Back to skill

Security audit

China Holidays

Security checks for vulnerabilities and agentic risk

Overview

The skill’s main purpose is coherent, but its refresh path can fetch and cache a URL taken from a remote search result without checking that it stays on the expected government site.

Install only if you are comfortable with a skill that may contact the network to refresh holiday data and write cache files in its own assets directory. Prefer cached use when possible, and treat force-refresh results as untrusted unless the retrieved URL is confirmed to be an expected gov.cn notice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fetch_holidays.py:226
Finding

Unvalidated Search Result URL Enables Server-Side Request Forgery

Content
View full analysis
str: headers = { 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) ' 'AppleWebKit/537.36 (KHTML, like Gecko) ' 'Chrome/120.0.0.0 Safari/537.36', 'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Accept-Language': 'zh-CN,zh;q=0.9', } req = urllib.request.Request(url, headers=headers) try: with urllib.request.urlopen(req, timeout=30) as response: html_content = response.read().decode('utf-8') return extract_chinese_text(html_content) # Line 555: Unvalidated URL reaches the request function content = fetch_notice_content(url) ``` ### Technical Analysis The destination URL is obtained from a remotely supplied search API response and passed directly to `urllib.request.Request` and `urllib.request.urlopen`. The implementation does not validate: - The URL scheme. - The destination hostname. - The destination port. - Embedded credentials. - Whether the hostname resolves to a loopback, private, link-local, or otherwise restricted address. - Redirect destinations followed by `urllib`. - Whether the destination remains within the expected `gov.cn` domain. Consequently, compromise or manipulation of the search response could cause the script to request an attacker-selected destination. An allowed initial destination could also redirect the request to an internal or otherwise prohibited endpoint because redirect targets are not independently validated. The returned response is processed by ...[truncated 1955 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to run a Python script that reads local cache files, writes cache files, and performs network access, but it does not declare any corresponding tool scope or allowed-tools policy. This creates an authorization ambiguity: an agent or runtime may permit broader capabilities than intended, making filesystem writes and outbound requests occur without explicit least-privilege controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document specifies the expected output as "纯中文内容", which imposes a fixed language requirement. Under the natural-language policy rules, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly justified and documented as region-specific behavior for user interaction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The module description states the skill fetches Chinese government holiday notices and later the implementation extracts and preserves only Chinese text. This is a natural-language locale restriction with no user opt-in or configurable language/locale choice, which matches the policy category for forced language behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The force-refresh trigger list includes generic phrases such as "刷新一下数据" and "重新下载", which are common everyday expressions and are not tightly scoped to holiday data or this skill. In a markdown skill description, these ambiguous trigger examples can cause the agent to infer invocation too broadly when the user may mean a different kind of refresh or download.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions say that phrases like "重新获取"、"刷新数据"、"从网上查最新的" and especially "刷新" should be interpreted as requiring a forced network fetch, but these phrases are highly generic. Because the markdown does not pair them with strict holiday-specific context or exclusion examples, the trigger condition is overly broad for safe skill activation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

SQP-3 applies to all file types and covers natural-language policy violations such as forcing a specific language without user opt-in. This file presents all user-facing content exclusively in Chinese and does not indicate that the language is optional or region-specific within the skill context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file is entirely in Chinese, including the title and body, with no indication that language choice is optional or that the skill is explicitly limited to a Chinese-language or China-specific context. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.