Back to skill

Security audit

xinjianxue-skill-social_wisdom-global

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but it needs review because it asks the user to paste a sensitive one-time account authorization code into chat and then stores credentials for a paid external API.

Review this carefully before installing. Only use it if you are comfortable connecting a XinJianXue account to the assistant, sending birth/gender/location details to www.xinjianxue.com, and spending service tokens. Do not paste the one-time authorization code unless you trust the skill publisher and the chat environment; prefer an official browser-based authorization flow if one is available. Store any resulting credentials only in an OS keychain or similarly scoped credential store.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:131
Finding

Sensitive Account-Binding Credential Solicited Through Chat

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 131–146
Vulnerability Type: Sensitive credential exposure through conversational context
Risk Level: Medium

Vulnerable Snippet

markdown
### Step 2: Ask the user for the XinJianXue AI authorization code and complete the binding

**The AI must stop here and ask the user for the XinJianXue AI authorization code.** It is a one-time credential, **usable only to bind the license above to the user's account**, and for nothing else. Use this fixed wording:

> "Open the official website **www.xinjianxue.com → sign in → "Personal Center" (个人中心) → "AI Assistant Authorization Code" (AI 助手授权码)**, and send me the 8-character authorization code shown there; I need it to complete the account binding.
> Reminder: this code is a **sensitive one-time credential** that is voided the moment the binding succeeds — please confirm you are talking to the official XinJianXue AI assistant (service domain `www.xinjianxue.com`) and send it only to me, this one AI; do not post it in a group chat, do not screenshot or share it, and do not give it to any other AI."

`POST /api/xinjianxue/ai/license/bind` with body:

```json
{ "license": "XJX-AI-xxxxxxxxxxxxxxxx", "auth_code": "<the 8-character code the user sent>" }

On success it returns api_key (the business credential).

⚠️ The AI authorization code is a sensitive one-time credential (8 characters, case-sensitive); it is voided once binding succeeds, and it may only be used for this one binding.

text

### Technical Analysis

The Skill explicitly identifies the authorization code as a sensitive, one-time account-binding credential but instructs the user to disclose it directly in the conversation. This places the secret in model context and potentially in chat transcripts, telemetry, application logs, browser history, moderation systems, extensions, or integrations.

Although the Skill warns users not to s
...[truncated 2049 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace chat-based credential submission with an OAuth-style authorization redirect, device authorization flow, or authenticated confirmation page hosted on the official service domain.
  2. Ensure the user submits or approves the binding directly with www.xinjianxue.com; the authorization secret must never enter model context or a chat transcript.
  3. Bind the authorization request to the intended license using a high-entropy, short-lived challenge and verify state, audience, expiration, and single-use status server-side.
  4. If a device-code flow is used, show only a non-sensitive transaction identifier in chat and require final approval in the user's authenticated browser session.
  5. Prevent secrets from appearing in logs, telemetry, traces, error messages, or analytics. Apply redaction as defense in depth rather than as the primary control.
  6. Add expiration, revocation, binding-status inspection, and self-service unbinding or recovery controls to limit damage from intercepted credentials.
  7. Until a secure flow exists, clearly state that users must not paste account-binding credentials into the conversation and disable automated binding through chat.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
85% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
**What this advisor will not take on**:
- Do not teach calculation and exploitation
- Do not judge whether social give-and-take is a good deal

> That is this advisor's sense of direction.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The skill authorizes the agent to perform onboarding-state checks and proceed with license/application flow based on API results, without an explicit fresh user confirmation at that step. In a skill that handles sensitive one-time credentials and external account binding, this autonomy increases the risk of unintended account actions, credential collection, or premature third-party data sharing if the skill is triggered incorrectly or context is ambiguous.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
Call `POST /api/xinjianxue/ai/license/verify` (include credentials if you have them; body or headers are both accepted). **The only criterion is `pass`:**

- `pass: true` → **already onboarded**: use the APIs directly, and do not ask the user for any credential.
- No credentials / `pass: false` → act on the returned `msg`; **go to Step 1 only once you have confirmed "never onboarded"**. Do not blindly re-apply (re-applying produces an extra license that nobody uses).

### Step 1: Apply for the AI business license (once only)

Static analysis

No suspicious patterns detected.