Back to skill

Security audit

跨境法律合规·小律同学AI

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent legal-search integration, but it can automatically send potentially sensitive legal questions to a third-party MCP service without clear confirmation or confidentiality guardrails.

Install only if you are comfortable routing legal research queries to aixllaw's remote MCP service. Avoid sending confidential case facts, privileged attorney-client material, trade secrets, or personal data unless you have reviewed the provider's terms and data handling. If you use an API key, store it only in the intended MCP configuration and review that configuration periodically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/mcp-setup-guide.md (reported line 85)May include surrounding context.

md
echo "Session: $SESSION_ID"

# Step 2: 执行法律检索
curl -s https://mcp.aixllaw.com/mcp \
  -X POST \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill enables implicit invocation for a remote MCP tool without any trigger constraints, exclusions, or user-confirmation guardrails. In a legal-research context, this can cause the agent to automatically send user queries or surrounding context to a third-party service when legal topics are detected, increasing the risk of unintended data disclosure and unreviewed tool use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/mcp-setup-guide.md (reported line 54)May include surrounding context.

bash
# 验证服务在线(免登录模式无需 token,内置免费额度,配置后即可直接使用)
# 说明:此请求并非完整 MCP 协议调用,返回 400/406 等错误状态码即代表服务在线可达,属正常现象
curl -s https://mcp.aixllaw.com/mcp \
  -X POST \
  -H "Content-Type: application/json" \
  -d '{}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/mcp-setup-guide.md (reported line 85)May include surrounding context.

md
echo "Session: $SESSION_ID"

# Step 2: 执行法律检索
curl -s https://mcp.aixllaw.com/mcp \
  -X POST \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all operational guidance, examples, and warnings exclusively in Chinese, and does not indicate that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file mixes a Chinese-facing interface with an English-only default prompt, but does not offer a language choice or explain the locale behavior. This may force a specific language mode without user opt-in, which fits the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This file's natural-language instructions, examples, and expected user prompts are all Chinese-only, with no indication that users may choose another language or locale. Under the policy-violation category, forcing a specific language without user opt-in can be a language/locale policy issue.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/mcp-setup-guide.md:66