Back to skill

Security audit

pansou

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real PanSou cloud-drive search tool, but it needs review because it broadly triggers searches for download/viewing links and can expose PanSou tokens in normal command output.

Install only if you trust the PanSou services you configure. Treat searches as potentially sensitive, avoid sharing verify output because it may contain a token, prefer the default POST mode over --get, and use the tool only for resources you are allowed to access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a functional网盘资源搜索 capability with intent triggering and concurrent querying across PanSou sites. However, the supplied code chunk is effectively a placeholder: it merely declares a non-Windows build constraint and an empty Go package. There is no observable implementation of the described behavior. This is a material mismatch because the actual code does not perform the skill’s stated primary purpose at all.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose is an end-user search skill for finding cloud-drive resources across multiple sites based on viewing/download intent. The supplied code does not implement any search, trigger logic, network access, concurrency, or link retrieval. Instead, it only changes Windows console encoding settings via system calls. This is a materially different behavior from the declared primary purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger conditions are intentionally broad enough to activate on common phrases like '看', '找', or a bare title, which can cause the skill to run in many contexts the user did not intend. In practice this increases the chance of inappropriate invocation, accidental querying of user-supplied endpoints, and unwanted assistance in locating potentially infringing content.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is expressly designed to help users find viewing or download links for films, anime, software, and study materials, which materially facilitates access to potentially copyrighted content through cloud-drive and similar sources. The surrounding examples and workflow make this more dangerous because they normalize direct retrieval of links rather than lawful discovery or general discussion.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guidance explicitly says to use the skill without waiting for clear trigger words, which weakens invocation boundaries and can override user intent. That makes the skill more dangerous in context because it encourages proactive searching for download/viewing links from loosely related conversation, including through user-configured external services.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

When token verification or re-login succeeds, the code returns JSON containing the authentication token and prints it to stdout. Exposing bearer tokens in normal CLI output is dangerous because they can be captured by terminal logs, shell history, CI logs, wrappers, or other local users/processes, enabling account/session compromise against the PanSou service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The CLI supports a --get mode for search requests, which places the search keyword and optional filters directly into the URL query string. In this skill’s context, users are searching for media/download resources, so queries may reveal sensitive interests and can be exposed through browser/proxy logs, shell history, reverse proxies, and monitoring systems; there is no warning or safety gate before using this mode.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

该文件以中文撰写并直接面向用户说明 CLI 参数,但没有说明这是面向特定中文用户群体的区域化文档,也没有提供其他语言选项。按规则,强制特定语言而无用户选择或明确合理说明,属于自然语言层面的语言/区域策略风险。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents all user-facing instructions and descriptions exclusively in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no language choice or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's user-facing messages, help text, and errors are consistently written in Chinese, and there is no mechanism to let the user choose a language or acknowledge the locale restriction. This can violate language or locale policies when tools are expected to be language-neutral or user-selectable.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.