue/ai/license/verify` (include credentials if you have them; body or headers are both accepted). **The only criterion is `pass`:**

- `pass: true` → **already onboarded**: use the APIs directly, and do not ask the user for any credential.
- No credentials / `pass: false` → act on the returned `msg`; **go to Step 1 only once you have confirmed "never onboarded"**. Do not blindly re-apply (re-applying produces an extra license that nobody uses).

### Step 1: Apply for the AI business license (once only)
Confidence
80% confidence
Finding
The skill directs the agent to make onboarding state decisions and proceed with account-linked API actions based on a service response, including applying for a license and using stored credentials without renewed user confirmation. In a sensitive workflow involving authentication, billing, and personal data transmission, this increases the risk of unintended external actions or privacy-impacting calls being taken autonomously.

Static analysis

No suspicious patterns detected.