Back to skill

Security audit

批量快递物流查询技能

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated logistics purpose, but it handles account passwords and stores reusable API/session credentials in a plaintext local file.

Install only if you are comfortable letting the skill handle this xdccy.com account's login and API credentials. Prefer a dedicated account/password, do not paste credential-file contents into chat, check that ~/.workbuddy/xdcc-credentials.env is private, and rotate or delete the API key/token if the file may have been exposed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (78)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SECURITY_AUDIT.md (reported line 22)May include surrounding context.

md
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/guided_register.py (reported line 26)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/guided_register.py (reported line 307)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/onboard.py (reported line 146)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/onboard.py (reported line 147)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-query/SKILL.md (reported line 50)May include surrounding context.

md
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-query/SKILL.md (reported line 154)May include surrounding context.

md
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-query/references/onboarding_guide.md (reported line 92)May include surrounding context.

md
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-query/scripts/guided_register.py (reported line 26)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-query/scripts/guided_register.py (reported line 306)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-query/scripts/guided_register.py (reported line 307)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-query/scripts/onboard.py (reported line 146)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-query/scripts/onboard.py (reported line 147)May include surrounding context.

python
## 📝 信息性提醒(非风险项)
1. **凭据仅从环境变量 / 本地文件读取,无硬编码**
   - `batch_query.py` 读 `XDCC_PLATFORM_ID / XDCC_API_KEY / XDCC_MEMBER_ID`(环境变量);
   - `guided_register.py` 注册成功后调用 `common.write_creds()` 写入用户显式指定的 `--creds` 路径(默认 `~/.workbuddy/xdcc-credentials.env`)。
   - 文档与代码中均无明文硬编码凭据。
2. **注册向导需客户本人输入手机号/密码**
   - 这是安全注册必需项,由客户在对话中提供或手动在页面填写;脚本**不替客户设定密码**、**不读取客户其他隐私**。

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the code's main function is obtaining API key or secret material from an existing userToken rather than performing the stated logistics operations, the mismatch can facilitate overcollection of credentials. In a skill context, collecting account keys is more sensitive than ordinary query automation and should be clearly disclosed and tightly controlled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the code's main function is obtaining API key or secret material from an existing userToken rather than performing the stated logistics operations, the mismatch can facilitate overcollection of credentials. In a skill context, collecting account keys is more sensitive than ordinary query automation and should be clearly disclosed and tightly controlled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the code's main function is obtaining API key or secret material from an existing userToken rather than performing the stated logistics operations, the mismatch can facilitate overcollection of credentials. In a skill context, collecting account keys is more sensitive than ordinary query automation and should be clearly disclosed and tightly controlled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the code's main function is obtaining API key or secret material from an existing userToken rather than performing the stated logistics operations, the mismatch can facilitate overcollection of credentials. In a skill context, collecting account keys is more sensitive than ordinary query automation and should be clearly disclosed and tightly controlled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the code's main function is obtaining API key or secret material from an existing userToken rather than performing the stated logistics operations, the mismatch can facilitate overcollection of credentials. In a skill context, collecting account keys is more sensitive than ordinary query automation and should be clearly disclosed and tightly controlled.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the code's main function is obtaining API key or secret material from an existing userToken rather than performing the stated logistics operations, the mismatch can facilitate overcollection of credentials. In a skill context, collecting account keys is more sensitive than ordinary query automation and should be clearly disclosed and tightly controlled.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill explicitly checks for and later uses a local credentials file containing platform and API key material. Accessing and persisting commercial credentials is highly sensitive in an agent skill because compromise of the host, overbroad tool permissions, or accidental leakage through logs/output could expose reusable secrets for the user's account.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

text
客户说「我要批量查快递」/ 提供一批单号
        ↓
【第 1 步】检查凭据(~/.workbuddy/xdcc-credentials.env 是否存在且可用)
        ↓
   有凭据 ───────────────┐
        ↓ 无凭据          │

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The documentation confirms that PlatformID and APIKey are written to ~/.workbuddy/xdcc-credentials.env, which is a reusable secret store. In the context of an agent skill with file and shell capabilities, local secret persistence significantly raises the risk of credential theft, accidental inclusion in archives, debugging output leakage, or unauthorized reuse by other processes.

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
---

**安全与合规提醒**
- PlatformID / APIKey 是商业凭据,写入 `~/.workbuddy/xdcc-credentials.env`,**勿硬编码进代码或公开文档**。
- Tel 仅用手机号后 4 位,勿主动索取完整手机号;注册密码由客户提供,技能不替客户设定密码。
- 注册的「短信验证码 + 滑块验证」是安全校验,必须由客户本人完成,技能不绕过。
- **发布合规**:本技能包不含任何第三方推广内容,也不内置外部联系渠道(即时通讯账号、电子邮箱、电话、外部站点地址一律不予写入);第三方页面注入的仅是无品牌标识的纯操作提示条,不做满幅铺排。

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The skill documentation instructs users to give the assistant their phone number and password and references local credential storage containing API access material. In this context, credential handling is central to the workflow, so normalizing assistant-mediated access to account secrets materially increases the chance of credential theft, accidental disclosure, or abuse of the downstream API account.

Content

Scanner excerpt · references/onboarding_guide.md (reported line 80)May include surrounding context.

md
- 已有小递查查网页账号:直接给助手手机号+密码,选择登录模式即可,无需重复注册。

**Q6:我的凭据安全吗?**
- 凭据仅保存在你本机 `~/.workbuddy/xdcc-credentials.env`,不会上传到任何第三方;请勿将文件发给他人。

---

Credential Access

High
Category
Privilege Escalation
Confidence
74% confidence
Finding

The troubleshooting step tells users to open a local credentials file and inspect specific secret values. While intended for self-service debugging, directing users to secret-bearing files increases the chance they will paste contents back into chat or expose them during support interactions, especially because the next step asks them to send error text to the assistant.

Content

Scanner excerpt · references/onboarding_guide.md (reported line 92)May include surrounding context.

md
| 步 | 操作 | 能定位什么 |
|---|---|---|
| 1 | 打开 `~/.workbuddy/xdcc-credentials.env`,确认三个键都在且非空:`XDCC_PLATFORM_ID` / `XDCC_MEMBER_ID` / `XDCC_API_KEY` | 凭据是否写全、有没有被误删 |
| 2 | 执行 `onboard.py --validate-only` | 当前凭据是否仍有效(过期/被重置会在这里暴露) |
| 3 | 把报错原文发回给助手 | 助手带着上下文继续协助处理 |

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The function writes sensitive API credentials and an optional user token to a plaintext .env-style file at an arbitrary caller-supplied path. Although the code attempts to tighten permissions on POSIX systems, the secrets remain stored unencrypted, and there is no validation that the destination is secure, not a symlink, or not in a shared/workspace location; in this skill context, the stored credentials grant access to logistics query capabilities and possibly webpage API access via the token.

Content

Scanner excerpt · scripts/common.py (reported line 89)May include surrounding context.

python
def write_creds(path: str, creds: dict, token: str = None, extra_comment: str = "") -> None:
    """把凭据写入 .env 风格文件(UTF-8)。会保留注释头,便于客户自查。"""
    pid = creds.get("XDCC_PLATFORM_ID", "")
    mid = creds.get("XDCC_MEMBER_ID", "")
    key = creds.get("XDCC_API_KEY", "")

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The script writes API credentials and a user token to a predictable plaintext file under the user's home directory (~/.workbuddy/xdcc-credentials.env). Storing long-lived secrets in an unencrypted env-style file can expose them to other local users, backups, accidental disclosure, or overly broad file permissions, especially because this skill's purpose is to acquire and persist usable API access for later automation.

Content

Scanner excerpt · scripts/guided_register.py (reported line 306)May include surrounding context.

python
p.add_argument("--password", help="密码(自动填入,可留空手动填)")
    p.add_argument("--no-autofill", action="store_true", help="完全手动填写表单")
    p.add_argument("--timeout", type=int, default=600, help="等待完成注册的秒数(默认600)")
    p.add_argument("--creds", default=os.path.expanduser("~/.workbuddy/xdcc-credentials.env"),
                   help="凭据输出路径(默认 ~/.workbuddy/xdcc-credentials.env)")
    p.add_argument("--chrome-path", default=None, help="Chrome 可执行文件路径(默认自动探测)")
    args = p.parse_args(argv)

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:73

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
xdcc-batch-query/SKILL.md:73