Back to skill

Security audit

SPX Express Tracking

Security checks for vulnerabilities and agentic risk

Overview

This SPX tracking skill does what it advertises, but it asks users to pass an optional browser session cookie on the command line and can expose detailed recipient/location data.

Install only if you are comfortable with the skill querying SPX and returning detailed shipment information. Avoid using the --cookie option unless absolutely necessary; if authentication is required, prefer a version that reads secrets from stdin, a protected file, or a credential store, and be aware that normal JSON/text output may include recipient names, full addresses, and precise location data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/spx_tracking.py:575
Finding

Sensitive browser session cookie exposed through command-line arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/spx_tracking.py:115-130, 575; SKILL.md:19, 27
Vulnerability Type: Sensitive data exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

python
def fetch_tracking(tracking_number: str, cookie: str | None, timeout: int) -> dict[str, Any]:
    headers = HEADERS.copy()
    headers["referer"] = f"https://spx.com.my/track?{tracking_number}"
    if cookie:
        headers["cookie"] = cookie

    response = requests.get(
        API_URL,
        params={"spx_tn": tracking_number},
        headers=headers,
        timeout=timeout,
    )
    response.raise_for_status()
python
parser.add_argument("--cookie", help="Optional browser cookie for authenticated requests")

The documented invocation explicitly instructs users to place the cookie on the command line:

bash
python skills/spx-tracking/scripts/spx_tracking.py <tracking_number> [--format json|text|summary] [--cookie "..."] [--timeout 15]

Technical Analysis

Browser cookies are authentication secrets and should not be passed as ordinary command-line arguments. Depending on the operating system and execution environment, command-line arguments may be visible through process inspection facilities, execution telemetry, job logs, diagnostic tooling, or shell history.

Although the request is transmitted to a fixed HTTPS endpoint and the script does not print the cookie directly, transport security does not protect the secret before it is placed into the HTTP request. The primary exposure occurs locally through the command invocation.

The documentation identifies the cookie as sensitive but still recommends the unsafe --cookie mechanism. No protected alternative, such as standard input, a restricted file, or a secret manager, is provided.

Attack Path

  1. A user follows the documented invocation and supplies an active brow ...[truncated 1127 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove or deprecate the --cookie command-line option.
  2. Read the cookie from protected standard input, preferably without terminal echo.
  3. Alternatively, accept a path to a permission-restricted file and verify that its permissions do not allow access by other users.
  4. Where available, integrate with an operating-system credential store or dedicated secret manager.
  5. Prefer anonymous API access and avoid requesting a browser cookie unless authentication is strictly necessary.
  6. Ensure that exceptions, debug output, request tracing, and telemetry never include the Cookie header.
  7. Document cookie revocation and advise affected users to clear command history and rotate sessions if the legacy option has been used.

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Unpinned dependency without integrity verification

Content
View full analysis

Vulnerability Details

File Location: requirements.txt:1; SKILL.md:32-35
Vulnerability Type: Non-reproducible third-party dependency installation
Risk Level: Low

Vulnerable Code

The complete dependency declaration is:

text
requests>=2.28

The documented installation command is:

bash
pip install -r requirements.txt

Technical Analysis

The lower-bound-only constraint permits pip to install any current or future version of requests accepted by the resolver. No lock file, exact version, package hash, or trusted-index restriction is supplied.

Consequently, installations are not reproducible and their integrity depends entirely on the configured package index and the state of the dependency ecosystem at installation time. A compromised package release, compromised index, malicious index configured earlier in the environment, or incompatible future release could cause unreviewed code to enter the runtime.

This is a supply-chain hardening weakness rather than evidence that the current requests package is malicious. The declared package name is legitimate, and no dependency confusion or typosquatting package was identified in the audited files.

Attack Path

  1. A user follows the documentation and runs pip install -r requirements.txt.
  2. pip resolves the unconstrained upper version through the environment's configured package indexes.
  3. An attacker must first compromise an accepted package release or index, or control a malicious index already configured in the environment.
  4. Because no version lock or hash is enforced, pip accepts the attacker-controlled artifact if it satisfies requests>=2.28.
  5. The package is installed and its code becomes available to the tracking script under the privileges of the installing or executing user.

This path requires a separate supply-chain or package-index compromise; the requirement alone does not directly execute an attac ...[truncated 528 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin requests to an explicitly reviewed version instead of using only a minimum version.
  2. Generate a lock file that also fixes all transitive dependency versions.
  3. Record cryptographic hashes and install with pip's --require-hashes option.
  4. Use an explicitly configured trusted package index or an internally controlled package mirror.
  5. Add automated dependency vulnerability and update monitoring.
  6. Review and deliberately update locked dependencies on a controlled schedule rather than accepting future releases automatically.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill documentation indicates the script performs outbound network access to a public SPX API, but the manifest does not declare any tool scope such as permissions or allowed-tools. Undeclared network capability weakens sandboxing and review controls, making it easier for a skill to perform unexpected external communication, leak user-supplied data, or expand behavior beyond what operators intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The report intentionally includes receiver name, full street addresses, and precise latitude/longitude for current and next shipment locations, then exposes them in both JSON and text output. For a tracking skill whose stated purpose is basic shipment status lookup, this is unnecessary over-collection and disclosure of sensitive personal/location data that could be misused for stalking, profiling, or privacy violations if surfaced to an agent or unauthorized user.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s user-facing output is hard-coded in Chinese, including status labels, headings, and report text. This imposes a specific language on all users with no option to select locale or language, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency is specified as requests>=2.28 without an upper bound or exact pin, so installations may resolve to different versions over time. This creates supply-chain and patch-management risk because builds are not reproducible and a vulnerable or incompatible release could be installed without review.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
requests>=2.28

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

The manifest references requests without pinning to a specific version, while the package has multiple historical advisories. Because the resolved version is unknown, the deployment could install a release affected by issues such as credential leakage or improper verification behavior, depending on environment and resolver outcome.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.