Back to skill

Security audit

CarBuying-CN 国内购车顾问

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese car-buying guidance skill with a simple local calculator and no evidence of hidden access, persistence, network use, or data collection.

Install this if you want China-focused car-buying guidance and simple local cost calculations. Treat prices, tax exemptions, registration rules, loan rates, and vendor recommendations as reference material, not current legal or financial advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description promises an end-to-end car-buying assistant with advisory coverage across selection, financing, inspection, bargaining, and registration workflow. The code actually implements a narrow CLI calculator for car purchase/loan/ownership-cost math and basic cost comparison. Some parts do align with the description—budget planning, loan calculation, and limited fuel vs EV cost treatment—but several prominent declared capabilities are absent, especially used-car/new-car selection, inspection checks, bargaining support, and registration-process guidance. Therefore the description materially overstates the implemented behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

An overly broad trigger can cause the skill to activate on loosely related car queries, increasing the chance of irrelevant or unintended guidance being injected into conversations. While not directly enabling code execution or data exfiltration, it can degrade routing integrity, confuse users, and crowd out more appropriate skills.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is entirely written in Chinese and does not indicate that the language choice is optional, configurable, or limited to a justified region-specific audience. Under the policy rule for natural-language violations, forcing a specific language without user opt-in is a reportable locale-policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. This skill content presents all instructions exclusively in Chinese, which may force a specific language on users without opt-in or an explicit documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file is entirely presented in Chinese starting from the title, with no indication that language selection is optional or that the content is intentionally restricted to a Chinese-speaking audience. Under the stated policy, forcing a specific language without opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to all file types and covers language/locale policy violations. The module docstring and CLI usage examples require Chinese-language commands and provide no opt-in, alternative language, or justification that this tool is intended only for a Chinese-speaking region or audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.