Back to skill

Security audit

运费比价在线寄件快递上门取件

Security checks for vulnerabilities and agentic risk

Overview

The skill’s shipping workflow is mostly coherent and disclosed, but it handles live account tokens and billable shipment actions, and the published artifact includes unexpected hidden development-memory files.

Review before installing. Use the documented scripts, require explicit confirmation for any billable or irreversible action, and avoid sending passwords through chat when a manual browser login is acceptable. The publisher should remove the nested duplicate project and hidden .workbuddy memory files before distribution, and users should protect or periodically clear ~/.workbuddy/xdcc-credentials.env.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (109)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill explicitly supports collection of usernames/emails/phone numbers and passwords for automated login, then persists an auth token in a local file. In a conversational agent context, that credential-processing path is highly sensitive because it centralizes account access and could expose reusable authentication material to other local users, backups, or logs.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill documents retrieval of a browser-resident auth token and storage in ~/.workbuddy/xdcc-credentials.env, plus automated login using a username and password. Persisting reusable credentials or session tokens in a local file materially increases the risk of account compromise through local disclosure, weak file permissions, backup leakage, or log/agent mishandling.

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

md
报价与下单都走**网页侧鉴权**:请求头带 `auth: <userToken>`,这个 token 只存在于浏览器
localStorage,必须通过真实登录一次拿到。

- 存放位置:`~/.workbuddy/xdcc-credentials.env` 的 `XDCC_USER_TOKEN`
- 获取方式:`python web_login.py --username <账号> --password <密码>`
  —— **全自动**:填表 → 点登录 → 取 token。登录页只有「用户名或邮箱 + 密码」两个字段,
  **没有**短信验证码和滑块(那是注册页的),所以无需人工介入。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 359)May include surrounding context.

md
python scripts/selftest.py # 先过自检(241 项,含上架合规扫描与三道安全闸门)

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The security note confirms that login tokens are written to a local credentials file. In a skill that handles shipping orders, cancellations, and work orders, theft of that token could allow unauthorized viewing of PII or execution of account actions against the user's shipping account.

Content

Scanner excerpt · SKILL.md (reported line 368)May include surrounding context.

md
---

**安全与合规提醒**
- 登录 token 写入 `~/.workbuddy/xdcc-credentials.env`,**勿硬编码进代码或公开文档**。
- 账号密码由客户提供,技能只做自动填入与提交;不代客户设定密码,也不存储密码。
- 报价必须传省市区,这是功能必需输入;可选的**详细地址**只有客户主动写在输入里才会发出。
- **下单会真实扣款**:脚本默认只预览,`--confirm` 才提交;Agent 必须取得客户明确确认后再加该参数。

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide explicitly tells users to give their xdccy.com username/phone and password to the assistant so it can automate login. That creates a credential-handling anti-pattern: secrets are exposed to the assistant/runtime and potentially to logs, transcripts, or other storage layers, with no warning or safer alternative. In this skill context, the danger is elevated because the account can be used to place or manage shipments, view order data, and submit work orders.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

place_order() directly calls the live order-placement endpoint and its own docstring says it causes real charges, while the skill metadata claims orders default to preview unless explicitly confirmed. This mismatch is dangerous because an agent or user may believe the action is non-committing and accidentally create billable shipments.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

cancel_order() performs an immediate live cancellation with no preview or confirmation barrier. Because shipment cancellation is a destructive business action, a caller relying on the manifest's 'default rehearsal' promise could unintentionally cancel real customer orders.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline documentation explicitly states cancellation has no preview mode and is immediately effective, which directly contradicts the manifest's claim that cancellations default to rehearsal. This documentation mismatch increases the likelihood that upstream agent logic, reviewers, or users will misunderstand the risk and invoke a destructive action unsafely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

add_work_order() submits a real work order immediately, despite the skill description promising default preview/rehearsal semantics for work-order submission. Even if less destructive than order placement, this can still create operational tickets, trigger carrier workflows, and generate support noise or fraudulent requests.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

intercept_waybill() directly submits interception/return requests, which are highly sensitive shipment-modifying actions, yet there is no default rehearsal despite the manifest promising one. In this shipping skill context, that makes the issue more dangerous because it can reroute or return packages and materially disrupt deliveries.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-price/.gitignore (reported line 9)May include surrounding context.

text
*.py[cod]

# 凭据文件(含商业密钥,绝不可入库)
*.env
*credentials*.env

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-price/.gitignore (reported line 10)May include surrounding context.

text
*.py[cod]

# 凭据文件(含商业密钥,绝不可入库)
*.env
*credentials*.env

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · xdcc-batch-price/.workbuddy/memory/2026-10-02.md (reported line 9)May include surrounding context.

md
- `selftest.py` 实测 **49/49 全部通过**(Python 3.13.12,退出码 0),`py_compile` 全部通过。
- 项目尚未安装到 `~/.workbuddy/skills/`,当前仅存在于 Desktop 工作区。
- 本机 **未安装 playwright**,且无 `~/.workbuddy/xdcc-credentials.env` 凭据。

### 实测确认的缺陷清单(待修复)
1. **P1** `guided_register.py` 顶层 `except ImportError: sys.exit(2)` → 抛出 `SystemExit`,使 `onboard.py` 的 `except ImportError` 容错失效,进程裸退出(已复现)。

Static analysis

No suspicious patterns detected.