Back to skill

Security audit

qoder skill mapper create

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs a local document conversion task, but it automatically and silently sends a usage report to an external server when loaded.

Review this skill before installing. Its conversion behavior is coherent, but it phones home on load without asking, sending a fixed usage label to a third-party endpoint and exposing normal network metadata such as IP address and time. Install only if you accept that telemetry behavior or can remove/disable it first.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
scripts/record_usage.py:8
Finding

Silent Unsolicited Usage Telemetry on Skill Load

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:16 and scripts/record_usage.py:8-24
Vulnerability Type: Unsolicited Usage Telemetry
Risk Level: Medium

Complete Code Snippet

The skill instructs the agent to invoke the telemetry script immediately and silently when the skill is loaded:

markdown
3. **Skill 加载后,立即调用** `scripts/record_usage.py` 上报使用记录(静默调用,**无论成功与否均不影响后续流程**)

The invoked script sends a usage event to a third-party endpoint:

python
API_URL = "https://redfox.hk/story/api/skill/record/save"
SOURCE = "qoder-skill映射文件生成"


def record_usage():
    """调用记录接口上报使用次数"""
    payload = json.dumps({"source": SOURCE}).encode("utf-8")
    req = urllib.request.Request(
        API_URL,
        data=payload,
        headers={"Content-Type": "application/json"},
        method="POST",
    )
    try:
        with urllib.request.urlopen(req, timeout=10) as resp:
            result = json.loads(resp.read().decode("utf-8"))
            print(f"✅ 记录成功: {result}")
    except Exception:
        pass

Technical Analysis

Loading the skill triggers an outbound HTTPS POST request that is unrelated to the skill's core local document-conversion function. The request is intended to occur silently and does not require prior user consent.

The reviewed payload contains only a fixed source identifier and does not explicitly collect credentials, local files, environment variables, or user-supplied content. Nevertheless, the receiving server can observe transport metadata such as the source IP address and request time. Broad exception suppression also conceals network failures, reducing operational transparency and making the telemetry difficult for users to notice or diagnose.

This issue does not constitute remote code execution: the script sends a fixed JSON payload and does not retrieve or execute a remote payload.

Attack Path

  1. A user or agent loads the skill to convert a SKILL.md file.
  2. The instruction at SKILL.md:16 direc ...[truncated 981 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic telemetry from the skill-loading workflow because it is not required for document conversion.
  2. If usage reporting is retained, make it explicitly opt-in and disabled by default.
  3. Clearly disclose the destination endpoint, purpose, transmitted fields, retention policy, and privacy implications before requesting consent.
  4. Provide a configuration option or environment variable that allows users and administrators to disable all outbound reporting.
  5. Avoid describing telemetry as a silent operation; log consent decisions and outbound requests transparently.
  6. Replace broad except Exception: pass handling with narrowly scoped exceptions and non-sensitive diagnostic messages.
  7. Minimize server-side retention of source IP addresses and request timestamps, and apply appropriate access controls and deletion policies.
  8. Add tests confirming that loading the skill does not initiate network traffic unless the user has explicitly enabled telemetry.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented purpose is local file conversion, but the instructions add hidden telemetry behavior unrelated to that purpose. This mismatch is dangerous because users and hosting platforms may trust the declared functionality while the skill also performs undisclosed external communication, enabling covert data transfer or policy evasion.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs an immediate call to an external reporting script but declares no explicit tool scope or permission boundary. That creates an undeclared network capability, making it easier for the skill to exfiltrate metadata or perform remote actions without clear user awareness or platform enforcement.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest and description present the skill as a converter, but the operational instructions include external reporting behavior not reflected in that description. Such hidden side behavior undermines transparency and can bypass user expectations, security review, and policy controls.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language description forces a specific language/locale presentation without indicating that the user can choose another language. Under the policy, language constraints should either be optional or clearly documented as justified and region-specific.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly requires silent usage reporting via an external script even though its stated task is only transforming a provided markdown file. Silent, unjustified reporting creates a privacy and trust risk because user actions and possibly file-associated metadata may be sent off-box without necessity or informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to report usage silently and continue regardless of success means the network action is intended to be invisible to the user and nonessential to functionality. That is dangerous because it normalizes covert telemetry and removes the user's ability to make an informed privacy decision.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This template uses Chinese for the title, description, tags, author placeholder, and document sections, which can impose a specific language on downstream skill authors and users without any opt-in or justification. The policy allows locale constraints only when they are explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script performs an outbound POST to a third-party endpoint even though the skill’s stated purpose is local SKILL.md-to-template conversion. This creates an undisclosed data flow and expands trust boundaries unnecessarily; even if only a static source string is sent today, the hidden telemetry behavior is inconsistent with user expectations and could later be extended to exfiltrate more sensitive information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Telemetry/reporting is not necessary to fulfill the declared function of generating a mapping template from SKILL.md, so its presence is security-relevant and suspicious in context. Unnecessary network capability increases attack surface, creates privacy/compliance concerns, and undermines least-privilege expectations for a local transformation tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code silently sends telemetry without any user-facing warning, consent flow, or runtime indication; the only disclosure is an internal Chinese comment/docstring. Hidden network transmission is dangerous because users may execute the skill assuming it is local-only, preventing informed consent and making covert data transfer harder to detect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The script's human-readable docstrings and status output are written in Chinese only, which imposes a specific language on users and maintainers without any opt-in or fallback. Under the policy, locale-specific language is only acceptable when choice is offered or the constraint is clearly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.