Back to skill

Security audit

xinjianxue-skill-self_qa-global

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed paid XinJianXue API integration that asks for consent before sending personal profile data, though users should understand the privacy and account-binding implications.

Before installing, be comfortable binding this AI to your XinJianXue account, storing the resulting credentials in a proper secret store, spending tokens per report, and sending the subject's birth details, gender, and location to www.xinjianxue.com. Use it only for yourself or for people who have explicitly agreed to the analysis.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:81
Finding

Privacy-Sensitive External Account Binding and Personal Data Transmission

Content
View full analysis
⚠️ **Before you start**: calling this service sends personal information about the subject — date of birth (plus time, if known), gender, place of birth, current location — to the XinJianXue API (`www.xinjianxue.com`) for processing; it is used only for this one analysis and is not stored. This AI calls under your account identity and consumes tokens per call. **Please confirm you understand and agree before starting.** ``` ```markdown ### Step 2: Ask the user for the XinJianXue AI authorization code and complete the binding **The AI must stop here and ask the user for the XinJianXue AI authorization code.** It is a one-time credential, **usable only to bind the license above to the user's account**, and for nothing else. `POST /api/xinjianxue/ai/license/bind` with body: ```json { "license": "XJX-AI-xxxxxxxxxxxxxxxx", "auth_code": "" } ``` On success it returns `api_key` (the business credential). ``` ```markdown Example request body: ```json { "license": "XJX-AI-xxxxxxxxxxxxxxxx", "api_key": "", "birth": "1990-01-01 08:30", "gender": "Female", "country": "United States", "place": "New York City", "current_country": "United States", "current_place": "New York City" } ``` ``` ### Technical Analysis The Skill directs the agent to establish a persistent relationship with an external service, collect a sensitive one-time authorization code, bind the agent license to the user's account, retain the resulting dual credentials, and transmit personal profile information to `www.xinjianxue.com`. The transmitted information includes date and potentially exact time of birth, gender, birthplace, and current location. In combination, these fields may identify or closely profi ...[truncated 2831 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
Call `POST /api/xinjianxue/ai/license/verify` (include credentials if you have them; body or headers are both accepted). **The only criterion is `pass`:**

- `pass: true` → **already onboarded**: use the APIs directly, and do not ask the user for any credential.
- No credentials / `pass: false` → act on the returned `msg`; **go to Step 1 only once you have confirmed "never onboarded"**. Do not blindly re-apply (re-applying produces an extra license that nobody uses).

### Step 1: Apply for the AI business license (once only)

Static analysis

No suspicious patterns detected.