Back to skill

Security audit

家庭消费意图识别

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to do its stated local intent-classification job, but its optional API can expose household chat classification over the network more broadly than the documentation suggests.

Install only if you are comfortable processing household chat snippets with this local classifier. Prefer the CLI or Python function for local use. If you run the API, bind it to 127.0.0.1, restrict CORS, add authentication for any shared deployment, and avoid sending private family conversations unless you have minimized or redacted them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
api.py:6
Finding

Unauthenticated API Exposed on All Network Interfaces with Permissive CORS

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
api.py:15
Finding

Missing Type and Size Validation for API Input

Content
View full analysis
Remediation
View remediation
4096: return jsonify({"error": "text exceeds the maximum length"}), 413 ``` 3. Register controlled handlers for malformed JSON, oversized requests, and unexpected exceptions. 4. Add per-client rate limiting at the application or reverse-proxy layer. 5. Use production deployment controls, including request timeouts, worker limits, and memory limits, to contain resource-exhaustion attempts. 6. Add tests covering empty input, non-object JSON, non-string `text`, malformed JSON, and maximum-length boundaries. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is explicitly designed to process family chat text, which is highly likely to contain personal, household, and behavioral data. Failing to warn users about the privacy sensitivity, retention expectations, and handling boundaries can lead to unsafe use, accidental over-collection, or disclosure of sensitive conversations.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

python3 intent_classifier.py "想买一台电脑"

API 调用

curl -X POST http://localhost:5000/intent -H "Content-Type: application/json" -d '{"text": "明天咱们去吃火锅吧"}'

text

## Python 调用

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code includes the service description, error text, docstrings, and startup messages only in Chinese. Under the policy, forcing a specific language without user opt-in or clear justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This Python file includes natural-language descriptions and expected output conventions entirely in Chinese, which effectively imposes a specific language/locale on users. The file does not indicate that the skill is intentionally limited to a Chinese-language context or provide any user opt-in or language selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content and examples are all in Chinese, which effectively constrains use to a specific language. Because the file does not offer multilingual support, user opt-in, or a documented justification for the locale restriction, it matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.